Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

44d1d3622a1f568fe5a4988612a1b8da

PEiD Signatures

Feokt

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
Feokt. 0x00001000 0x00027000 0x0001ec00 7.97927929674
.rsrc 0x00028000 0x00000200 0x00000200 2.50473907299

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000280a0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000281c8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library KERNEL32.DLL:
0x401100 ExitProcess
0x401104 GetModuleHandleA
0x401108 GetProcAddress
0x40110c LoadLibraryA
Library USER32.DLL:
0x40111c MessageBoxA

!Sorry, for Win32... :(
Feokt.
KERNEL32.DLL
USER32.DLL
ExitProcess
GetModuleHandleA
GetProcAddress
LoadLibraryA
MessageBoxA
**Error. Can't load dll library
**Error. Can't find function in dll library
kernel32.dll
GetProcessHeap
HeapAlloc
HeapFree
HeapCompact
c{:+XRN
A'.R(f
Cjl$49fw
dXNk[Lh
Gp6_]04
%xp'`S8
'!T;9i,
7ytu>w
wx'aGqB
=9PWyW
LBPbs"4
,xcOXa81
G1&NrI
7{+:vQa
.r_gyE
uninst.exe
httpdesc.m
licee.txtV
FMform
BUTTON
I agree with is ,nd cpt ems.
Target:
STATIC
Upda tryn mauAdto rtupNT ServmouTvsiohana. Tssyc nowAftngccdelsr
[CGrp("SmHTTP")]
[Sh,1I%s\ "DripL1
PROGMAN
cfg.lnk
'tfile
May bpu ?
Cloag.
=;Arun
up %Xd
open SCMSOFTWARE\Microsoft\WindowCurrV\Run8
SeMage
DdeInitializ
konn[Tr
PostQu
GetEnab
Textkwsptf
[;Botroy
sorRegerCl
{[IsDog
32.dSleepDFRemovroryK
+_l_hwr
GbalAocLkUnF
leLastTimhdEx
knelStObjdc))
gdiSHBwFldPathFmIDLSp
l{VueKeyCfig
advap[mmLMZ
LSor, :(
,,Feokt.
KERNELDLL
ddrLibra
**. l fun
USH_PAAresu?
Dow %s*.*Dj
`P.rsrc|
<|;(gN>EAZxo0+)
Lp|NU9
&'>!TT
Z4;&I4
B\{.Gj
SJQL G
2Ny]|l
{)#@d>
LSN fM
Tb^QwYU
oiioWq
R&Ev 0
Z3Gm~{
Z]+K^*R$
84AG{B:
w80rX^
eX'6BiS
m=kK:_
ZQ`Hza
c}7:((
}f:QsM
('R[=\
?b?GkJ
*6%{B0''[
ys%xuKZF15
2ln2dCi
WP|ILe
+CCH_<2
_#Cu+Z
*r3zO!
JS04s H
;,OIMS
kn,a=}
z!lym61
kJp2'*1
d&6w+}
IFZWi`h;
5M^hnj
s>F(2bI
(Y:<9
jH+bLhk
tq1.s/
Gr?FW6
v;a6eCJ
.>hU2Q
WQz0w3m
JrY~0m
ew|aC
)+i,n^Se
3i.4D:
288];w
ix02k`
{\@VbI
%U.C'V
]<YhfC
IInHX}
zMu74
T!(3ek
bie__,
ZC2|pOTMf
u>gWk{
lhDK"B.JY@
B$T*6Y
\.&6_^
?G8ilL=
x]E"e[K
xA?EFb
i_H)*m"
Rxk}F<
#97$W9b&Q
uh%L*6
8&::!Bl&
r6XBi.E
^aLf*a
A )*3C
MPNHgH
`f,`V{>H
y+0UIo\
/US{V{
O90I%bj
k8JhL>
0rA6Dp]C+
gj99!`
<iiI;
=8r+Y'
uF??K!:{'+
okYdg1n
~"`pyh
>/P#kB,
MT2!m=E
gC><.\
>Nj?Nh&7
0!n%0
>QW.k%
atnhEe+g
f9=B^jZ2*
yCeo{#
GFs,r?z^Ym
kM?_"N3
7VpLdL
G25dJ}
<R9()o
M.~/Vf
f'KY>7
o%8,$T
_g8^x2
T3K5s
<|3iRo
$nw-I4HRKJ
^Jxy(J
qSx$O.
O0.zWY
8wh,YP
D+!/aV
3If=~r-H
u&Dj#Px
czawZm
kgaV>
J6<UO9
HrA1d`gj
RC*+6>
!L/h!9
.hT#JL
+0Nd$'
!fa7Wf
}C#qWKE|v
0{1R:[
z/0.SKl
s.-ok=/
5OQQHw(
bhc$H&
>.u' 2#Yav
n d';i
(h27huXKg6
PgTrm
ErZ@8Y
5UeB?p
9:e>aAg
]9:6;0*O
5g}l{u5
s_8_x~
aZN@t]
GjkHW9
NXf^:W
*7t`b:
bN}HS7
xI6c|%
g/4lC0
:mnK,1-_i
D*6&|6
g~jcQM
@rrM$nF
0.RLG^
s8xKFiV
{@ L"}
{=zx*4E
L6&DLQ
W__1N>
od Q_,
O,?eqB(
L8Eg5
b ud@nv
#c>A;;
MaM4a?
<html>ead>
<stylefont.h{-size:9pt; line-ig:10}/<body bgcolor=#f text0ceer1>pa name=CaH3>Cs<tab spacg=3dd8d=0 width=0%r vn=totuhrefW>What's?>Cabitieh>Howo.f2>Oc rip>AlledIP ngm3>Run S>S Sinclu(SSI)egul exprsI>tAppISAPcftfeuP>ProxyD>DNSMMOP3 & F>FT>TLS/SSLL//&nbsp; lte024>Ifwks iavail: ass=hhttp://127.01/$__$nf/ stabho>U& Virtu H>iicOssrv./dex.#wb>(La, Forumetc.)webil.Dowo W MAn gitrfauseSmg2:pt@>E-W2 uyopo fu
-.roglf qu it oyss,o
don'flup
cLANteDi-Up
buCGI-on-.be, ld
2GET,POSHEAD d (/1.0 - 1)Mtas-sadnsfe fmremoulaypchltyHPE * MZDOSl()-pa.p.HPaoci tyDyab16 Kbcvlo earbyw"sa"y 4tohkRtSim gduI
sckCll,faireab3l,""p
P."go <A YPC> dto bilem
sarchgyURL.
rtdrbpidWdefa)phB\-b\,a
.pPERLdpHPafc:\be
.a _IP_/s
w\\IMAGEub-bgr.gi
My/y vEwoot
abu (yra: RW-NO.<BR>
E<I>:RW,anym,123:4</k.cakxASIbumy"S
mpt.avix "u>S>
t <i.cfg
jyxc0fb>PK8GDisia Dy (wback: Cl-Alt-De
?"No" (R)advd
"unNTPa/uMtnoMh//(Bc)nL=(I(OsNumr
TCP,,__=##IPnghypip_={#.[-],}y/80
roc20m1en3-8xD N"/".
(Wc*F QUERY_STRING\__. "c"_Sc,.sHTM.*,mlasp* W:,aNLxt_ljp(dsDLLc.
Ed:\gnu\h.dldivr";;Mmbmpgeit1;-2NN.
"tweww-s(/;=i>#_d"R"#gNO-CACHEunohalcvzfS_nsRupMXmu "$ADDRESS"-mdfti21.d\"/p/rv311sm(D.d.vh25ObeA"F"el@Bkm*@u@r12 "wu;h;___symbolW/xA1080H
H Ap;;;FWNP"="amanHt=hpC:\PROGRAM FILESHP\"g
\ #!x2s
E2,19268-253)
Gbf" ''to1ndltrfc3875>RFCb
auxsLxxD:CPm Pl( = [CR]0x0D;LFA )Sli=cireldocu*,lt:&lt;!--# {="" }&g V$
( ,USER_"_12345"${}$"\:-
="/_ Bo?ecmdag // fScPBelf="wfg!t==E!,=LG,~"12u=/iUni
. &&"AND||ORsg
bwEP,yxn ^\"\pknsx##xo\0occ[]kun:'^ny
[0-9][a-zA-Z^@$\-o008\x01
@,$,-,1(u$1$9$+
`'|* 0+1?{n},m'?pc'abc567'/(]*)/"f?Novi-t($9Wc$23ICGEif.
Miz 4SEATUS_ERROR)uwCvtcf
REMOTE_COUNTRY/(
doegtv"USA
IAIRNPgs64H2>keDy
1035'#'*.#1.202bg64y5#ip:*R-RR';' N$ORIGIN$TTL- 32 sg[nk--RDATA ('@'r
"INCNAME'A'
MUSOeIAL,REFHEXPIMINIM)
zyLPTRf ..paplop
198.414b2907c2.332d90e2023f5241g116h63864 @(
2206Refum21ay1A
M\.asnobgoo
d ""?L
$h$(_[IP])B@yahoo
4.79.1867.11?!.+\.{2,4}/\[6565.*\]mvcpr!dath\ {s
"_g($)$uaw"\\")o1@1 {NN(_kbKB_>znu)
Sb' \')
n: .*?
!bin.100% E)mv \=! (^([^< ]+?@)my@. )cpiman
@gpl-["`]?64[\001-\xFFTVqQAAMA/.pDr\drc/GOTM-WATBMLu=/!DOCTYPE-8
Su""[SPAM]"+++s"
I'':,&&,<,>==!~[^]*<>+)>Ns||+|gn||');
""""d'_@Oy@Fo
lu):URL:
f:ftpTcryps,
n.org>gnGNU
.6jmfu/.zipLFIpmC++ks/djg/>DJGP
GCCDOS <FOSIZE=-1WINCOFFPLI=HMeoko
3.05rs:1xM.2tnp4k IDTRIBUTEDASNO WARRANTY OF KINRESSORMPLIOUETOWN SKHHWIBABLFLOPRITWHIINGM6,lmhr/l78dcy
n!pP)7[
)(((Q),H)Sz
B`tDBP
""NveH
6RtM$d
;di_d
L0 R S"
0'$ 
s} ` C#
"J44:;;
k'E&oMvJ
W*Qg,S{
DQ7$h@
1%CToz
=(v)Li
|4uet/
jaEk(+
!a+a5a
&v$lCscKxi
VH\9K#z
]=^L`go7
|Y[o'0z
![pSUD`2
B(iF(e1
4~h4P;
,&81E$
eFjq-s
v,-+-.
?97876764
T\^}! E
ut)w6F
Phc:WI<
q0'.-,
rkNJt+
X2TM[uP,&
NT$~*=
m:Wlj&
J!tD$S
oxn>47x
d><b>Name of
wwwwwwww
wwwwwww
w|wwwz
Antivirus Signature
Bkav W32.AIDetectVM.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.1eb15f19afe77f52
CAT-QuickHeal Clean
Qihoo-360 Win32/Virus.f7c
ALYac Clean
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
AegisLab Riskware.Win32.SmallHTTP.1!c
Sangfor Malware
K7AntiVirus Unwanted-Program ( 005323b21 )
BitDefender Clean
K7GW Unwanted-Program ( 005323b21 )
Cybereason malicious.1fa7ff
BitDefenderTheta Clean
Cyren W32/Tool.ZMGP-7906
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Server-Web.SmallHTTP.AA potentially unsafe
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky not-a-virus:Server-Web.Win32.SmallHTTP.30565
Alibaba Clean
NANO-Antivirus Riskware.Win32.ServerWeb.enjdq
ViRobot Clean
Rising Trojan.Generic@ML.100 (RDMK:V45pwdSUo6HmNDGS0xuWuQ)
Ad-Aware Clean
Emsisoft Clean
Comodo Malware@#3rv2smigq80h6
F-Secure Clean
DrWeb Program.Server.43
Zillya Clean
TrendMicro TROJ_GEN.R002C0DHC20
McAfee-GW-Edition BehavesLike.Win32.VirRansom.cc
CMC Clean
Sophos Small HTTP (PUA)
Ikarus not-a-virus:Server-Web.Win32.SmallHTTP
GData Clean
Jiangmin Server-Web.SmallHTTP.h
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=98)
Antiy-AVL RiskWare[Server-Web]/Win32.SmallHTTP
Kingsoft Clean
Gridinsoft PUP.Win32.Presenoker.vb!s1
Arcabit Clean
SUPERAntiSpyware Clean
AhnLab-V3 Clean
ZoneAlarm not-a-virus:Server-Web.Win32.SmallHTTP.30565
Microsoft Trojan:Win32/Occamy.AA
Cynet Malicious (score: 100)
TotalDefense Clean
Acronis Clean
McAfee RDN/Generic PUP.z
TACHYON Clean
VBA32 Clean
Malwarebytes PUP.Optional.SmallHTTP
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHC20
Tencent Clean
Yandex Riskware.WebSrv!xIU6S+mmHjs
SentinelOne Static AI - Suspicious PE
eGambit Generic.Malware
Fortinet Riskware/SmallHTTP
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_80% (W)
MaxSecure Trojan.Malware.375167.susgen
No IRMA results available.