Static | ZeroBOX

PE Compile Time

2022-09-14 08:31:10

PE Imphash

07530c85f3bf8d18d55bc566a43ea905

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00010fa8 0x00011000 6.85155976513
.rdata 0x00012000 0x00000492 0x00000600 3.55905684701
.data 0x00013000 0x000062d0 0x00005c00 7.9365586457
.pdata 0x0001a000 0x00001374 0x00001400 7.90520744996
.reloc 0x0001c000 0x00000a60 0x00000c00 6.28366097343

Imports

Library gdi32.dll:
0x1001204c CreateSolidBrush
0x10012050 TextOutW
0x10012054 SetTextColor
0x10012058 SetDCBrushColor
0x1001205c GetPixel
0x10012060 GetDeviceCaps
0x10012064 CreateFontW
Library USER32.dll:
0x1001202c GetMessageW
0x10012030 IsDlgButtonChecked
0x10012034 LoadImageW
0x10012038 DefWindowProcW
0x1001203c CreateMenu
0x10012040 CreateWindowExW
0x10012044 DialogBoxParamW
Library KERNEL32.dll:
0x10012000 GetAtomNameW
0x10012004 SetLastError
0x10012008 GetTickCount
0x1001200c GetProcAddress
0x10012010 GetModuleHandleW
0x10012014 GetModuleHandleA
0x10012018 GetLocaleInfoW
0x1001201c GetLastError
0x10012020 FreeLibrary
0x10012024 GetFileAttributesW

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
.reloc
X_^ZY[
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
cccc||||wwww{{{{
kkkkoooo
gggg++++
YYYYGGGG
&&&&6666????
nnnnZZZZ
RRRR;;;;
[[[[jjjj
9999JJJJLLLLXXXX
CCCCMMMM3333
PPPP<<<<
~~~~====dddd]]]]
ssss````
""""****
2222::::
$$$$\\\\
7777mmmm
llllVVVV
eeeezzzz
xxxx%%%%....
ttttKKKK
pppp>>>>
ffffHHHH
aaaa5555WWWW
UUUU((((
BBBBhhhhAAAA
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
00006666
CCCCDDDD
TTTT{{{{
####====
ffff((((
vvvv[[[[
IIIImmmm
%%%%rrrr
]]]]eeee
llllppppHHHHPPPP
FFFFWWWW
kkkk::::
AAAAOOOOgggg
tttt""""
nnnnGGGG
VVVV>>>>KKKK
yyyy
YYYY''''
____````QQQQ
;;;;MMMM
ccccUUUU!!!!
euo[7z
SQRVW3
*?t'=]
SQRVWj
SQRVW3
_^ZY[]
_^ZY[]
_^ZY[]
_^ZY[]
SQRVW3
9D$$ua
L$ 9L$8}>
9|$0r4
T$PWSR
9|$0r4
D$PWSP
D$LEH;
+L$HRQW
+D$H[_]^
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
CreateFontW
CreateSolidBrush
GetDeviceCaps
GetPixel
SetDCBrushColor
SetTextColor
TextOutW
gdi32.dll
CreateMenu
CreateWindowExW
DefWindowProcW
DialogBoxParamW
GetMessageW
IsDlgButtonChecked
LoadImageW
USER32.dll
FreeLibrary
GetAtomNameW
GetFileAttributesW
GetLastError
GetLocaleInfoW
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetTickCount
SetLastError
KERNEL32.dll
)1/|@N`u2^R
Rrzzrl
ocHvGy9
oN.iq
Z\iH{Y
H|XZlE
`bT cx
>Q0"sY
_6`iI[
S\,p*\
xojm65
x=p{Z`
wHzTz7
4)EqQ
|=/ZqF?
cwOCo1
;xU&:hs:$
tT9R^m
d.N9%w
$R7{Ii~
/Sk#g9
S!`]4&}r
F"m7J[
#`P4=Q
4,z>@aD
Xr&Ivo
|:M*3$K
8W;Y!+
/=H-:P
K5q )J
3GMi[J
c0aZ1h?
?%U$38O
6:s8&K<s+
r')v p$7X
.qXd0x
Loyn?P00
D[~Rlc@
2>372+
DzGL,i
rw-0+p
cqyDCd
s0ZCm`
>:?A?H?O?s?
0!0&0t0
0"1)10171U1\1c1j1
2!2(2/2M2T2[2b2
3=3D3K3R3
344;4B4I4
4 5'5.555w5~5
5E6L6S6Z6
;_;q;w;
44+404<4A4M4R4^4c4o4t4
78;8W8v8
>S?Y?l?r?
0B0H0Q0u0{0
1"1(1M1S1\1g1v1|1
2'3>3W3n3
6;6Z6u6
=(===F=e=
'0I0V0
2'2>2W2k2
3G3a3z3
4595X5p5
656G6[6
8#888G8V8
8+9>9L9
==:=I=
>?9?m?
0!0*090H0
4<4_4w4
7,8R8p8
9,92989B9
:7:<:B:K:Q:W:a:u:
;=;F;];h;u;~;
<<,<5<]<
= =B=L=u=~=
= >)>;>F>S>\>y>
3!3/3=3O3`3
7*8B8\8p8}8
9 :-:K:
;4;=;W;
<:<]<~<
< =*=@=N=`=o=x=
?/?R?x?
131E1Z1
3<3G3[3j3~3
4:4C4U4l4{4
9*9<9a9s9
;;;L;W;
<<P<`<j<
>)>=>Q>c>
:#:_:;;H;X;b;
>->R>d>r>
0.0N0]0l0#2j2
40585T5c5q5
767<7B7l7
8%8=8R8[8q8
879J9i9
:=;l;r;|;
=0=j=u=
=8>=>C>Q>[>n>{>
?"?(?-?2?A?V?
8)8E8\8
9*9>9v9|9
;";v;|;
=*=<=C=I=N=T=
>+>M>b>
6H7R7e7
::H:Q:l:
:!;/;:;?;Q;
=)=8=\=f=
>M>[>f>k>}>
?f?p?z?
0$0.0@0T0]0h0
1(2?2I2S2a2k2}2
3"383i3
4&4/4=4G4[4d4o4y4
5?5E5Y5b5o5
6"606:6I6P6V6_6h6y6
6M7a7x7$:
D?J?P?V?\?b?h?n?t?z?
((((( H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.mtwx
Elastic Windows.Ransomware.Lockbit
ClamAV Win.Ransomware.Lazy-10003135-0
CMC Clean
CAT-QuickHeal Ransom.Lockbit.S30100487
ALYac Gen:Variant.Ransom.BlackMatter.40
Cylance Unsafe
Zillya Trojan.Filecoder.Win32.27016
Sangfor Ransom.Win32.Save.LockBit30
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Ransom:Win32/Lockbit.07209ab2
K7GW Trojan ( 005975a31 )
K7AntiVirus Trojan ( 005975a31 )
huorong Ransom/BlackMatter.b
Baidu Clean
VirIT Trojan.Win32.Vundo.FE
Paloalto generic.ml
Symantec Ransom.Blackmatter!g2
tehtris Clean
ESET-NOD32 a variant of Win32/Filecoder.BlackMatter.M
APEX Malicious
Avast Win32:MalwareX-gen [Ransom]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Ransom.Win32.Lockbit.pef
BitDefender Gen:Variant.Ransom.BlackMatter.40
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Trojan.Win.Z.Blackmatter.103936
MicroWorld-eScan Gen:Variant.Ransom.BlackMatter.40
Tencent Malware.Win32.Gencirc.10bc376d
Sophos Troj/Lockbit-W
F-Secure Trojan.TR/Crypt.EPACK.Gen2
DrWeb Trojan.Encoder.36774
VIPRE Gen:Variant.Ransom.BlackMatter.40
TrendMicro Ransom.Win32.LOCKBIT.SMYXDLK
McAfeeD ti!B582F63E5D9D
Trapmine malicious.high.ml.score
CTX dll.ransomware.lockbit
Emsisoft Gen:Variant.Ransom.BlackMatter.40 (B)
Ikarus Trojan-Ransom.LockBit
GData Gen:Variant.Ransom.BlackMatter.40
Jiangmin Trojan.Generic.hopdl
Webroot W32.Ransom.Lockbit
Varist W32/ABRansom.QJML-9094
Avira TR/Crypt.EPACK.Gen2
Antiy-AVL Trojan/Win32.LockBit
Kingsoft malware.kb.a.999
Gridinsoft Ransom.Win32.LockBit.sa
Xcitium Clean
Arcabit Trojan.Ransom.BlackMatter.40
SUPERAntiSpyware Clean
ZoneAlarm Troj/Lockbit-W
Microsoft Ransom:Win32/Lockbit.HA!MTB
Google Detected
AhnLab-V3 Ransomware/Win.LockBit.R521854
Acronis Clean
McAfee GenericRXUJ-SV!F5B840356356
TACHYON Clean
VBA32 TrojanRansom.BlackMatter
Malwarebytes Lockbit.Ransom.FileEncryptor.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Ransom.Win32.LOCKBIT.SMYXDLK
Rising Ransom.LockBit!1.DFDC (CLASSIC)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/BlackMatter.K!tr.ransom
AVG Win32:MalwareX-gen [Ransom]
DeepInstinct MALICIOUS
alibabacloud RansomWare:Win/Lockbit.x1glab
No IRMA results available.