Static | ZeroBOX

PE Compile Time

2010-02-01 21:19:51

PDB Path

c:\LotMiss\wavedog\FarFood\Strong.pdb

PE Imphash

3c45c2eae973252af425589125584d7a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00048f75 0x00049000 6.07456629444
.rdata 0x0004a000 0x0000fc94 0x0000fe00 5.7930723317
.data 0x0005a000 0x0000f7fc 0x00000e00 3.07749367803
.rsrc 0x0006a000 0x0002a660 0x0002a800 3.17695280812
.reloc 0x00095000 0x00002022 0x00002200 4.41785380715

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00094180 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000945e8 0x00000076 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0006a280 0x0000038c LANG_ENGLISH SUBLANG_ENGLISH_US PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x0006a610 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library USER32.dll:
0x104a110 CreateWindowExA
0x104a114 SetMenuItemInfoA
0x104a118 GetMenu
0x104a11c SetWindowLongA
0x104a120 IsWindow
0x104a124 SetScrollInfo
0x104a128 LoadIconA
0x104a12c GetSysColor
0x104a130 CallWindowProcA
Library ole32.dll:
0x104a154 CoCreateInstance
0x104a158 CoUninitialize
0x104a15c CoInitialize
0x104a160 CoTaskMemFree
0x104a164 CoTaskMemAlloc
Library KERNEL32.dll:
0x104a000 InterlockedIncrement
0x104a004 CompareStringW
0x104a008 CompareStringA
0x104a00c GetLocaleInfoA
0x104a010 GetStringTypeW
0x104a014 GetStringTypeA
0x104a018 LCMapStringW
0x104a01c MultiByteToWideChar
0x104a020 LCMapStringA
0x104a028 WaitForSingleObject
0x104a02c LoadLibraryA
0x104a030 TlsGetValue
0x104a034 TlsAlloc
0x104a038 VirtualProtect
0x104a03c Sleep
0x104a044 GetSystemDirectoryA
0x104a048 HeapSize
0x104a04c IsValidCodePage
0x104a050 GetOEMCP
0x104a054 GetACP
0x104a05c RaiseException
0x104a060 RtlUnwind
0x104a064 GetCurrentThreadId
0x104a068 GetCommandLineA
0x104a06c HeapAlloc
0x104a070 GetLastError
0x104a074 HeapFree
0x104a078 TerminateProcess
0x104a07c GetCurrentProcess
0x104a088 IsDebuggerPresent
0x104a08c WideCharToMultiByte
0x104a094 GetModuleHandleW
0x104a098 GetProcAddress
0x104a09c TlsSetValue
0x104a0a0 TlsFree
0x104a0a8 SetLastError
0x104a0ac InterlockedDecrement
0x104a0b0 ExitProcess
0x104a0b4 SetHandleCount
0x104a0b8 GetStdHandle
0x104a0bc GetFileType
0x104a0c0 GetStartupInfoA
0x104a0c4 DeleteCriticalSection
0x104a0c8 GetModuleFileNameA
0x104a0d0 GetEnvironmentStrings
0x104a0dc HeapCreate
0x104a0e0 HeapDestroy
0x104a0e4 VirtualFree
0x104a0ec GetTickCount
0x104a0f0 GetCurrentProcessId
0x104a0f4 LeaveCriticalSection
0x104a0f8 EnterCriticalSection
0x104a0fc VirtualAlloc
0x104a100 HeapReAlloc
0x104a104 WriteFile
0x104a108 GetCPInfo
Library dhcpcsvc.DLL:
0x104a140 DhcpCApiInitialize
0x104a144 DhcpCApiCleanup
0x104a14c DhcpRequestParams

Exports

Ordinal Address Name
1 0x103f4b0 DllRegisterServer
2 0x103f5b0 Methodhour
!This program cannot be run in DOS mode.
Rich8u?
`.rdata
@.data
@.reloc
Z{{Xr{tj
kV@rj9
+h=;xv
Fat+Zr
'_3:DE
Z)~lU!
Y&A_1^
/zy\~nDg
i|Banji
SM[nmh
_&C_lE>
\U4:nrC
8wUDbj
<{Q-,J
jR&[H[
+^cwCKZ&
'xSl.b
(9{*?r
0{-"?mL
8bbO<|
J_M/eJ
Z4.:'9
;^iqy-yREO
0e_{~:~
*),YT:6
4,Gf6$
K8~|rq<+
/(nj,1!
^[UNT?
<<A(d4OJi
ZeeWg
rM{ckR
,H0|9*
T6jn-z
.)/;z-
V?1v67
l%:x*h
S9&i2Z
[<UT{i
D=q?J,x
CEmG8?8
rPR=/
oJ,,3o
&{y~62
[{AZ]1Sh
(Rw/>'
(&Jz[8
+P^^XNu
O_GE&Y
,*6U8v
)6=on`{J.
uLf;'{]
{g'z2=
_gzknn,
k}/;V>p
wnu"ye
2E:KJ_
zsXVvU
,4qan|
<4>:IF
DO*6e~
P*>7hd
wi_bYc
=5?*X
X;*IMI
PG/WFr
,Q^U1{
AZ6]Mh
Un^"$*
RCxKk&,ki:l
RSD/~
hE_HBC-_
ZvVR0_?
}&nZ7b
OrmW1}
K_15_4
|/`%HR
i>/S`4
UrAHCSM
"5kT^:"
_E2L2k42
<29E4h
sgQ+Nu
*.ytnC
{r9`36
X/w--J
^2PtjB
N31,
:|XSXr
=r<.=
cWV32I
NrFFo2
E&2&cmE6
E5\_&y
r3g,171
\r[^Er
mV?m4u
!7;Qjm
|@Sz~W;
:tlR_3
P%=]b3zo
1QNs0QK
T]kbij
9`^lZ:
n2EWG2,
'H__Ez
B2 V4R
xkKXI?E
(zmCn=
[v8YtU
/3Hr4Y
U",l67
cNDS*>
!Nvx~#}
ok>Q2S
AQ:}9%4
%j[l8&',
(E4@FEHm
"HwV<I/.
o7u%1E
148NW]4
l7J:$;<Gg>
:VP*cIh
xv[W7*Z
S^EZT_
E{%?!4
4>m\K@8
dZC7 c
)Lk~Jw
p&$L^j
iQQEcdL
19[smfO
k}|v)cw
e4HGGH
rfqi0.
poN_1u
-[,M<\
93ug,fk
pEFj_f"&
]Zy+,U
]_5en9<
@Bd>3/
+}dBo
E=m"/r
k*Y%2a=e
hUz11v
a:|@R|
6P;G0j]w
F}BCv6
p'>W&J
iD:CHf
'Qe)"l/
71?Y^qg
"rKM=3/
;}MF:.
:l_E2_4
Ok>%y6;B
{*\bh_?X
)\;rmcR
hC_C=E
,,7oCK&
yD:zq?
x}{)+Rm
/keq<Yx
:,CR;k
W_4EPjMG
&)X]om
=l.hlOhm
+MAIKI>
A5bi24
qz*'.P
KttsiZ
Ckh]k2j
EU2EQ!
h&&5c&4
JEF3_+
_r=E_V
c+l&//bm%
sYJ2}m<
jSs*A\
BEKVem
M^D,::%
0gjo?> u
tI="HGv~
z[h?U]r
lKc|H<
[hyD$/
Y|jbwh
w^T+(Q
w1j[/<K3
zBv`i@
qj-VY_2
NIY:|,
{y^mzO
:8z6vo3{/
vs?j{R.t
"wExrn
F&j2Z?y;wv.rn
}9sr=
Em`gX<{
zr,c=[@
_hCFba
;w>a6={
C)5yo|
}13?in
D#nq:x7
W'|fn?
p8j\b:
wA=W'y
QiG<5A
Sf"o2>
(s}Vli
,i6WE*Zc
hSE3TZaT
C(P8h:
fkR2)p
}!}26
9n[.ht
T7F}R_
_4:[\]
rs[xjk
voM(iq\
[m"v;y
EYEhS/E
5E<kDL
:oV'V[
b|;{(}
Hrl(z.
{B;A2e
cn<x?EQ;
Sd(qgq
yjS8_*
42-c2V_
~b6E'_
9/_,_'
1RX)"
=xN;7`
4_G_EEB
+tLR{V
Ii2~0K
J2S44&
C6cd4)z
R<~uZV
z:N\Zi1
G329WU
6n+4GO
}6:}|<R
ohe4N7|_
t/8]y7
DuE_jE4'
R)m2cE
Ea2:UR
_V45Ci
gDxUOD
'bNM74
,Cl2EV
4EcC:a
FVPZOq
5}`'E.d
5cE4iEDG\
)__X4&\]y
F_224E
Q._zMq
EaUJMB
E:GrO4
c4_6nF
0SWX3&
4E9KT_W2n
&4_GqU
b42Ev(
IFmpFW
W'E4E+
EFr.DE-
UFs9TF
WX:G4&
hSMX.i
4C)em[
Es_99_
es'1_(
/DM5TT
T[EE_n
0WWWWW
0WWWWW
^SSSSS
^SSSSS
^WWWWW
^WWWWW
QQSVWd
0SSSSS
>:u8FV
VVVVVQRSSj
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
j@j ^V
>=Yt1j
URPQQh
0SSSSS
0A@@Ju
;t$,v-
UQPXY]Y[
0SSSSS
t"SS9]
PPPPPPPP
PPPPPPPP
t+WWVPV
bad allocation
6"}_xE}
pk=14A|
$2JFWn
}5|-=+F
$9*"+r
8(YP8{
@@42Et
>AE|E6
oZ&'1_
IEED<c4
5YjUCM
(m,]2?EBm
&EHEXF
E'26E7
-62cE4|E
JQ(>F[
>2&&IN
~}*Q1+d
`^f~tb
~9{Xq!
x>=EuZ
4&A44O
Jnad89
D\vFb>p
$5S)@2y.|
|A7~Mvo
`HE9^j
E)jO_1
ym'Z22
9n$2Pl>
wfu5|s
"y"e2p
C/>hfb
U=V.i)
:'J&Y
FN5^4;Hv:
g),x[b
zQF(#D8Gmc5W
JyB>6/&z
;xLO8Xk
2WXQHE
F9H;43
/<C=EE
*5M4Ai
P1dv:P
P2pw#qF
;9E4E`
$UyZx6
YJa:y7
CTDPyaG0
#4=y44
EEIM@&
yTT_B5
1emkIh
h Z(Ct
o=lYSy
??xbyX\@
r!4C>S
K62UHI-<
/h8Yz.
26745n
)(fg>d
ZI'~w.{
E42EE=
;\v>bT
=~YXj4
y0\*cD
c5JK^4
EGb/2_
lSVXzc
@B>C/A
wrKV4L
0rE1Bu
$buCq?
;O7j'B
0fG!(q
fMqJ|!
p6UEF5
o'WEO7
L_I5g(8
q98_^E
\EFRJQi
CG5OGV_
_HX9E38&EPg.
4aQ\cl
2`2N\K
bad allocation
string too long
invalid string position
Unknown exception
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
c:\LotMiss\wavedog\FarFood\Strong.pdb
CreateWindowExA
LoadIconA
GetSysColor
SetScrollInfo
IsWindow
SetWindowLongA
CallWindowProcA
SetMenuItemInfoA
GetMenu
USER32.dll
CoTaskMemAlloc
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoInitialize
ole32.dll
WaitForSingleObject
LoadLibraryA
TlsGetValue
TlsAlloc
VirtualProtect
GetEnvironmentVariableA
GetSystemDirectoryA
KERNEL32.dll
DhcpRequestParams
DhcpRemoveDNSRegistrations
DhcpRegisterParamChange
DhcpDeRegisterParamChange
DhcpCApiInitialize
DhcpCApiCleanup
dhcpcsvc.DLL
GetSystemTimeAsFileTime
RaiseException
RtlUnwind
GetCurrentThreadId
GetCommandLineA
HeapAlloc
GetLastError
HeapFree
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
WideCharToMultiByte
GetTimeZoneInformation
GetModuleHandleW
GetProcAddress
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
InterlockedDecrement
ExitProcess
SetHandleCount
GetStdHandle
GetFileType
GetStartupInfoA
DeleteCriticalSection
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
HeapCreate
HeapDestroy
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
LeaveCriticalSection
EnterCriticalSection
VirtualAlloc
HeapReAlloc
WriteFile
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapSize
InitializeCriticalSectionAndSpinCount
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
CompareStringA
CompareStringW
SetEnvironmentVariableA
Strong.dll
DllRegisterServer
Methodhour
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
f"*b-$
$QLMMcbb
zb"!brr
%`"PL
B,BQ,;
PIFf2Zt
^(y|"a
w/fffj
K bC<!c
(^=eU
PJaUZp
w)Gww7
5`+!$R
{:@JD:~
{n.^FK,
ur82Nq
Bn('NF
PJG)0Ld
pG5G\0
`-'{<.tt(
P ""
P ""
 ""
0 ""
0 ""
0 ""
""p!##
0!##
 !##
@!##
@!##
0!##
P!##
0!##
@!##
""`!##
""p!##
@ ""
""` ""
0 !!
""p
0!!
""p
0""`!!
P
!!c!!
-!!
 G!!
 S!!
 Q!!
 ?!!
$!!
I!!
/!!
 D!!
 n!!
!!k!!
 ?!!
 <!!
!!= Y!!n!!|!!
!!z!!l U
 )!!
!!l!!
3!!
 D!!
 %!!
!!t
!!R!!
!!}!!K
 A!!
!!}!!
!!n!!
!!_!!
##2!!
f!""
9
P ""
 ""`!!
""`
""` ""
3#3'3-31373;3@3E3K3Q3W3]3b3g3m3s3y3
4!4&4+41474=4C4H4M4S4Y4s4{4
5-535;5Q5k5}5
6!6,62686C6a6n6t6
7787@7H7[7k7
8$8.838A8H8O8U8c8i8y8
9!909F9S9Y9_9f9l9s9z9
:!:(:1:6:=:C:N:V:\:b:m:s:
;';-;3;>;D;R;Y;f;l;u;
<!<&<4<:<@<[<h<n<z<
=#=0=6=<=C=I=P=W=]=k=p=
>)>7>F>T>Z>j>x>
?!?-?2?A?I?V?[?e?o?t?z?
0"00080@0F0S0Y0_0f0l0s0z0
1"10151;1G1M1\1d1q1w1
2!2(20252C2I2d2j2v2|2
3#3-343;3B3M3V3\3c3k3r3~3
4#4)4?4H4X4_4r4w4
525=5E5K5b5y5
626G6U6c6p6{6
787A7I7c7l7v7~7
8(858;8A8G8U8x8~8
9&9,949B9G9U9\9m9s9|9
:":(:B:Y:e:y:
; ;&;1;C;I;T;j;~;
<%<=<X<b<p<v<
=%=,=6=F=L=U=`=r=
>>3>W>_>j>
? ?&?3?Y?g?s?
0%0+070<0I0X0^0h0
1.1;1G1]1s1~1
2'212A2I2O2T2`2g2u2
3)323G3M3R3Y3_3|3
4'424B4X4^4o4~4
5+565D5O5U5Z5`5e5k5w5
6$6*636:6A6T6c6i6s6
7!7'7-73797?7G7N7T7d7i7
8 8&8@8H8P8a8g8m8~8
9$9/9:9@9H9M9S9g9s9
:':B:N:[:a:g:s:y:
;(;5;>;
L2R2X2^2d2j2q2
3#3R3_3r3
3-4Q4v4
=;>H>x>~>
2.333=3q3
3.4J4b4
:3:Q:X:\:`:d:h:l:p:t:
:6;A;\;c;h;l;p;
<Z<`<d<h<l<
=>;>^>
?-?S?q?x?|?
V0a0|0
1 1$1(1,101z1
3:3K3P3V3g3l3y3
7(70767<7
8%8.8<8J8
9 9-9@9M9o9_;f;
>.?7?C?|?
030:0N0U0|0
1$101>1D1P1V1c1m1t1
2M2S2}2
4 4&42484H4N4c4q4|4
5!5&555K5V5[5f5k5v5{5
161C1A354
4(5.545:5@5F5M5T5[5b5i5p5w5
60696f6
7 737>7C7S7]7d7o7x7
7,898c8h8s8x8
8"9/989L9m9s9
:D:N:v:
; <*<z<
<^>o>w>}>
?2?>?K?R?
060E0J0k0p0
11%1+1M1
4!5)595@5J5t5
609>9D9^9c9r9{9
:(:/:C:J:P:^:e:j:s:
2:2C2J2S2
353G3k3
:^:d:p:
<?<s<y<
<p=5>_>
33)3q3y3
737O7X7^7g7l7{7
7"8e8k8
;f<k<p<u<
=S=X=_=d=k=p=
0#010q0
0^1e1k1g4n4
5G6Y6f6r6|6
90:::R:Y:c:k:x:
>">4>F>X>j>|>
0%0.0:0D0P0[0
?=?X?c?g?l?
X1\1`1t1x1|1
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0
; ;0;4;8;@;X;\;t;
<(<8<<<L<P<T<X<`<x<
= =l=t=|=
>0>D>L>X>x>
?0?8?D?t?x?
080X0d0
1$10181h1p1t1
2$2(2H2d2h2
3(3H3h3
14181<1`1l1
6$6,646<6D6L6T6\6d6p6
7<7H7L7P7T7X7`7d7
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Figure cotton Corporation
FileDescription
Figure cotton Glad sleep
FileVersion
0.5.1.143
InternalName
Last magnet
LegalCopyright
Figure cotton Corporation. All rights reserved
OriginalFilename
Strong.dll Happendone
ProductVersion
0.5.1.143
ProductName
Figure cotton
Glad sleep
Industry
188711
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.164551e24aa4d9ad
CAT-QuickHeal Trojan.Multi
Qihoo-360 Win32/Trojan.Generic.HgkASQAA
McAfee RDN/Dridex
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Trojan.Win32.Cridex.a!c
Sangfor Trojan.Win32.Cridex.gen
K7AntiVirus Trojan ( 005789a61 )
BitDefender Gen:Variant.Zusy.369718
K7GW Trojan ( 005789a61 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
Cyren W32/Trojan.DJSJ-0808
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HJSK
Baidu Clean
APEX Clean
Avast Win32:Malware-gen
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.Win32.Cridex.gen
Alibaba TrojanDownloader:Win32/Dridex.2d1add29
NANO-Antivirus Trojan.Win32.Cridex.intxuh
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.369718
Rising Downloader.Cridex!8.F70 (CLOUD)
Ad-Aware Gen:Variant.Zusy.369718
Emsisoft Trojan.Agent (A)
Comodo Malware@#2jd0bsf6spf1w
F-Secure Clean
DrWeb Trojan.Dridex.735
Zillya Trojan.Kryptik.Win32.2923328
TrendMicro TROJ_FRS.0NA103C321
McAfee-GW-Edition RDN/Dridex
CMC Clean
Sophos Mal/Generic-R + Troj/Dridex-AFA
SentinelOne Clean
GData Gen:Variant.Zusy.369718
Jiangmin TrojanDownloader.Cridex.aeh
Webroot W32.Malware.Gen
Avira TR/AD.Dridex.onksh
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Downloader.oa
Arcabit Trojan.Zusy.D5A436
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Dridex.NS!MTB
AhnLab-V3 Malware/Gen.Reputation.C4357419
Acronis Clean
VBA32 TrojanDownloader.Cridex
ALYac Gen:Variant.Zusy.369718
TACHYON Clean
Malwarebytes Trojan.Crypt
Panda Trj/RnkBend.A
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103C321
Tencent Malware.Win32.Gencirc.11bb2dde
Yandex Trojan.Kryptik!nDWliVXQtYA
Ikarus Trojan.Win32.Crypt
eGambit Clean
Fortinet W32/PossibleThreat
AVG Win32:Malware-gen
Paloalto generic.ml
MaxSecure Trojan.Malware.74221143.susgen
No IRMA results available.