Static | ZeroBOX

PE Compile Time

2021-09-15 18:14:20

PE Imphash

17737ef37d45565c07115078a38f8da4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000aefc1 0x000af000 6.14893211721
.rdata 0x000b0000 0x000005c4 0x00000600 4.71480791248
.data 0x000b1000 0x00000098 0x00000200 0.147365075305
.pdata 0x000b2000 0x000000a8 0x00000200 1.87742412536
.ndata 0x000b3000 0x000075f9 0x00007600 4.26269903193

Imports

Library KERNEL32.dll:
0x1800b0000 GetCurrentThread
0x1800b0008 WaitForSingleObject
0x1800b0010 WaitForMultipleObjects
0x1800b0018 CreateThread
0x1800b0020 TlsGetValue
0x1800b0028 GetThreadPriority
0x1800b0030 DuplicateHandle
0x1800b0038 ResumeThread
0x1800b0040 CreateFileA
0x1800b0048 DeleteCriticalSection
0x1800b0050 EnterCriticalSection
0x1800b0058 GetCommandLineW
0x1800b0060 GetLastError
0x1800b0068 GetModuleHandleA
0x1800b0070 GetProcAddress
0x1800b0078 GetProcessHeap
0x1800b0080 HeapAlloc
0x1800b0088 HeapFree
0x1800b0090 HeapReAlloc
0x1800b00a0 LeaveCriticalSection
0x1800b00a8 Sleep
0x1800b00b0 VirtualAlloc
0x1800b00b8 VirtualFree
0x1800b00c0 WideCharToMultiByte
0x1800b00c8 LoadLibraryA
0x1800b00d0 GetSystemTime

Exports

Ordinal Address Name
1 0x180001490 DllGetClassObject
2 0x180001440 DllRegisterServer
3 0x1800017c0 PluginInit
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.ndata
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVATVWSH
[_^A\A^A_]
UAWAVAUATVWS
Sk%oE)
UA(BE)
&{Bo-0
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
1 F-E)
uPVaE)
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
z}Md-0
[_^A\A]A^A_]
Mc[<L)
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVAUATVWSH
[_^A\A]A^A_]
kernel32.dll
VirtualAlloc
VirtualFree
DllGetClassObject
DllRegisterServer
PluginInit
GetCurrentThread
WaitForSingleObject
WaitForMultipleObjects
CreateThread
TlsGetValue
GetThreadPriority
DuplicateHandle
ResumeThread
CreateFileA
DeleteCriticalSection
EnterCriticalSection
GetCommandLineW
GetLastError
GetModuleHandleA
GetProcAddress
GetProcessHeap
HeapAlloc
HeapFree
HeapReAlloc
InitializeCriticalSection
LeaveCriticalSection
VirtualAlloc
VirtualFree
WideCharToMultiByte
LoadLibraryA
GetSystemTime
KERNEL32.dll
3=2=>475737778797>7;7<7=</;>8081?:838485868788894:8;8<8=8>9/909192939495969798999:9;9<9=9>:/:0:1:2:3:4:5:6:7:8:9:::;:<:=8>;/;0;1;<::4>;7;64;;/76=943;;?171:0A4>9>9?6:4?5?4>6>=?7>9>0:<><>=?=?>?<>6;3?6?2;6>9>;?3;:?4?2;=A::>;1@1<=<:<0<2@8>4>3>/@>>;><>=>>?/?0?1A534=047=597?296=99;?692==6/@:6><4:1;36::367@266@>49@561:47/A:7>;173A=7:=>77A2769;57A271;3</2:<>:3>/2><986<722<6:;>724<18>=/3:=>609<959=95=732=63:3;3<3=3>4/404142434445464748494:4;4<4=4>5/50518290545572==5=59425:467>5>6/606162636465=6678:896/6=62616>9/70717265747576777879@>6=7<7=7>9/8081828384@5858788898:9;8<8=8>91909194939495969798999<9;9<9=9>:/:0:1:233:4:5:6:;:8:9:::;:<:=:<;/A0;1;2;3:4;5;6;7;8;9;::;;<;=;></<0<1<2<3=4<5<6<7<8<9<:=;<<<=<>=/=0=1=2=3=4=5<6=7=8=95:A>=<==56>/>0>1>::/>4>56:>7>8>9>:>;><>=>>?/?0?1?2=3?4?586?8?8?9?:?;?<?=?>@/@0@1@2@3@4@5@6@7@8@9@:@;@<@=@>A/A0A1A2A3A4A5A6A7A8A9A:A;A<A=A>2/202122232425262728292:2;2<2=2>3/303132333435363738393:7;3<3=8640404142434445464748494:4;4<4=4>5/50515253545556575859347>5<5=5>6/606175786465667768696:716<6=6>737071
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.46982868
Malwarebytes Trojan.IcedID
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanBanker:Win32/IcedID.7aa65050
K7GW Trojan-Downloader ( 00580ce61 )
K7AntiVirus Trojan-Downloader ( 00580ce61 )
BitDefenderTheta Clean
Cyren Clean
Symantec Trojan.Gen.2
ESET-NOD32 Win64/TrojanDownloader.IcedId.F
Baidu Clean
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky Trojan-Banker.Win32.IcedID.txva
BitDefender Trojan.GenericKD.46982868
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.46982868
Rising Clean
Ad-Aware Trojan.GenericKD.46982868
Emsisoft Trojan.GenericKD.46982868 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Drixed.bh
FireEye Generic.mg.9f3d6ad1891e088e
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Downloader.IcedID.6JCWMN
Jiangmin Clean
Webroot Clean
Avira TR/AD.Bazar.kuqsp
Antiy-AVL Clean
Kingsoft Win32.Troj.Banker.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D2CCE6D4
ViRobot Clean
ZoneAlarm Trojan-Banker.Win32.IcedID.txva
Microsoft Trojan:Win32/Tnega!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!9F3D6AD1891E
MAX malware (ai score=89)
VBA32 Clean
Cylance Unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.SuspectCRC
eGambit Clean
Fortinet Malicious_Behavior.SB
AVG Win64:BankerX-gen [Trj]
Avast Win64:BankerX-gen [Trj]
MaxSecure Clean
No IRMA results available.