Static | ZeroBOX

PE Compile Time

2021-09-28 16:36:49

PE Imphash

f104e80119f78ba5be523e1d9fb681d0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000daa8 0x0000dc00 6.14558126667
.rdata 0x0000f000 0x00002d58 0x00002e00 5.57334979255
.data 0x00012000 0x000021e0 0x00001000 6.2072132527

Imports

Library WS2_32.dll:
0x40f204 recvfrom
0x40f208 setsockopt
0x40f20c sendto
0x40f210 bind
0x40f214 ioctlsocket
0x40f218 WSAStartup
0x40f21c send
0x40f220 recv
0x40f224 WSACloseEvent
0x40f228 WSARecv
0x40f22c WSASend
0x40f230 WSAGetLastError
0x40f234 gethostname
0x40f238 connect
0x40f23c inet_ntoa
0x40f240 inet_addr
0x40f244 htons
0x40f248 getsockname
0x40f24c shutdown
0x40f250 socket
0x40f254 closesocket
0x40f258 gethostbyname
0x40f260 WSAEventSelect
0x40f264 listen
0x40f26c getpeername
0x40f270 accept
0x40f278 WSACreateEvent
0x40f27c WSASocketA
Library SHLWAPI.dll:
0x40f160 PathFileExistsW
0x40f164 StrCmpNW
0x40f168 PathMatchSpecW
0x40f16c PathFindFileNameW
0x40f170 StrChrA
0x40f174 StrStrIA
0x40f178 StrCmpNIA
0x40f17c StrStrW
Library urlmon.dll:
0x40f2e4 URLDownloadToFileW
Library WININET.dll:
0x40f1d8 InternetReadFile
0x40f1dc InternetOpenUrlW
0x40f1e0 InternetOpenW
0x40f1e4 InternetCloseHandle
0x40f1e8 InternetOpenA
0x40f1ec HttpSendRequestA
0x40f1f4 HttpOpenRequestA
0x40f1f8 InternetConnectA
0x40f1fc InternetCrackUrlA
Library ntdll.dll:
0x40f294 memcpy
0x40f298 _chkstk
0x40f29c _aulldiv
0x40f2a0 RtlUnwind
0x40f2a4 mbstowcs
0x40f2ac NtQuerySystemTime
0x40f2b4 memmove
0x40f2b8 isdigit
0x40f2bc isalpha
0x40f2c0 _allshl
0x40f2c4 _aullshr
0x40f2c8 memset
Library msvcrt.dll:
0x40f284 rand
0x40f288 srand
0x40f28c _vscprintf
Library KERNEL32.dll:
0x40f028 GetLastError
0x40f02c CreateProcessW
0x40f030 GetLocaleInfoA
0x40f034 DuplicateHandle
0x40f03c GetThreadPriority
0x40f040 SetThreadPriority
0x40f044 GetCurrentThread
0x40f048 GetCurrentProcess
0x40f054 InterlockedExchange
0x40f058 WaitForSingleObject
0x40f060 GetCurrentProcessId
0x40f064 HeapSetInformation
0x40f068 GetSystemInfo
0x40f070 GetProcessHeaps
0x40f074 HeapValidate
0x40f078 HeapCreate
0x40f07c HeapFree
0x40f080 HeapAlloc
0x40f084 HeapReAlloc
0x40f08c CreateThread
0x40f090 CreateMutexA
0x40f094 CreateEventA
0x40f098 ExitProcess
0x40f0a4 SetEvent
0x40f0ac SetFileAttributesW
0x40f0b0 lstrcpyW
0x40f0b4 DeleteFileW
0x40f0b8 GetDiskFreeSpaceExW
0x40f0bc FindNextFileW
0x40f0c0 lstrcmpiW
0x40f0c4 QueryDosDeviceW
0x40f0c8 RemoveDirectoryW
0x40f0cc lstrlenA
0x40f0d0 GlobalLock
0x40f0d4 GetModuleHandleW
0x40f0d8 GetTickCount
0x40f0dc GlobalAlloc
0x40f0e0 Sleep
0x40f0e4 lstrcpynW
0x40f0e8 ExitThread
0x40f0ec MultiByteToWideChar
0x40f0f0 lstrlenW
0x40f0f4 GlobalUnlock
0x40f0f8 GetFileSize
0x40f0fc MapViewOfFile
0x40f100 UnmapViewOfFile
0x40f104 WriteFile
0x40f110 CreateFileW
0x40f114 FlushFileBuffers
0x40f11c CreateFileMappingW
0x40f120 CloseHandle
0x40f124 FindFirstFileW
0x40f128 GetDriveTypeW
0x40f12c MoveFileExW
0x40f130 CreateDirectoryW
0x40f134 GetLogicalDrives
0x40f138 CopyFileW
0x40f13c GetModuleFileNameW
0x40f140 lstrcmpW
0x40f144 FindClose
Library USER32.dll:
0x40f184 RegisterClassExW
0x40f188 TranslateMessage
0x40f18c GetClipboardData
0x40f190 EmptyClipboard
0x40f198 SetWindowLongW
0x40f19c DefWindowProcA
0x40f1a0 wsprintfW
0x40f1a4 SendMessageA
0x40f1ac CloseClipboard
0x40f1b0 GetMessageA
0x40f1b4 wvsprintfA
0x40f1b8 GetWindowLongW
0x40f1c0 CreateWindowExW
0x40f1c4 DispatchMessageA
0x40f1c8 OpenClipboard
0x40f1cc SetClipboardData
0x40f1d0 SetClipboardViewer
Library ADVAPI32.dll:
0x40f000 RegSetValueExW
0x40f004 CryptGenRandom
0x40f008 CryptReleaseContext
0x40f010 RegQueryValueExW
0x40f014 RegOpenKeyExA
0x40f018 RegSetValueExA
0x40f01c RegCloseKey
0x40f020 RegOpenKeyExW
Library SHELL32.dll:
0x40f158 ShellExecuteW
Library ole32.dll:
0x40f2d0 CoInitializeEx
0x40f2d4 CoCreateInstance
0x40f2d8 CoInitialize
0x40f2dc CoUninitialize
Library OLEAUT32.dll:
0x40f14c SysAllocString
0x40f150 SysFreeString

!This program cannot be run in DOS mode.
`.rdata
@.data
>ilciu1
>ilciuo
L$$QRP
;PCOIu^
>ilciu
F(;F$s
VC20XC00U
;t$(v(
UQPXY]Y[
HTTP/1.1 200 OK
LOCATION:
239.255.255.250
M-SEARCH * HTTP/1.1
ST:urn:schemas-upnp-org:device:InternetGatewayDevice:1
Man:"ssdp:discover"
HOST: 239.255.255.250:1900
Mozilla/4.0 (compatible; UPnP/1.0; Windows 9x)
Content-Type: text/xml; charset="utf-8"
Connection: Close
Cache-Control: no-cache
Pragma: no-cache
<?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><m:GetExternalIPAddress xmlns:m="urn:schemas-upnp-org:service:WANIPConnection:1"/></SOAP-ENV:Body></SOAP-ENV:Envelope>
SOAPAction: "urn:schemas-upnp-org:service:WANIPConnection:1#GetExternalIPAddress"
<?xml version="1.0"?>
<SOAP-ENV:Envelope
xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"
SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<SOAP-ENV:Body>
<m:AddPortMapping xmlns:m="urn:schemas-upnp-org:service:WANIPConnection:1">
<NewRemoteHost></NewRemoteHost>
<NewExternalPort>%d</NewExternalPort>
<NewProtocol>%s</NewProtocol>
<NewInternalPort>%d</NewInternalPort>
<NewInternalClient>%s</NewInternalClient>
<NewEnabled>1</NewEnabled>
<NewPortMappingDescription></NewPortMappingDescription>
<NewLeaseDuration>0</NewLeaseDuration>
</m:AddPortMapping>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>
SOAPAction: "urn:schemas-upnp-org:service:WANIPConnection:1#AddPortMapping"
<?xml version="1.0"?>
<SOAP-ENV:Envelope
xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/"
SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/">
<SOAP-ENV:Body>
<m:DeletePortMapping xmlns:m="urn:schemas-upnp-org:service:WANIPConnection:1">
<NewRemoteHost>%s</NewRemoteHost>
<NewExternalPort>%d</NewExternalPort>
<NewProtocol>%s</NewProtocol>
</m:DeletePortMapping>
</SOAP-ENV:Body>
</SOAP-ENV:Envelope>
SOAPAction: "urn:schemas-upnp-org:service:WANIPConnection:1#DeletePortMapping"
TCP: P2P_SendGETLPacket(0,%s) failed!
twizt)
twizt)
twizt)
twizt)
www.update.microsoft.com
s405940
SOFTWARE\Microsoft\Security Center
FirewallOverride
FirewallDisableNotify
AntiSpywareOverride
AntiVirusOverride
AntiVirusDisableNotify
UpdatesOverride
UpdatesDisableNotify
SOFTWARE\Microsoft\Security Center\Svc
FirewallOverride
FirewallDisableNotify
AntiSpywareOverride
AntiVirusOverride
AntiVirusDisableNotify
UpdatesOverride
UpdatesDisableNotify
14673222387840093601L
12gcwY6q4pv4DBbEjeQXwbhDBesLDc755VE2kyzzXRtvBvzd
18xjALsLW57DQcXSgvGE8H9iXkXYvPjSWc
3PLk48rqFRT7ZB2GZVHMJE5aiHr5jjBfZcw
39t2ndtRZKxHPHaprbe6kPaws4vs1nWA94
qz9vrpv9h2j5e6fsqwwsh8e9aaumwvql956ynh9rs9
XmgkLqGXu8HGU7tTbbwWvaJYrgvybx3eZE
DSVC6eMqTCpkaMkCVp6Yn2U7FYkU76VhKB
0xd4F8DfD1cDBa76e9ac6b3b31Ef3C6C6c3D1ea1d0
LXz2Jhi73bna54msz2zpsEpRVAh8KbeYRL
rPTusqR9SMoh7QuYfJ3EJF7Ewogp6HVJEt
TCW3T7UyyN3MWqakTPViWVRAL1kGsYyTL6
t1gE3Hz4ivvEAQMWagv5XuUMkUPcnNkuNGB
tz1U9d1x7U3AEMw8UPSVMtEH4u9eShBX6prG
hxd697fe63e8c4d138cd47d9cdbff6bbf6facbd1fb
QQeW6TaSKUA9yuG2mPKMd6epoXa6vnRqh6
RRqRTmr9WDk2LdTn7mfMHXofz1XaoTrG3C
NBGLRULGKDFPLIDQZRDQOORKONAV5VRWOV3CDGJW
AUpwoQdnjVynLKhDkNt1TJh6sgduJnxyJy
SNjNq8EbkPcfEqQtE6FTM5eftqS33otZY4
zil1afs50sm4fe7ulsdygvvl7x6tygtcwmkrqtzqlq
s1iibbBPLCP843XGjxRxoT9Skk542HMLU5v
bitcoincash:qz9vrpv9h2j5e6fsqwwsh8e9aaumwvql956ynh9rs9
cosmos1j2j4n8mn2al28g62uzsrf9jhhqjsdpr58et5j4
46wi3NQz8eWV9HnGGKtpqKFcyGqWvLXsRP9C4oh3FgJ8M11QzmSrWWu6hW2kdredmQDYFjkJNg8t4Lye6vPuRcCsK71DPYr
addr1qx6957p39d7v53mvqe7gqc62eazsmmxhlth870590x9v8mq0pjv9yx5jd4sgndnt87zmdutq87r8xh0m8pn65k2p9yasl4vamq
Fd8ScFbi4ZnkrDYZa2Fhanx3BuoWXFzDaG
GAWB6FUMRQBOF4JSVWAH6GO26C24UL5P44G3LDWK46WMFAS2TAZD7EBC
GLnwYTx21SBA1XAsBqtFumkDMpB97tmqsp
bnb1yzw7m55vrhqmmw2e0xpven8q49u8m63prv3hhz
band1ecl9c2w2dtxx70pewvsl6le3sd8srrlg36vthx
bc1q4eym03072yk0zahdm9jym28vk0dxwyvs57sr6g
U30212907
E30940134
B30912949
WS2_32.dll
StrStrW
PathFileExistsW
StrCmpNW
PathMatchSpecW
PathFindFileNameW
StrChrA
StrStrIA
StrCmpNIA
SHLWAPI.dll
URLDownloadToFileW
urlmon.dll
InternetConnectA
InternetCrackUrlA
InternetReadFile
HttpOpenRequestA
HttpAddRequestHeadersA
HttpSendRequestA
InternetOpenA
InternetCloseHandle
InternetOpenW
InternetOpenUrlW
WININET.dll
isalpha
isdigit
memmove
NtQuerySystemTime
RtlTimeToSecondsSince1980
mbstowcs
ntdll.dll
_vscprintf
msvcrt.dll
lstrlenA
GlobalLock
GetModuleHandleW
GetTickCount
GlobalAlloc
lstrcpynW
ExitThread
MultiByteToWideChar
lstrlenW
GlobalUnlock
GetFileSize
MapViewOfFile
UnmapViewOfFile
WriteFile
InitializeCriticalSection
LeaveCriticalSection
CreateFileW
FlushFileBuffers
EnterCriticalSection
CreateFileMappingW
CloseHandle
FindFirstFileW
GetDriveTypeW
MoveFileExW
CreateDirectoryW
GetLogicalDrives
CopyFileW
GetModuleFileNameW
lstrcmpW
FindClose
RemoveDirectoryW
QueryDosDeviceW
lstrcmpiW
FindNextFileW
GetDiskFreeSpaceExW
DeleteFileW
lstrcpyW
SetFileAttributesW
GetVolumeInformationW
ExitProcess
CreateEventA
GetLastError
CreateMutexA
CreateThread
ExpandEnvironmentStringsW
HeapReAlloc
HeapAlloc
HeapFree
HeapCreate
HeapValidate
GetProcessHeaps
HeapSetInformation
GetCurrentProcessId
InterlockedDecrement
WaitForSingleObject
InterlockedExchange
InterlockedIncrement
InterlockedExchangeAdd
GetCurrentProcess
GetCurrentThread
SetThreadPriority
GetThreadPriority
DeleteCriticalSection
DuplicateHandle
GetLocaleInfoA
CreateProcessW
KERNEL32.dll
SetClipboardViewer
SetClipboardData
OpenClipboard
DispatchMessageA
CreateWindowExW
RegisterRawInputDevices
DefWindowProcA
SetWindowLongW
ChangeClipboardChain
EmptyClipboard
GetClipboardData
GetWindowLongW
RegisterClassExW
TranslateMessage
wsprintfW
SendMessageA
IsClipboardFormatAvailable
CloseClipboard
GetMessageA
wvsprintfA
USER32.dll
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
RegSetValueExA
RegOpenKeyExA
RegSetValueExW
CryptAcquireContextW
CryptReleaseContext
CryptGenRandom
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
CoCreateInstance
CoInitialize
CoUninitialize
CoInitializeEx
ole32.dll
OLEAUT32.dll
WSAWaitForMultipleEvents
WSASocketA
WSACreateEvent
WSAGetOverlappedResult
WSAEventSelect
WSAEnumNetworkEvents
WSASend
WSARecv
WSACloseEvent
SetEvent
CreateIoCompletionPort
GetQueuedCompletionStatus
PostQueuedCompletionStatus
GetSystemInfo
memset
_aullshr
_allshl
memcpy
_chkstk
_aulldiv
RtlUnwind
NtQueryVirtualMemory
wLI"Q/}
.FKiY&
?__H%P*
N'eNRa
'<+Z]vo,;
V]Pk''9
0123456789abcdef
Sep 28 2021 10:36:37
0123456789
0123456789abcdef
Sep 28 2021 10:36:36
jjjjjj
%temp%
%s\%d%d.exe
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.82 Safari/537.36
%s:Zone.Identifier
%s\%d.exe
%s:Zone.Identifier
service
serviceType
serviceList
device
deviceType
deviceList
urn:schemas-upnp-org:device:InternetGatewayDevice:1
urn:schemas-upnp-org:device:WANDevice:1
urn:schemas-upnp-org:device:WANConnectionDevice:1
GetExternalIPAddressResponse
urn:schemas-upnp-org:service:WANIPConnection:1
urn:schemas-upnp-org:service:WANPPPConnection:1
controlURL
URLBase
NewExternalIPAddress
wsecsvcmgr.exe
Microsoft Windows Update Service
%s:Zone.Identifier
%userprofile%
wsecsvcmgr.exe
%windir%
Software\Microsoft\Windows\CurrentVersion\Run\
Software\Microsoft\Windows\CurrentVersion\Run\
%s\nodesinfo.dat
%s\cmdinfo.dat
Microsoft Corporation
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDrives
/c start .\%s & start .\%s\VolDriver.exe
%windir%\system32\cmd.exe
%s.lnk
%s\%s\VolDriver.exe
shell32.dll
shell32.dll
Thumbs.db
$RECYCLE.BIN
desktop.ini
System Volume Information
%s\%s\%s
(%dGB)
Unnamed volume
bitcoincash:
cosmos
bitcoincash:
vbitcoincash
cosmos
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Fwdisable.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37675794
CMC Clean
CAT-QuickHeal Trojan.Generic
ALYac Trojan.GenericKD.37675794
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005533551 )
BitDefender Trojan.GenericKD.37675794
K7GW Trojan ( 005533551 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Phorpiex.V
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Worm:Win32/Phorpiex.8efc1669
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.86 (RDMK:y7ivWWGuFPyeanKUnks+fg)
Ad-Aware Trojan.GenericKD.37675794
Emsisoft Trojan.GenericKD.37675794 (B)
Comodo Malware@#1focjyur33i1g
F-Secure Clean
DrWeb DLOADER.Trojan
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.lh
FireEye Generic.mg.c532ac418f3e8679
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37675794
Jiangmin Clean
Webroot W32.Trojan.FWDisable.emW@aCxrSb
Avira HEUR/AGEN.1135016
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH012.a.(kcloud)
Gridinsoft Malware.Win32.GenericMC.cc
Arcabit Trojan.Generic.D23EE312
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4630408
Acronis suspicious
McAfee GenericRXQF-OJ!C532AC418F3E
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Phorpiex
Panda Adware/SecurityProtection
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CIS21
Tencent Win32.Trojan.Generic.Swkg
Yandex Clean
Ikarus Worm.Win32.Phorpiex
MaxSecure Clean
Fortinet W32/Phorpiex.V!tr
BitDefenderTheta AI:Packer.2619E80B1E
AVG Win32:KadrBot [Trj]
Avast Win32:KadrBot [Trj]
No IRMA results available.