Static | ZeroBOX

PE Compile Time

2019-04-23 15:25:24

PE Imphash

6ed4f5f04d62b18d96b26d6db7c18840

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0000e000 0x00000000 0.0
UPX1 0x0000f000 0x00017000 0x00016e00 7.84892079573
UPX2 0x00026000 0x00001000 0x00000200 1.38215794943
.rmnet 0x00027000 0x0000f000 0x0000e200 7.96583966943

Imports

Library KERNEL32.DLL:
0x426028 LoadLibraryA
0x42602c ExitProcess
0x426030 GetProcAddress
0x426034 VirtualProtect

!This program cannot be run in DOS mode.
.rmnet
S++ 0)
vod&q0
OSb/$`
3[UMNF
^b`flv
4MKC;3+
aoLPt,-
siRA+X
[n7`4MW
HnYhQl0mTDm
ENoC<9B
i&4FTb
0>Xhv4M
(J)S)s
s_c__GL
OBAL_HEAP_SELECTED
MSVCRT
7runtime error
- Kablto ini|
heap7'7
ugh spac#n
nf{lowi8a
5pur+virtu!
opeX1soM
desc+8
a/lock
p@gram
Bak Jm6/0
k4+0.+8
Oargu(s_02
%,klwn>p
GetLa2A
essageBoxA
us%32.d
46co\..
cRg)goB
o_CiG+
rTpu~+l-
3K50G{+6
pY.|,
l+G~tH{
85:kr2
f]\[ZY
Xgfedci
iba`on
hwvutsi
gJt"}[5
Jm#d7r_
u!,y>o
#vw>"b,r
:ClJFo
[58y>;
[<cFdY
\v+mq2
=7;OWjnC
i%+;AI
(/?Nx!
O'K~f
8J$i8#
4M_KG3#
SKO?7#i
7^1ON6Oj
S]6+AA%
I%gk1W%
755.M8
=,>}:=CU
FpF88tM(C
2`CS>[;U+
:wN:IGW
B21^O(q
W&=kN&
8/7JL><~
,As18-M;2@E;FL
</F$]$
1_H%c%
T_Yg~9
KyUffT
hOkYwRRtgPP
Srv.exe`A
eHandl
2Fi1Wri
"Modul
U8Nw$`
wqE1z<
|OK'Ea
C%6="h
_YD_WI
G*&o/:V
NBP{H6
2$E5~O
Rd/jIe
En!@^*
P1c}".
B%Z((39
H6S9WW
I^Dz0^
czf}W)7
0~So+5
(.LHc{;m
rN'otc
^%b21m
(B<)_=j
=6"b_i
3Q&xYg
Z+6Ch+
U*rQR[
V~8ELsH
6XU1}7
{IU\4.z
r^*^9J
x0rV&l
6oU0#0
`(%A@k"
"|\0B"
k0~YncG
1'?Y}c
hq<^/GSZd
~8YQ6A}
yib}D
d6d#^mu
gG `f'
>69q!|B
T4QEmb
8dv(s]
,7QyE3O
=-rUyk
eeBj2w
wgC'S
+E\7vVb
#)L9KK
s r(tn
6E-WbA
SOPXT*
\>fA%
2a=&Y'
=#d-)aH
y7X"O\
yS-9>J
ZSS(Q<i
vh'crlW
-DgGiW
^2q CqGz
7zAgr]
.[_7*
g\f:lc
K#3N&+
c)la~+
]uI|Zm
S6Qd~a
itYL*:!
.@$nxT
*va\*#`
9XfQf5n}
7P$L"`\<%
fZI&[n
!JIq:{
>xE]_/
`|m2T#
V:TJN|
6PF$F)9%
;X^fl$m{
2r@Fr>{
AddrUQ[
7IsB^E
adPtrOm
RtlUnwindaiseEx\pQ1
StaWpInfo
Comm-
6wn!Vers?J
bur9nK>
}{ideCbrToMJ^By[
6agmCM[
XPTPSW
KERNEL32.DLL
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
KyUffThOkYwRRtgPP
Srv.exe
FreeLibrary
CreateMutexA
CloseHandle
ReleaseMutex
GetLastError
CreateFileA
WriteFile
GetModuleFileNameA
CreateProcessA
kernel32.dll
Y9C(,qm
-U8Nw$`
wqE1z<
pSf%6="h
_YD_WI
fo/:V<
NBP{H6
5~OtNF
Rd/jIe
En!@^*
F*B|y\
4 ?+e@-
I^Dz0^
czf}W)7
Hv9A"r
0~So+5
>oYL,R
rN'otc
_)Xya@
^%b21m
(B<)_=j
][(tp#
#'Ay70
=6"b-8i,$
3Q&xYg
Z+6Ch+
U*rQR[
08ELsH
{IU\4.z
@x5Py@@
r^*^9J
x0rV&l
6oU0#0
"|\0B"Slb
k0~YncG
Xok@(H
1'?Y}c
#/T%Bj
cWNVo'
hq<^/GSZ
~8YQ6A}
-~(%][
yib}D
d6d#^mu
gG `f'
>69q!|B
T4QEmb
,7QyE3O
^n~Yi.
wgC'S
h=ri,RC
e?9'rh_-
+E\7vVb
#_GL9KK
+F)r)k
6E-WbA
SOPXT*
3l92~9pS
PkIN4kA
2a=&Y'
=#d-)aH
yS-9>J
ZSS(Q<i
vh'crlW
wR:/N8
-DgGiW
'!^=#q CqGz
.[_7*
A3`BKs
5,Ekep
c)la~+
HuI|Zm
|@)u\w
)T`D?p
S6Qd~a
itYL*:!
*va\*#`
9XfQf5n}
7P$L"`\<%
fZI&[n:
ZAx#yj
!JIq:{
>xE]_/
`|m2T#
6PF$F)k
2r@Fr>{
jjjjjj
Antivirus Signature
Bkav W32.RammitNNA.PE
Lionic Virus.Win32.Nimnul.tn4U
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal W32.Ramnit.A
McAfee W32/Ramnit.q
Cylance Unsafe
VIPRE Virus.Win32.Ramnit.a (v)
Sangfor Virus.Win32.Ramnit.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Win32.Ramnit
K7GW Trojan ( 004bcce41 )
K7AntiVirus Trojan ( 004bcce41 )
Baidu Win32.Virus.Nimnul.a
Cyren W32/Ramnit.B!Generic
Symantec W32.Ramnit!inf
ESET-NOD32 Win32/Ramnit.A
APEX Malicious
Paloalto generic.ml
ClamAV Win.Trojan.Ramnit-1847
Kaspersky Virus.Win32.Nimnul.a
Alibaba Clean
NANO-Antivirus Virus.Win32.Ramnit.eslalb
SUPERAntiSpyware Clean
MicroWorld-eScan Win32.Ramnit
Tencent Virus.Win32.Nimnul.d
Ad-Aware Win32.Ramnit
Emsisoft Win32.Ramnit (B)
Comodo Packed.Win32.MUPX.Gen@24tbus
F-Secure Clean
DrWeb Win32.Rmnet
Zillya Virus.Nimnul.Win32.1
TrendMicro PE_RAMNIT.H
McAfee-GW-Edition BehavesLike.Win32.Ramnit.cc
FireEye Generic.mg.47c116db3f0e5d53
Sophos ML/PE-A + W32/Patched-I
Ikarus Virus.Ramnit
GData Win32.Virus.Ramnit.C
Jiangmin Win32/PatchFile.et
Webroot Clean
Avira W32/Ramnit.CD
MAX malware (ai score=80)
Antiy-AVL Trojan/Generic.ASVirus.1EB
Kingsoft Win32.Infected.Ramnit.sr.(kcloud)
Gridinsoft Malware.Win32.Gen.bot!se59456
Arcabit Win32.Ramnit
ViRobot Win32.Ramnit.E
ZoneAlarm Clean
Microsoft Virus:Win32/Ramnit.A
AhnLab-V3 Win32/Ramnit.B
Acronis suspicious
VBA32 Virus.Win32.Nimnul.a
ALYac Win32.Ramnit
TACHYON Virus/W32.Ramnit.B
Malwarebytes Clean
Panda W32/Cosmu.gen
Zoner Trojan.Win32.Ramnit.23698
TrendMicro-HouseCall PE_RAMNIT.H
Rising Virus.Ramnit!1.9AA5 (CLASSIC)
Yandex Win32.Ramnit.Gen.3
SentinelOne Static AI - Malicious PE
MaxSecure Virus.Nimnul.A
Fortinet W32/Ramnit.A
BitDefenderTheta AI:FileInfector.EAEEA7850C
AVG Win32:RmnDrp [Inf]
Avast Win32:RmnDrp [Inf]
No IRMA results available.