Static | ZeroBOX

PE Compile Time

2021-02-23 17:28:17

PE Imphash

61a0ecfcf6fd30fcdee45e90e04a32c9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0004c6b7 0x0004c800 7.75355892169
.rdata 0x0004e000 0x000056a6 0x00005800 4.95879251835
.data 0x00054000 0x0000519c 0x00004800 5.23805245852
.reloc 0x0005a000 0x00000e70 0x00001000 6.24735040276

Imports

Library KERNEL32.dll:
0x1004e000 Sleep
0x1004e004 GetCurrentThreadId
0x1004e008 lstrlenA
0x1004e00c WriteConsoleW
0x1004e014 GetCurrentProcessId
0x1004e01c InitializeSListHead
0x1004e020 IsDebuggerPresent
0x1004e02c GetStartupInfoW
0x1004e034 GetModuleHandleW
0x1004e038 GetCurrentProcess
0x1004e03c TerminateProcess
0x1004e040 InterlockedFlushSList
0x1004e044 RtlUnwind
0x1004e048 GetLastError
0x1004e04c SetLastError
0x1004e050 EnterCriticalSection
0x1004e054 LeaveCriticalSection
0x1004e058 DeleteCriticalSection
0x1004e060 TlsAlloc
0x1004e064 TlsGetValue
0x1004e068 TlsSetValue
0x1004e06c TlsFree
0x1004e070 FreeLibrary
0x1004e074 GetProcAddress
0x1004e078 LoadLibraryExW
0x1004e07c RaiseException
0x1004e080 ExitProcess
0x1004e084 GetModuleHandleExW
0x1004e088 GetModuleFileNameA
0x1004e08c MultiByteToWideChar
0x1004e090 WideCharToMultiByte
0x1004e094 HeapFree
0x1004e098 HeapAlloc
0x1004e09c FindClose
0x1004e0a0 FindFirstFileExA
0x1004e0a4 FindNextFileA
0x1004e0a8 IsValidCodePage
0x1004e0ac GetACP
0x1004e0b0 GetOEMCP
0x1004e0b4 GetCPInfo
0x1004e0b8 GetCommandLineA
0x1004e0bc GetCommandLineW
0x1004e0c0 GetEnvironmentStringsW
0x1004e0c8 LCMapStringW
0x1004e0cc GetProcessHeap
0x1004e0d0 GetStdHandle
0x1004e0d4 GetFileType
0x1004e0d8 GetStringTypeW
0x1004e0dc HeapSize
0x1004e0e0 HeapReAlloc
0x1004e0e4 SetStdHandle
0x1004e0e8 FlushFileBuffers
0x1004e0ec WriteFile
0x1004e0f0 GetConsoleCP
0x1004e0f4 GetConsoleMode
0x1004e0f8 SetFilePointerEx
0x1004e0fc CreateFileW
0x1004e100 CloseHandle
0x1004e104 DecodePointer

Exports

Ordinal Address Name
1 0x10036e1e DllRegisterServer1
!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
LLO$-'R#
ZiL,(PQc
NjI'(M
zgd[,Q
;PC,Aj
AkJ;_K|
_qUoTwg
s4HL
vuK<hz
<nGV[H"
M@' ?
gNa%E\
Fw$>"%
o]W*yT
`eCe%7
7FF_N]A
7(8%<<
M/7nFS
e7X&G)<
v4bd(K
lqArK:
K;}a9H6
QnoL1XM
g'>?Tb
D^@`\5
fY~EQ[#
U?Cc4@25
S.1e=l
.4wYyb
kGQ>QR
>jUt!"s
\"Qx4X
3=*" w(o
^KSN^q
%!:*{E
a(M/Y9&
cX#iPk
NK2-]A
a"~HuI
+U/d*+
Dio|iV
&{*u'
j=7'k K
9x|&:q<
NFXH9<
F_+v/QT
@E_x2!4Qb
'6Rk"hK
u$\xl}
`g9[!]R<1t
`m}}~3
D\S">G
Xk|?5D
%| .BH
f*^~[\
M.s}_{b
PXT6qa`
9m1?fc
w3p[fDf
mYmfS4
m@C7zmY
L&?D`
#%b{ J
%OX!Es
,@Ot}h
uo4zPZ
K||"N)
?7E!ib,QPh
\&YBRA
\C.wFR
v~pP\X
=,^.5R
$Mdn^r
_lrX"YI
-x#q;%
d=T}7K
trA#}]
3D=]7h
,`gO4
w\'!zp
kd;9M}
/S9%oI[
J%tai}
-`rAji
7N&*%gMC
u.~v'lq
lkK`~6
><=Iqz(
lf9?g&rA
Ho:=:@
5~d7e?
a@G%e~
DBbeW)
n=<>#V
99n8j|4"f
R|c^;07@
i=:q/6u
R1mz$
CnJ"wJ$
I;>,VC
]Z/Ya5
lSJ"Oz]cg
V'~{-%
h"?4,R
Oo|[s'[
-YO^`k5
3|<@>r>
|lX7=m
1{(y-n
Z2Xg_!{
hM/ZEm
\Zc2{4
u+LL=s
H4&Me8
\O)~DV
h.>1Iw
gd}]ge
0*)Nxp
>A+|^e
}BjJ=+
sY8;Ac
r{#a2v
$Q/bFv
s!o]HN
H5BCP2
",RC$XC
A<57c
5S~e`T,u
Y?FLr!-J
!p/D`Z
jK9k- #
a2g//utKJ
n>k)b>
u=37?H
nodIT
4%55m
WXzi@}
vw=E
kT6k@;
zTldN!
vV8dB?1[m
)>Nkgt
6;M_Hu}
{%/48k
xJs;0I
t=Ino4;'u
JGdImR
lEh9;7
iFx/%-K
N\ql u
)8TF7J
tG8@s-
PSr/zb
J_MQSSC
1[%M=gg [$c
y{VEZ
B`MTP2N-b
'7BWN
7t$Je6'
|Xyy>g
{a%FS<-
tDYzDn
8.3i.
5fEN~@
5 >4tS
Z`,&[_\
&Snul;L
0+,p'[
4qm.DC?
;*A>\V
<lYxHF
YuN3~Ac
-Y>OsJ
mU\'W?
tlMa)Vy
Q(QG{F
yfna:/
bAs^hi3
=p(}W0
k"<VJl
{soT*h%
(y80GVc
Tr?`(/C
4zS'bp
5j?x*S
xQxWeqD
lJxG68br
T=6Mys`v
(%3V{!
{GtSDd
rLRAcN
nBTS"9
C.LAkR
A`OOii
hcNN!k
6}L3#(
fxtN5"
V `'ZN
!hB$a#
A.>`8<
pe1FSI?
`VCNK-0(K
NCp8v{l[7
/Fj1i!
=N5KXKA
?=q3R
w~GDo3
=\}u`$*
Xy1q|w
$tQdCC
7PWYG3}
~jW}F<
!4`%[8
xF&2fY
;zCKF#Y
b/0$Il
mr*ZT}R$E
.IGyN
}W\=L3k
).h3xNX
C%7abG9
p-*bEW
Yl-lC|
&@Ve!jD
'LFR[g
^3.,l/
!6B_1oB
zo}[]B
[&'@ud
dwN--K
4;COf/
H7n1lP(
i-7=:k
]l83I#
\hb5/$
IXDNfMj
EX`^=S
8'2N^"
)b<,K(
g-Cp}b
\b1Ij}
S?rVtfFr
DJHbcR
-nEysl6
.2B=v{
K 1e+Z|dV^
tONXb`
!nkjyr
O24?(&
&:^RdO
1LrEB{
i4UjqOHt
qtoJcS
>/Soi-
nOSF8d
+Bz4_M}
ksd*Kp
WA(Ow<LG5
,_uJ?
P;p}$2
~9'_fT[j
{VF1sR
!5Y@>p
,fB?SP
M{]}BC
01+y1c
W`U-?c
y_/V*]
lKwt F
8.1L{R
'8^B:R
AN~J,m
Va'C5fC
XsC@zf
O*/U`a
M,*+wPC
]__hy&
q5nU:O
$6<,Bg1
D=gW7L
t5n.Q
\x9({)lFN:p8#
@*87i#
"ND:`
7)GvhFQs
b}FZR5x
r(KK<J
/|Sy=8
TU`T1U
Y~ns>/
&9oxN{
+sShfB
:RC{g`<
S(K#d78h
q1y&D\
`H-x1
8,5,.?Z
5nG! &
1=*%$&
vqw]>2
Vg}rCy
khE2nw2
EIr$D%
%kU]o
K*S\Fl
V6m=14
l/{\A-
_jDxrOQ
V![-d&
Xx0&`|ERb
)D<X@/
HCC{-
Y\{5%D
dj)t3
0p9|C:q0
dI|q8L
tJ~}t
nD.%{<
l2!T$|
!Ati;"
h];a!^
?Fk?6S2
(""W*4
OA/Oia7
_'2pe5
7I."I@-
#epJ22
7"JcDk
~WCb
]m\7_w
SP8_^;
M+?^od
m"Q2|Rr
3U)5Y#
0$A~.!
$LoZDi
5\mNNN7
R8}mApw
m_E`e@e
58{TWQ
qM>'T(
["-:q[
2i5[.]
Z+m>v^
k%jpzG
u%]JiM5
"coH0o
URPQQh@E
;t$,v-
UQPXY]Y[
SSSPSW
u-PSSW
SSVWh
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSWj0j@
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
DllRegisterServer1
GetCurrentThreadId
lstrlenA
KERNEL32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
InterlockedFlushSList
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
HeapFree
HeapAlloc
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
2'3e3k3
7>8T;e;
;"=/=K?
;b?k?t?}?
6&6+686
627D7h7
9&9,929>9D9
; ;3;?;O;`;v;
;)<6<Z<8=X=b=}=
=@>N>i>t>
?U?i?p?
0;0A0G0M0S0Y0`0g0n0u0|0
6 6K6P6
7,7@7\7f7p7~7
8 858H8b8}8
89'9Z9d9v9
:B:N:S:X:
;#;/;9;K;P;l;u;
;1;E;Z;a;m;
=0=K=w=
12:2J2O2Y2^2i2t2
3C4U4h4l4t4
5 5+515?5]5v5{5
5*606B6
<<&<C<j<
=(=8=E=n=w=
>%>G>X>e>~>
-070D0w0
1/161I1y1
7#7n7u7|7
60;0@0P0U0Z0
1>1F1~1
2!2&2A2K2g2r2w2|2
3#3(3F3P3l3w3|3
4&4B4a4
78:8E8q8
9d9i9n9s9
>?:?G?U?c?n?
1?1X1]1f1
=v>4?:?
0!1;1w1
2#292t2{2
3C3X3i3
3-4I4h4
=#=(=6=
=E>a>s>
?'?9?Z?l?~?
0+151_162
373D3t3
4P5V5[5b5r5
7T7^7y7
7)81898A8I8g8o8
=9>V>f>
0#1/1;1N1m1
6"8=8S8i8q8
00%0q1
1 1$1014181T1X1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
; ;,;4;<;@;D;H;L;
= =$=(=,=0=4=8=<=
@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
8$8,848<8D8L8T8\8d8l8t8|8
=,=0=L=P=p=
>0>P>p>
?0?P?p?
000L0P0
7 7$7074787<7@7D7H7L7
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
&yOpt.
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.847374
FireEye Generic.mg.5091a400a52fa023
CAT-QuickHeal Trojan.Trickbotcrypt
Qihoo-360 Win32/Trojan.Generic.Hx4CgxsA
ALYac Gen:Variant.Razy.847374
Malwarebytes Trojan.MalPack
Zillya Clean
Sangfor Trojan.Win32.TrickBotCrypt.PZ
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Razy.847374
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
Arcabit Trojan.Razy.DCEE0E
Baidu Clean
Cyren W32/Trojan.NSSC-1023
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Trickpak.gen
Alibaba Trojan:Win32/TrickBotCrypt.e4d1eb32
NANO-Antivirus Trojan.Win32.Trickpak.inlsgv
ViRobot Trojan.Win32.Z.Razy.359424.K
Rising Trojan.Trickpak!8.122C7 (TFE:6:1239c4crYYR)
Ad-Aware Gen:Variant.Razy.847374
TACHYON Clean
Emsisoft Trojan.TrickBot (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.Win32.Generic!BT
TrendMicro TROJ_FRS.VSNTBO21
McAfee-GW-Edition Trojan-FTJO!5091A400A52F
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Krypt
Webroot Clean
Avira TR/Kryptik.jualt
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/TrickBotCrypt.PZ!MTB
SUPERAntiSpyware Clean
AhnLab-V3 Malware/Gen.Reputation.C4345946
ZoneAlarm Clean
GData Gen:Variant.Razy.847374
Cynet Malicious (score: 90)
ESET-NOD32 a variant of Win32/Kryptik.HJQZ
Acronis Clean
McAfee Trojan-FTJO!5091A400A52F
MAX malware (ai score=85)
VBA32 Clean
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.VSNTBO21
Tencent Win32.Trojan.Trickpak.Sudt
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet W32/Kryptik.HJLB!tr
BitDefenderTheta Gen:NN.ZedlaF.34608.vq4@aiNcEEg
AVG Win32:BankerX-gen [Trj]
Avast Win32:BankerX-gen [Trj]
MaxSecure Trojan.Malware.109946090.susgen
No IRMA results available.