Static | ZeroBOX

PE Compile Time

2021-02-24 16:56:26

PE Imphash

f2c474e93666bbd585aa036f9c203ef8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.rdata 0x00001000 0x00033000 0x00033000 7.9956091958
.text 0x00034000 0x000184f7 0x00018600 6.36052090502
.rdata 0x0004d000 0x000056a2 0x00005800 4.97018456486
.data 0x00053000 0x0000519c 0x00004800 5.23783580807
.reloc 0x00059000 0x00000e74 0x00001000 6.26548348838

Imports

Library KERNEL32.dll:
0x1004d000 Sleep
0x1004d004 GetCurrentProcessId
0x1004d008 GetCurrentThreadId
0x1004d00c lstrlenA
0x1004d010 WriteConsoleW
0x1004d01c InitializeSListHead
0x1004d020 IsDebuggerPresent
0x1004d02c GetStartupInfoW
0x1004d034 GetModuleHandleW
0x1004d038 GetCurrentProcess
0x1004d03c TerminateProcess
0x1004d040 InterlockedFlushSList
0x1004d044 RtlUnwind
0x1004d048 GetLastError
0x1004d04c SetLastError
0x1004d050 EnterCriticalSection
0x1004d054 LeaveCriticalSection
0x1004d058 DeleteCriticalSection
0x1004d060 TlsAlloc
0x1004d064 TlsGetValue
0x1004d068 TlsSetValue
0x1004d06c TlsFree
0x1004d070 FreeLibrary
0x1004d074 GetProcAddress
0x1004d078 LoadLibraryExW
0x1004d07c RaiseException
0x1004d080 ExitProcess
0x1004d084 GetModuleHandleExW
0x1004d088 GetModuleFileNameA
0x1004d08c MultiByteToWideChar
0x1004d090 WideCharToMultiByte
0x1004d094 HeapFree
0x1004d098 HeapAlloc
0x1004d09c FindClose
0x1004d0a0 FindFirstFileExA
0x1004d0a4 FindNextFileA
0x1004d0a8 IsValidCodePage
0x1004d0ac GetACP
0x1004d0b0 GetOEMCP
0x1004d0b4 GetCPInfo
0x1004d0b8 GetCommandLineA
0x1004d0bc GetCommandLineW
0x1004d0c0 GetEnvironmentStringsW
0x1004d0c8 LCMapStringW
0x1004d0cc GetProcessHeap
0x1004d0d0 GetStdHandle
0x1004d0d4 GetFileType
0x1004d0d8 GetStringTypeW
0x1004d0dc HeapSize
0x1004d0e0 HeapReAlloc
0x1004d0e4 SetStdHandle
0x1004d0e8 FlushFileBuffers
0x1004d0ec WriteFile
0x1004d0f0 GetConsoleCP
0x1004d0f4 GetConsoleMode
0x1004d0f8 SetFilePointerEx
0x1004d0fc CreateFileW
0x1004d100 CloseHandle
0x1004d104 DecodePointer

Exports

Ordinal Address Name
1 0x1003614e DllRegisterServer
!This program cannot be run in DOS mode.
.rdata
`.text
`.rdata
@.data
.reloc
6@d!-=}o
_?NT:/
[ j?}~
KcJgvdD
m/Eudw
Mm.NNZ
W@2v+y
y|:J$K
aq;J|)
bNL)1N
XY<x'6}0s
y#)]{$#
j] uasQ
Ge'_Uh@9
h)#hwYj
9&`Y/5Y
g1i$g'
t.)ICX
7CJqSo
f^U.2bL
s~Y1z^
Zr7aFo
YGK/SC
CRpo#b
7["p|"V
&U`_=\c
FhfrL+
33gL=D_
:@'$RLy
o5_')1aj
`pEc_'-
SUv5Pe
X"0;<U@:
qSu%7&
y[(m$O#
x\zjOo|l
T[PIx)E4
)Q8CcV
IXM`!>
eVe^:m
AoOCDm#
O'E=U9o
oXO,mz
,(xp+)
]Hq=1V
Hr{pZK-
M'(^AV
F0/R'^
AnDVn
"V6Y~g
Z(Pe=Vuw
?Y-6W#SB
',k7;(
A7s|ZF
&i?*|C
%`{Jz-
/|X^c#Fm
\/f}lV
i]Af~k
T%nRGv
:Q2Ba
eo'qzP>;
^RE7"X
@O|PyS
HfUzlV
*3#qwT92
&F`i"u
Zw DlN
.jB96G<
y!]cJn
|cdGJ;
feuYaDT
GzL`!.>
,:mg0D`
bm~^{\
yjx`ea
kG5VZ4n
*Kw*Jl
k`:AM!
**IAGs?
QTXB5
mV??_'
xw;H7H
MW9(2@
8G9$:%:Sm
}*M}ok
%Y;|gE
H\. t18(e
;mJiOr
IBXWdJ
U2WX7D
Y}k%%I
V~LfxO
-v0f9{
\uUD$d
7&>X_]kK
pw9-%'
<MltCP
e7f2^%+
.7RS:'
oslNHPf
[iPsqW
&2fTX#jq
)s^8d8
@BN]U,*Go95
ZsKL'5
Rv{]AW
%mgOHxz
6R"O\,dR
<CS;?pS
n"1zL dE
P{}8E{
*}V4#z
W=fSGz
A9le7+
-5SUxP
!_+Ik|
`qhkV
J|j{zs
A/wo9hh * F
r:EASe
dPAykaR;W
FNtI($n
|vwV~O
PJY^]}
^*gwAS
kU}MXM
m%XvBZ
C@T2nJcU
rK-j?o
'<I7s
]O`woRN
Z/}kcU
wM].oz
>%kkAe
|"kE!&
~Y/m4r\
{o1O^j
Qx!DrL
"!4Pa,$`[`
<zACq'
f>JLh~J
Yz1ms8
NoXMznk
Kho.$V,
9a]F5BJ
tB"18t
/-4R#%
qE:PZrO
=KPj x
{TRpOj
EJ/=zb
XtV ;T
w=;=d=+
5;{Qx!s
$Q%A;o
3CK?Obbh.l
I\aiYVO
N3@:&M
cqD+r2V
w>PU*/
ym:Cc?zO6
\[xjp
6,gocx~
rzfPn V
&3cTr}rN?Ij
C`ovQ$
Er]Tb
L BOVO
vQ,nEHG
f$5oa;
xvO>=x"
Pu'Oa`
8H=O B
e~%JYF
)8:]7B
(UV`FA
2nJX`K
(/iz9z
Pm|c?y}
}y|-=$
;wxZc[8r
aC0nCNf
]/?of,
*"]3~\
ZIv1MJY
C<|<=i
RHdZ<"
;z./bc
xqZjn<
UkUN*,
=Cj)G`Ua
vB+)Hg
YwT49Kl
%7^UY;
b*H`PwCRX9
+V]Sdm
E]/pRl}
,,zmJp
Q{]meu
T258{|v
$Bq(Ask
^dy1$#9{
'F]H6a
Pcktumu&
3ea,N+
=H+l+|
$&=L-w
AJ4VX`
yVhLor
q,8&2hP
}";H}e
~vXE)Z
]9{H)!
fsXK.d
6VZ->j
8M#?0P
\jE53x
09]\43
/V2:LV
<[^N+!
rq+Ueo
Rm}u+C
k(4>wt
Q~ 9b,
p7Uo]L
Np8{ z
Nef^#;
.R*:?+V
UOIQDL;.*9
(vB~,^L
K-U[G|K
gxNw3oV
Xbd`J%
ND'[ff`}
X@$.nd
F?l-X9
XFIdDY
fodY9/
DO7QH5
kX_%S!?
;^{p1G
?Nj+ax"
T=]&O$3A*h
W05r}
#~#oeW
f$*+N|%
0o*aJdZL"
tq9KO^
JyX|QL"
53W12ml
:%e30`
Kn.Sz<5
}+~_P*
$~@wfB
ko4R@f
. Zr]/
`-ggU\
;_@u/o
ojw+7Yb.
o+0A!Z
mZy=_C}
=x~0G4W
<HzC;;
zTU{}56
T*mShZ
5r%AwZE
#SOxbk
_g.^noF
8j/fW
P-A-f'?py
E6'K[$
EI7c"QP$l
_9@2G3fgl0o
|m%2lo
oh+;"d
~JzH4
4j`%-Zf
`rC.Y%&
*Wj9D(
iv""q/
MrQ|K:qQ
Gu!(bM~
@x=;N1tW
`vLO?3
V:fKg`
sA9K=G
pNr[2z
Bcy}E$y
|s^[QT
:%lzk-}t
Z=f$7I^
l<@_a4
YVQA{a
;KV([a
n%?z J
7)+4l[
q0jQl=x
+(jGpA
[u Tx
ts;:7N1
1f6^=Im
?>?PcPI
)/&5=*
.%QI+$N
|Kj#or
."fPKF
ax(uf7
|(.)iJX
ZX}5E;(
H+lF&1
K}ouhs
ctouV:
#PN7=\H
gOY>Fe
2DT~8(
keVdjj
tIb6Vw
fJZ'/LD
`w6wc(S<
'L72jx</
5IW,3n
RQ *rY
Zc8t'j
%c]\5h
&q%U|*
E^ZgJcI
L:qHr<
,$h48sTo
}})[*v
(i^hMj
uXqR 7M
6C$#)W
dX|&.c
o,A?Z*sv
N#8A]{
4Mu7YD
MYNrnt+
#mLOM-.=
]ho;\-
p)R)+
`l4R3dj
,ll?1/
I:8R$8&!
Gr*GXZ1
CKZQP*
$*8z1X
at`Jff
QIlh0h
6$u8j!6
+fA)xk
rjWl6{
j]lF),
/7yoW=
1rX*T{
%::xfV
bSsh?e
T[4[QP#<0}!
zN_vfp
,?"kgy
D} CD@
t=f&4j>
m^YbZz_
qkQ]0zgAX
n`eBKj
6%<RG<y0
z)kV#A
,(/F(8
kjo%ET
-Z6%#7
uz<_Xj
ozNp}B
85K=Mc
URPQQh
;t$,v-
UQPXY]Y[
SSSPSW
u-PSSW
SSVWh
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSWj0j@
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.rdata
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
DllRegisterServer
GetCurrentProcessId
GetCurrentThreadId
lstrlenA
KERNEL32.dll
QueryPerformanceCounter
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
InterlockedFlushSList
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
HeapFree
HeapAlloc
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<;=,>
4%4F4K4d4i4v4
7N7W7d7j7p7|7
8&9O9^9q9}9
<H=Q=Y=
>'>=>F>Q>X>x>~>
?#?3?C?L?
;0C0U0
3.454[4`4
5#5)5D5l5
6%6E6S6Z6`6u6
737_7g7
88$8H8T8Y8^8
9"9,9Q9c9o9y9
;';E;S;
=8=?=D=H=L=P=
8@9M9\9q9
: ;2;:;D;M;^;p;
020_0z0
2%3<3G3O3Z3`3k3q3
34<4j4p4
4Y5a5i5K6V6
:.:H:_:f:
;,;S;h;x;
<-<:<T<[<e<
?L?o?v?
4"5A5d5
9H9T9f9
:$:-:H:
<-=2=8===
0-0R0]0b0g0
1.181T1_1d1i1
33+383?3I3_3
3 4W4i4
5*5F5j5
6 6<6`6{6
60777>7E7R7
9919^9
=&===`={=
"0)0E0L0c0y0
8;8X8w8
;#;*;@;V;c;h;v;
==1=C=U=g=y=
=+?k?u?
4 4.4a4
6i6q6y6
717=7I7i7
8*8.9_9
>%>5>F>
?>?c?o?{?
50A0M0Y0l0
3(5b6}6
>->K>_>e>
1 1$1014181T1X1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
; ;,;4;<;@;D;H;L;
= =$=(=,=0=4=8=<=
@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
8$8,848<8D8L8T8\8d8l8t8|8
=,=0=L=P=p=
>0>P>p>
?0?P?p?
000L0P0
7 7$7074787<7@7D7H7L7
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Elastic Clean
DrWeb Trojan.KillProc2.15167
MicroWorld-eScan Trojan.GenericKD.45781014
FireEye Generic.mg.fcf94dfc58e09cac
CAT-QuickHeal Trojan.Trickpak
McAfee RDN/TrickBot
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Trickpak.do
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.45781014
K7GW Trojan ( 005785ae1 )
K7AntiVirus Trojan ( 005785ae1 )
BitDefenderTheta Gen:NN.ZedlaF.34608.vu4@aW7PAmi
Cyren W32/Trojan.YFLG-6079
TotalDefense Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win32.Trickpak.do
Alibaba Trojan:Win32/Trickpak.e181b4ba
NANO-Antivirus Trojan.Win32.Trickpak.inmjrr
ViRobot Trojan.Win32.Z.Agent.354816.HD
SUPERAntiSpyware Clean
Rising Trojan.Trickpak!8.122C7 (CLOUD)
Ad-Aware Trojan.GenericKD.45781014
Emsisoft Trojan.GenericKD.45781014 (B)
Comodo Malware@#17gck4vicjhb2
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R066C0DBS21
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.45781014
Webroot Clean
Avira TR/AD.TrickBot.vgsvr
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Clean
AegisLab Clean
AhnLab-V3 Malware/Win32.Generic.C4347287
ZoneAlarm Clean
Microsoft Trojan:Win32/TrickBot.DM!MTB
Cynet Malicious (score: 100)
ESET-NOD32 a variant of Win32/Kryptik.HJQZ
Acronis Clean
VBA32 Trojan.Trickpak
ALYac Backdoor.Agent.Trickbot
TACHYON Clean
Malwarebytes Trojan.TrickBot
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R066C0DBS21
Tencent Win32.Trojan.Trickpak.Eill
Yandex Clean
Ikarus Trojan.Win32.Krypt
MaxSecure Trojan.Malware.115353901.susgen
Fortinet PossibleThreat.MU
AVG Win32:BankerX-gen [Trj]
Avast Win32:BankerX-gen [Trj]
Qihoo-360 Win32/Heur.Generic.Hx4CgxsA
No IRMA results available.