PE Compile Time

1996-01-09 15:00:06

PE Imphash

cd7fcdda5ab111ed483e93c44d1d1ae1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.vjNlbf 0x00001000 0x00001613 0x00001613 6.18108937849
.kudd 0x00003000 0x000412fd 0x000412fd 0.130827821263
.FeE 0x00045000 0x000023d1 0x000023d1 6.18522519568
.kbVKK 0x00048000 0x00027d81 0x00027d81 0.252476712181
.WKQ 0x00070000 0x000061e7 0x000061e7 0.860017168254
.J 0x00077000 0x0006fbca 0x0006fbca 0.0988650196848
.UXAdns 0x000e7000 0x0006b988 0x0006b988 0.0567068628073
.data 0x00153000 0x00065274 0x00065274 2.63539603818
.jFpzOB 0x001b9000 0x0006228e 0x0006228e 0.0247831855366
.cmF 0x0021c000 0x00018dd1 0x00018dd1 0.200151858655
.rsrc 0x00235000 0x0001485c 0x0001485c 7.91117506861
.reloc 0x0024a000 0x000002b2 0x000002b2 6.47404692997

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x002353c8 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US Device independent bitmap graphic, 32 x 64 x 32, image size 4224
RT_DIALOG 0x00236470 0x00000044 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x00245b28 0x00003b00 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00249628 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0024963c 0x00000220 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library kernel32.dll:
0x470000 CompareFileTime
0x470004 GetVersion
0x470008 GetProcAddress
0x47000c FindResourceW
0x470010 CompareStringA
0x470014 HeapCreate
0x470018 lstrcatW
0x47001c RemoveDirectoryA
0x470020 LoadLibraryA
0x470024 SetComputerNameW
0x470028 RemoveDirectoryW
0x47002c lstrcpynW
0x470030 GlobalFindAtomW
0x470034 ExitProcess
0x470038 SetCalendarInfoA
Library USER32.DLL:
0x470040 GetMenuItemCount
0x470044 CharUpperA
0x470048 GetTopWindow
0x47004c GetDC
0x470050 GetDlgItemTextW
0x470054 UnregisterClassW
0x470058 LoadIconA
0x47005c CreateDesktopA
0x470060 FillRect
0x470064 GetCapture
0x470068 InsertMenuItemA
0x47006c GetMenuItemID
0x470070 GetClassLongW
0x470074 RegisterClassExW
Library gdi32.dll:
0x47007c SetDeviceGammaRamp
0x470080 UpdateICMRegKeyA
0x470084 GetPolyFillMode
0x470088 CreateRectRgn
0x47008c EnumFontFamiliesExW
0x470090 GetEnhMetaFileW
0x470098 MoveToEx
0x47009c UpdateColors
0x4700a4 GetCharWidth32W
0x4700a8 WidenPath
0x4700ac SetPixel
0x4700b0 GetKerningPairsA
0x4700b4 SetBkMode
0x4700bc CreateEnhMetaFileA
Library advapi32.dll:
0x4700c4 RegSaveKeyW
0x4700c8 RegEnumValueA
0x4700cc RegOpenKeyA
0x4700d0 RegQueryInfoKeyW
0x4700d4 RegOpenKeyExA
0x4700d8 RegDeleteValueW
Library SHELL32.DLL:
0x4700e0 SHGetFileInfoA
Library shlwapi.dll:
0x4700ec UrlCompareA
0x4700f0 SHOpenRegStreamW
0x4700f4 PathIsRootA
0x4700f8 StrRChrW
0x4700fc PathIsLFNFileSpecA
0x470100 PathIsRelativeA
0x470104 StrNCatA
0x470108 UrlCombineW
Library setupapi.dll:
0x470110 CM_Free_Res_Des
0x470114 SetupPromptForDiskW
0x470120 SetupDiSelectDevice
Library VERSION.DLL:
0x470128 VerInstallFileW
0x47012c GetFileVersionInfoW
0x470134 VerFindFileA
Library inetcomm.dll:
0x47013c CreateNNTPTransport
0x470148 HrSaveAttachmentAs
Library wsock32.dll:
0x470150 TransmitFile
0x470154 gethostname
0x47015c rcmd
0x470160 ntohl
0x470164 GetNameByTypeA
0x470168 s_perror
0x47016c setsockopt
0x470170 WSASetBlockingHook
0x470174 WSAAsyncSelect

!This program cannot be run in DOS mode.
.vjNlbf
@.kudd
`.kbVKK
.UXAdns
.jFpzOB
@.rsrc
@.reloc
PTZBPL@J
@VLH\T
HR@BHTV
XNZBXJTJRX&$4
0$ $2
$0&$$$
2"02&
"&46$&
& 42 6
4 6662
p&pPdd
AA@AA@
@AA@AA
@@@A@A
@A@AA@@@
@@H@H@H
@HH@HHH
221!012
Q@@PAQ
@HHHH@
@HHHHH@@H
5#'$%24#$
((0 0(0 (
( 0 800
SR@BQPSB
($ $($
$ ,,,
,$ (,((
$,($$(
Eda @dEa
`AAaaade
% a aE
DeAe@d$
$d@ ae!dd$EeeE%e
$E!$ead
$$daa@d
A`%`A`
Daa d Ae@@!%da!E@$d
@e@!EeD`
dE@Aed
eD%`d@!ad
EE%D Dd `DAE
DD@D@@
Gj%j4jKj
BjijNj%jTjHjPj{jMj:j
heL323
h21vM_W
YHPYYHAH
LF&f(lnD
hfN FDj
*DJ,fj"bhD"(HJ
b(BL(Fn
##!!'"''
!"" %!$$&
!!0 1!!10
!!1101
1100!
zC#Kz{!A
hK8Yc"
c3J#ZrK+P(*8K**[
1sC;8s
Jc1)09
S Cz@2
DHB.&&hdb@
hFBHl&
@Bh.fJ
Jh (nlN.*
`J`jn,L
J&`$h&(
HHFDDB
Ff`h,"(@@
Ld"HJNjd
B(j,@B,
JBD* `b
$&F,&,& &DDJnF"f(
:64:06
.<(,<6(
DDHNBJBBDJ
NNNDJ@
5!%!5$$
CompareFileTime
GetVersion
GetProcAddress
FindResourceW
CompareStringA
HeapCreate
lstrcatW
RemoveDirectoryA
LoadLibraryA
SetComputerNameW
RemoveDirectoryW
lstrcpynW
GlobalFindAtomW
ExitProcess
SetCalendarInfoA
kernel32.dll
GetMenuItemCount
CharUpperA
GetTopWindow
GetDlgItemTextW
UnregisterClassW
LoadIconA
CreateDesktopA
FillRect
GetCapture
InsertMenuItemA
GetMenuItemID
GetClassLongW
RegisterClassExW
USER32.DLL
SetDeviceGammaRamp
UpdateICMRegKeyA
GetPolyFillMode
CreateRectRgn
EnumFontFamiliesExW
GetEnhMetaFileW
RemoveFontResourceExA
MoveToEx
UpdateColors
GetAspectRatioFilterEx
GetCharWidth32W
WidenPath
SetPixel
GetKerningPairsA
SetBkMode
GetEnhMetaFileDescriptionA
CreateEnhMetaFileA
gdi32.dll
RegSaveKeyW
RegEnumValueA
RegOpenKeyA
RegQueryInfoKeyW
RegOpenKeyExA
RegDeleteValueW
advapi32.dll
SHGetFileInfoA
SHGetDataFromIDListA
SHELL32.DLL
UrlCompareA
SHOpenRegStreamW
PathIsRootA
StrRChrW
PathIsLFNFileSpecA
PathIsRelativeA
StrNCatA
UrlCombineW
shlwapi.dll
CM_Free_Res_Des
SetupPromptForDiskW
SetupDiCreateDeviceInfoW
SetupDiGetDeviceInstallParamsA
SetupDiSelectDevice
setupapi.dll
VerInstallFileW
GetFileVersionInfoW
GetFileVersionInfoSizeW
VerFindFileA
VERSION.DLL
CreateNNTPTransport
MimeOleUnEscapeStringInPlace
MimeOleCreateMessage
HrSaveAttachmentAs
inetcomm.dll
TransmitFile
gethostname
WSAAsyncGetHostByName
GetNameByTypeA
s_perror
setsockopt
WSASetBlockingHook
WSAAsyncSelect
wsock32.dll
FLR^RR
^B\@LP
VLV@L@
" #""
! #!
\|IE}!Iy%5X4
<Q]i1UhXH
98\qu1
8XqIhH
eE 1 Pt$iP4
=Y4t(L4$
M%eUA]
Xdi$1D
pM051-
P1"""""
!$$$!!
HZXBZB
ZXRHZr:"
R0pHb:
P(0brh
r"PP8PHz
xzb:J0Ph
b0jRp:
j*R2Xp
hhb*8p*J
B#qp`Cp3
BS!s 2rRpcQ3"#
r3r`Pq01Ap`
PS#P3@SC BB`b
RqS!@R!
3B"RqRssAH
H@AH@A@H
@HI@I@AH
I@AHAI
'"12=4*3;91804,"73&>
Pafenyk
Polofuc
(*,*&*:&@@&!5e~
:.>693%7,5&9%@?+8@'<
=+915"-<':&6:'%*7<$
2X*<7.16/#>+$&)K
@)'#%+,.+'97!\
$<*#3"6)72'<>59=&%11?"#48<=9;69(:&')&0&3>??&0($#/+=
1#<09"30126<,$<340,5,?3.75-@$-?>?96&/@)%7(%-:)K
Jesebaxiqedecato
Pafyxebawewelad
/=#&*/+"%6>46*+1
2@-:#;54+-3(;9)?=?/,93;$3"-03'791.:>7&3>4;88oxUu
.;-8>0$J
C;1<>&::9ML
751,>2
?(7.%Wekahapu
$%%(@4%#%+1Pyho
*6!4-:>B
'41.>)-*63%)%731.
DYc<8*>><>?-;,6%?>.6.48
,7>,#&"$;-(=*<)99;;%,*+:)*8:9):'=4$,"5.-6"#0&;4=/&:$;(=/4-Qiq
03@>;?+R
@+?!?)(,&,-9
Dugifozy
2$7!-8<;+*;K
<7+>++#!"60/8359.((.9%+"%"!7
p%3$";522$"#?=&94+@>#=!@!10Qahybupu
6&&1+"7#@,;=4%8>;!1q
>,53&+"919>*5<+)3:/5*,(8<7'0@@6-,5453
C'Kida
,%$;2$?;+;8</H
&?(:)></?)08(,1.*2+763<3
/"=.@,3>,@+2,5<0X
)*!0<@)965)
>2"),+:71,4,5781!5W
1@.4%:Jox
Rymyga
Kuvuneriqohe
@'%10:1)+
3##7/(&<3
Nagaduk
4/9959!3)8>+8@3<21$f
@@jbH`("jb(jb
b`BBh B
@Jb`j*
B* `(h
J (bj
*"BHbhBJB `*(hB
bA$AhH(
DAGBDDDB
@PRXBBH
XBXXHX
7!<)?(
|Z3"u(
pRWZ1F
s%?[q0A
dYo-4C
^y:gmsW
["dYC
=5\rzB)
dG'!d""
#FCBGB!
$a%F A
%$d#&fCADB#fe''
&EdF'dE
E`g$CEB$
!G@$"Gf
eFF&FCA@`&&DaGe!&&bf$
%`CeCF
#!!agg#%%GF
$ `E`C$
EBD&```#
&Ee@Fg
bg'&FD$GA
qyY(A h) )PyQIX
ap@H`P
p(1HHpa8x
@!Y`019H
Y)Xh@@@9
hIApX0)
Aq(@h@)(Q!
!I8X`Q
i)x p9
a((XipIy!
Y1Pq(y
APpix(( 8
00@ @
20!*02*#"
"""0)!88"8
H@@@@@
@HH@@H
@H@@@@
@@H@@H
H@@#A
"aC B`! Cc
C"#"b ""A
" " bB
@C`cbbc
cC !cc
"bAcCb@Ba!
"BB`A#
cC@!b@
"!aC#BCb``C
@cC#`A
b`#aCAc
!A!a"
CA`Ca A#
jBp":[
rACAsx
Bdf@ $
d@$DB$`f
D"" $B`$d&b
bF@@bD&$d$
$F $ "`
&$""df$
f`&@$BfF"`
DBb fF
BFB$"BD
d@&B$ $bf@d $D$&B DDf
F" Bf$ $B
DDbd@B@
@fb"$$@
"02 2"2
" 2
0 0 22
2"00
Q1*tmN
lJ]PF=
t>S]42O
F^lYr%
BCzB<V
R?SU#YbfZ
!*xeEN
5)aY#_
-B)x \p
:cy}"|
@[[vtO
s'NE)rT=
-pzRYg
:!o"kY
/DpL;E
O1e]E>}W
81EZ&v
?/nN;;+`
eYwo2{
Ul[z{W
flb$PrT~
zQ{?Oa^
9tw~@e(
?y[bX9
x8N$\|
_6X$.8
Z&{}]ZW
t1{aSDA
lh,,0^
nxB7!a
__^]+C
#D;YV|i
L=?AW"d~W
S/4>QKo
Fl)914
0)@S4-
m93>GN
PS?KN
BxtlQYf
Y6B*$e
#.)>l=
|qd[a7f(
rQHEFM
U]b#wp
5V_!'d
%6\\/x
3V}tm~w
r L;dY
6PUx\8
Ydx(Z1_p
m5KRO
-RPdSJ+O=
7A-[a$
>-0rP>H
6]Io3!
B|Nsj"
<l {+S
$ykMa*<C
F;q&;4h
P='Z[T
@,|hwl
Kk@#{fdN<
Eiwc{N
PawQtu
{MZyo-
u)<R
sxMyGeQ
nk?O~r
q0%RC_G
/n.feO?m
L?{%Xv
LBE&A!P
~3e|<D
pT8vH<
]KDR'M
M!SHBG4
}vc_DX
yy2ALK
Hg1$I`"
X s>Z=a/
1#_eQS
O:DO%Y
S[FR*v
F-1'wa
ZxdW,r
XBLf_)|6
`d8I]r0
ihhWnY
)2[F!b
BWhiqC
]/jHl2
%q;8\_
J!=(h
7L!m5,
Q,&HJ2o
P>a`oDZ
8:J*Q/U
\}5d;v
P ::eF
|)8i^a
LF$,|Qx
|S|m4*y
/c(*mJ
~~G38j
7`xYb8
{NyS5w
~${+c@
)!""lJR
ZZz:&Ask
R) _7\E=
I`K'65
@7V:bi
uQjVW7
uix-,Ai]
XW7&M
oT5vBn
Jg>e>i
ZQw4<+
~!Ditmi
Qe{hmE}
\}[f|&
|8t@9M
\]U?='
{x%2-m
m4ni?S
$|`&L-S>
kEjw>L
WB)<jq
1*doGw
'y5Up;6N7
p.;ArV
eVhfrj
T1*i2z4
Pdt)d
4kI+@F/
l~FeE)s
.781+;V
Guroqub
+3,2=-5$Quwepibisit
%!6!8465"5>
.;,8+#4(Jizeguhixuj
hMupoxat
0<()==1+"+8<%'1@.:6(5&@$
#Hyluto
Keqiba
<;#&?*41.?:,'7<1",WT
B_7DgO
&<:/.5"0*(#P
Xecowe
js"!9"P
'+?#(6)@.;;/Kukezaf
>252>:%23.9@7!<90N
[t,#@88<<=/&30';:7,.#1'&V
-<98*7"!)#-4F
44!>*?(&9>#@(6$?
#+,;.5440%$2%>8#8>C
;:3>0,:-68#!?(<#@@&
";#8%4@=>3.>$:B
Lavuzi
1&($94<='?73/1(.;+?27$#(:8$.7:@/?&2=*082;$2=(*"<;>;82)4!5@/2!>.5>6%17&6!)+2!&%"?>X
Miwozaty
Tuveryvij
Jaqexobud
8922-$:64%Dit
3!/43+0!:!1p
"1>;6$?)+>?)!.R
5@@<8-)972*9.9+"
Ropepojeguxu
Makowarusudijykoj
%4-)<>1,)0>5>/Nas
,@?6--?$"!#@9"6$".6
+79'<9&/"=9*!.H
n%bPUb!6
"0$$"+C
"?-,7?-$>('4#$?)2;
=r$'!%5:6&@70@"=$0151$\['&(7(57?5#1(:.,2087Xyn
Wewekeju
;?+1*;7.0>.,:-:"47')"%+8>74@Jegi
8";8:4@6(,337
gr"//250"8-4:&:
'.>@6.>,?+.=)#1;:&>"S
<&/'/+.8$*414+43289584%<;3
@^577::
4"*844),3,")?41'V
Gowydymixen
$!5,&>/528Qajex
Symydoqyfuji
a99:<-=8<&%-4';4Bobeca
-+.:1-?(#.(612?-88J
Padukiqyce
>%/$2+8:,#?(7'F
4@8#<H
Cikime
Carysu
Linuvapyduj
Fomatigirujuzagi
}x4Gytibe
764%$-6%61:"$8Vuwemej
:(*4502cR
>,6!(6566@7-=/:23.?-90#:~Tepove
Hegeru
!=.9-?@<0))>1!>?:$4*'!#1)%v_
()0<$"&&$4!$$"'930Zyqi
"&U\^`
"D _+c
/]gVoPY
'bxYyZ
&=V(At
<]4\[!
o'G^AOo
$k=!bY
>4Vpw2
9k;=*S
=0i1P6
62^sr>
6uIxzU
$$QAE,
}7o\$q
(lHJZPr
{{G2HP
+!820[
b7vFUI8
MFa%2o6q
W.:c@V
/+XSfD
W|guTtB
OS\4:x
OO{DYt
qXI&2S
pS+w{>
N6dMXZI
FGPkeD
I{p)gmS
fE43;cx
C[6IBa
DNpN!RX
Um8y)kU
j$gcx/
I}}[PAmP
5bI+COiWB
>:P>sH
r7"S\3j1R^
K'hF7:
v*uEDC
~,9#R<
bY4d'Y
ND~iBV<
sitb[Zv
{ 1Wa6
-dd7rr
po`~&
@.>4*|
;^HBB)
kxG^'w
1cy6i
iXlH{M
;~}FKl
'-mDC
x=)P$7mB7x
q"GxY)b_|
Q^[AdU
tSo^GW
Hlfsoh6
GGr)tK
V$T>Zq
{qxnOl
eL9B`[0
w9epAh*
Zje*!s
GGJMB$
iRL/^d
gBh,,z
\ZO,z?
a{lv'&
Mj,N!#
e&^EhZ
F%@NEa
Ew7>RA
%'*P9R^
PmB|l[
k6P^2#
5~i<Ua
ga&H$an
Wr!#
$sngF*
r+\FG<
DK/]>u!
hnnPAD3
J'4+A-#
XlDhak
ljRrpxx
QeiZV_
^V|\;2ku
f_m[k.
uHEL9Ens%
P>Y3Vl
0Q^!:
1a{{W0
W*8`^)pB5"
0WHVUDK
=Nt,"wc
2*?G5,
s*-%O,
J2D4T&
l)xR;y
0Zr[RB
}wMc8W
}YL+'5
JyerPIK
^9O):S
2z8>R1
-&NM>v>T
!g,}m%={
$sW!
51FU:F&
kS`g+[
k}rAF5'
kgndP_
x(9_{^
@(*j0
lAUei:O
bi+WAa
E{&{^z+.b(p;Y<4
Y;?aEK+
YQ=VCnCd
JU8H/#;
!]YyJa
:;Cpw"|
9|27ob
@ur12q
fXHC!$e?
w)ML<e@
GEX%;L
5*=Neu
tt%\JJ
wAnR>j
/"5~3T
Ixguxa
)!'2'l
9B}VQ#
s3[<-f
?Mjs?q
KAu43u
U,yfjp.G
|i=oLk
}%PDyD
V[tK9;
Gh<#oaS
u>L pt
1<t D}.I:
XMI1Qy
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
4090i0n0t0}0
1-1:1M1S1x1~1
2!2-2@2T2k2
5#5)5`5
66J6[6a6
8>8G8M8j8
==M=a=n=|=
>&>=>C>W>y>
?6?P?V?q?w?
;0Z0g0
1$11171
5"4@4a4f4k4|4
616A6S6
7'767P7Z7a7v7
5#5*5u8
9%9R9f9k9r9w9}9
4#:):1:7:B:I:k:y:
;%;;;M;
?/0J0o0
2+262d2
jjjjjjjjjjh
jjjjjjjjjj
Zapode
Tehopat
Kajuqa
aDexyr
qSepuxywe
jMyrol
Jikawup
oCymal
Vadubi
bFonoly
Vovoxe
Ruvihy
Xugase
Curewep
Zivywur
Jycuda
Sojolek
xQohaz
Jakata
Paqowyfe
GQKQGMLSLXAXDVZIKJD
AZAZAQAEATAWACAR
BOBGBPBHBM
CCCJCQCRCBCLCNCN
DGDJDRDCDNDH
EVEREZELESEM
FZFAFXFKFMFH
GYGBGIGEGM
HGHXHLHOHOHT(
kpk(qc5
Verdana
VS_VERSION_INFO
StringFileInfo
000004b0
FileVersion
9.7.6.1
ProductVersion
3.1.6.5
FileDescription
anticipation
CompanyName
ArcaBit
LegalCopyright
monerozoan
ProductName
Hoggish
VarFileInfo
Translation
No antivirus signatures available.
IRMA Signature
Trend Micro SProtect (Linux) Clean
Avast Core Security (Linux) Win32:Zbot-NIZ [Trj]
C4S ClamAV (Linux) Clean
Trellix (Linux) Clean
Sophos Anti-Virus (Linux) Clean
Bitdefender Antivirus (Linux) Gen:Variant.Babar.692152
G Data Antivirus (Windows) Virus: Gen:Variant.Babar.692152 (Engine A)
WithSecure (Linux) Clean
ESET Security (Windows) a variant of Win32/GenKryptik.HMUN trojan
DrWeb Antivirus (Linux) Trojan.PWS.Ibank.323
ClamAV (Linux) Clean
eScan Antivirus (Linux) Gen:Variant.Babar.692152(DB)
Kaspersky Standard (Windows) Backdoor.Win32.Shiz.raj
Emsisoft Commandline Scanner (Windows) Gen:Variant.Babar.692152 (B)
Cuckoo

We're processing your submission... This could take a few seconds.