Static | ZeroBOX

PE Compile Time

2021-04-05 23:21:59

PE Imphash

2715a19d1d4a50604e0ace50d5e16153

PEiD Signatures

Ste@lth PE 1.01 -> BGCorp

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00009c38 0x0000a000 5.66646938155
.rdata 0x0000b000 0x00000fd7 0x00001000 1.51756171722
.pdata 0x0000c000 0x00020f43 0x0001f000 7.82913974532
.rsrc 0x0002d000 0x00006c10 0x00007000 6.32673969755
.reloc 0x00034000 0x00000138 0x00001000 0.724428833369

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00032c90 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00032c90 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00032c90 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00032c90 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x00032c90 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000330f8 0x0000004c LANG_NEUTRAL SUBLANG_DEFAULT data
RT_VERSION 0x00033148 0x00000964 LANG_NEUTRAL SUBLANG_SYS_DEFAULT data
RT_MANIFEST 0x00033ab0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library GDI32.dll:
0x40b00c OffsetClipRgn
Library USER32.dll:
0x40b030 GetMenuState
0x40b034 EnumDisplayDevicesW
0x40b038 TranslateMessage
0x40b03c DragDetect
Library WINTRUST.dll:
Library ADVAPI32.dll:
0x40b000 RegLoadAppKeyW
Library KERNEL32.dll:
0x40b018 CloseHandle
0x40b01c OutputDebugStringA
0x40b020 LoadLibraryA
0x40b024 LoadLibraryW
0x40b028 GetPriorityClass

`.rdata
@.pdata
@.reloc
\$'2\$'
L$H9D$
D$O"D$O
a<[R,9
y,7'>S
(~0LgP
S,g<dF
]R,g,`B
!t"Y/v<
{;D$`t
\$>f3\$>f
N<+D$8
D$4#D$4
t$.f3t$.
D$<:\$+
jR+D$,f
D$T%*&
LdrGetProcedureA
RSDSeg'
Gsp.pdb
OffsetClipRgn
GDI32.dll
DragDetect
GetMenuState
EnumDisplayDevicesW
TranslateMessage
USER32.dll
CryptCATAdminCalcHashFromFileHandle
WINTRUST.dll
CloseEncryptedFileRaw
RegLoadAppKeyW
ADVAPI32.dll
GetSystemDefaultUILanguage
GetPriorityClass
LoadLibraryW
LoadLibraryA
OutputDebugStringA
CloseHandle
KERNEL32.dll
_Pk'km
|~dW(k
|KPk'km
7q&u@N
|~Pk'k
'4})oC
W2Bnwv
uM!u$zL
dk)zTu
$2u-9K
$6-,9S
<[RH7
1t">~8!
VH<t?g
`&1gL}
.wN-F\R
R,8<#>
t"m?u!
?<[Q`]
t&9g|><[
'Q##m9I
"!)yxQS
v'DC<'9
i$.M,9U
$rb-9UK
g$.L,9U
!'Mx!
R,8<#>
4TQ+8<#
R,8<#F
H`7S,9
OI18s
(`OR,9
eP`#S,9UK
8`/S,9
(`/R,9
X`WR,9
(`;R,9
%*S,9U
$J',9S
Q#m9U
bA_"m9
Pn9~8!
nc?[R,9#
(`oT,9
[\jvx5
'8@5^L
\Q+82?&k
B=-mUk
0[R,8<#B
`#R,9G
;1.>~j
(`_S,9
<[R,!wp
j9<[R,
P=S/Sx
@P+8UK
,9Q'YM
\Jzy^P
s'MT7S
[R,!+a
\R,DL#f
< `oS,92O[
\R,8|#f
!'1xE
<[R,92
ON<[Rrt|#N
f=g@<[
S'TpS~eo
#^,DRP
slkv'5
PR,9SC
#!*)x%
#!*Ix)
B@I"[q
$ro,9S
;]S,9<
;]S,9<
$6|,9U
`sR,9Q{
$bR,9S
slkr'5
G<[R_&
NAF[R;
&<AYX9
tLN1<[R
$vR,9.:
$nO+8S
B+-m/f
~W<]R,
t|4}; tB
$>Q+8SC
)-5XuZ
,9 WYI
%Z,DVP
>2=-mV
#^,DRP
$Nml[R
NPH~g,
$f1+8M
;ijz2V:
gc|cU,9
j$R'+8U
8=[R,9
n?u!VWQ+"m
@,<~8<#
'xx?g
$B0+8UK
?S,9SC
u *[R,
z'yw$m9
(`cS,9
%IR,9SD
,3Q+![
9t6tN
V}L`*[
BYgL];Z
$N?+8M
FBia'U
/,.>~j
g,T;Z:
<#2:1z4Q
X@<2t@
MO[KDv
GQnnOf
/,]Rz%hO
:[S,9D
6Z}[E;
"5x4^)
HG3_
$zK+8M
eTE[T,
1tB>~<%CFV_
4g8i;Z
8GL~e'
cC[R,9
&Pt/4}
ZQ|8<#
nuu+JZQ+""
[l7&ks
Bi5^ +
>ZoDH]r
jN=FT^
8'=~e'
8SM~e
6%5pn.
[cjwx=1
"BgDI;Z
#^,DRP
:9PP%C
tnn?u
<[=9vnd
~> ldi'
}:[R,t4#
y2R,9<#
OQVPY<
-`4LE(
_l/$cA
+Ml'$}P
9#n^N.
~?+b\ZFC
$^g080
nQ7TWH
Qc5h? \
BTwkl}N
Z*~Qy6
-zjk^T{A
yE Sx.
5 #+fi
2TB;)1
Dpx$Zpx%Ar
u(X&hV.
23B;)q
lr2DB;)
e_-lD]
`2GB;)
self.ex
wB*v=,C23
`x:v=LE
n Nku1
?JI<HD
0v<d\y
oM='<6
FOU~^.
$M:[h/
D!<..$B
326IU&
{MsOZB
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
9H:P:V:
;I;`;i;o;
92:>:r:~:
;);D;Z;x;
<!<C<O<
D3S3Y3
ntdll.dl
--s--pp----
VS_VERSION_INFO
StringFileInfo
080004b0
Comments
CompanyName
Avira GmbH
FileDescription
Configuration Panel
FileVersion
87.20.00.00
InternalName
Olhjeaaeltldf Rsiot
LegalCopyright
Copyright
2000 - 2010 Avira GmbH. All rights reserved.
LegalTrademarks
AntiVir
is a registered trademark of Avira GmbH, Germany.
OriginalFilename
olhjeaae.exe
PrivateBuild
ProductName
OlhjEaa Ltldfqr
ProductVersion
87.20.00.00
SpecialBuild
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.3be35148cc6c8099
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren W32/Dridex.CF.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Avast Win32:Evo-gen [Susp]
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Trojan.Dridex!1.D4AE (CLASSIC)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Drixed.dc
MaxSecure Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Dridex!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!3BE35148CC6C
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Banker.Dridex
eGambit Unsafe.AI_Score_71%
Fortinet Clean
BitDefenderTheta Gen:NN.ZedlaF.34670.mu8@aS1mr0oO
AVG Win32:Evo-gen [Susp]
Paloalto Clean
Qihoo-360 HEUR/QVM40.1.62DF.Malware.Gen
No IRMA results available.