Static | ZeroBOX

PE Compile Time

2021-09-07 01:41:46

PE Imphash

63393299977e5acc51eaba5bf320ad3d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000cf6 0x00000e00 4.71687447284
.rdata 0x00002000 0x00000834 0x00000a00 4.23902732503
.data 0x00003000 0x0000043c 0x00000600 5.17022141781
.rsrc 0x00004000 0x000001e0 0x00000200 4.70150325825
.reloc 0x00005000 0x00000078 0x00000200 1.71385727147

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00004060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x402034 VirtualProtect
0x402038 GetAtomNameA
0x40203c GetFileAttributesW
0x402040 SetLocaleInfoW
0x402044 PurgeComm
0x40204c SetMailslotInfo
0x402054 LoadLibraryA
0x402058 GetVolumePathNameW
0x40205c GetDateFormatW
Library USER32.dll:
0x4020bc MessageBoxW
0x4020c0 VkKeyScanA
0x4020c4 CharToOemBuffA
0x4020c8 IMPSetIMEA
0x4020cc CharNextExA
0x4020d0 GetWindowRgn
Library WININET.dll:
0x4020dc FtpOpenFileW
0x4020e4 InternetReadFile
0x4020ec InternetHangUp
0x4020f4 InternetCreateUrlW
Library OLEAUT32.dll:
0x4020a0 VarParseNumFromStr
0x4020a4 BSTR_UserUnmarshal
0x4020a8 VarR8FromDate
0x4020ac SysReAllocString
0x4020b0 VarEqv
0x4020b4 VarI4FromDisp
Library MSWSOCK.dll:
0x402080 GetAddressByNameA
0x402084 GetAddressByNameW
0x402088 SetServiceW
0x40208c rexec
0x402090 GetNameByTypeW
0x402098 sethostname
Library AVICAP32.dll:
Library MSVFW32.dll:
0x402068 ICSendMessage
0x40206c ICImageDecompress
0x402070 ICSeqCompressFrame
0x402074 ICOpen
0x402078 MCIWndCreate
Library AVIFIL32.dll:
0x402008 AVIStreamGetFrame
0x40200c EditStreamSetNameW
Library CRYPT32.dll:
0x402024 CertFindExtension
0x40202c CertSaveStore

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
GetDateFormatW
GetVolumePathNameW
LoadLibraryA
RegisterWaitForInputIdle
SetMailslotInfo
WritePrivateProfileStringW
PurgeComm
SetLocaleInfoW
GetFileAttributesW
GetAtomNameA
VirtualProtect
KERNEL32.dll
ChildWindowFromPoint
VkKeyScanA
CharToOemBuffA
IMPSetIMEA
CharNextExA
GetWindowRgn
MessageBoxW
USER32.dll
FtpOpenFileW
ReadUrlCacheEntryStream
RetrieveUrlCacheEntryFileA
InternetReadFile
InternetCheckConnectionW
InternetCreateUrlW
InternetHangUp
WININET.dll
OLEAUT32.dll
SetServiceW
sethostname
GetNameByTypeW
MigrateWinsockConfiguration
GetAddressByNameA
GetAddressByNameW
MSWSOCK.dll
capCreateCaptureWindowA
GetOpenFileNamePreviewA
AVIStreamOpenFromFileW
EditStreamSetNameW
ICOpen
ICImageDecompress
ICSeqCompressFrame
MCIWndCreate
ICSendMessage
AVIStreamGetFrame
AVICAP32.dll
MSVFW32.dll
AVIFIL32.dll
CryptSIPRetrieveSubjectGuid
CertDeleteCertificateFromStore
CertSerializeCertificateStoreElement
CertFindExtension
CertEnumCertificateContextProperties
CertSaveStore
CRYPT32.dll
SVWjuXjrf
Xjl_jm[joYjnf
Xjg^jff
XjsZjbf
YjyXjxf
j.XjnYje[jkf
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
< <&<,<2<8<><D<J<P<V<\<b<h<n<t<z<
Antivirus Signature
Lionic Trojan.Win64.Injects.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.37546021
FireEye Generic.mg.43c4cf6c6e519b98
CAT-QuickHeal Clean
McAfee RDN/Generic.hbg
Cylance Unsafe
VIPRE Lookslike.Win32.Sirefef.c!ag (v)
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 00581f961 )
BitDefender Trojan.GenericKD.37546021
K7GW Trojan-Downloader ( 00581f961 )
Cybereason malicious.7d298e
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34126.auW@aOI8CDei
Cyren W32/Agent.DJF.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FVW
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win64.Injects.awf
Alibaba TrojanDownloader:Win32/Remcos.29aae33d
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
Avast Win32:MalwareX-gen [Trj]
Rising Trojan.Generic@ML.87 (RDML:/5iox6IYKq7CLRpG4bGSMA)
Ad-Aware Trojan.GenericKD.37546021
Emsisoft Trojan.GenericKD.37546021 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.hbg
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Downloader.Win32.Agent
Jiangmin Clean
MaxSecure Clean
Avira TR/Dldr.Agent.mrubr
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Remcos.PMW!MTB
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win64.Injects.awf
GData Win32.Trojan.PSE.1TJHEHQ
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Remcos.C4625888
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 BScope.Trojan.Injects
Malwarebytes Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet PossibleThreat.PALLAS.H
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Panda Clean
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.