Static | ZeroBOX

PE Compile Time

2023-03-05 20:46:58

PE Imphash

039032eedb13fb00811bf4343043c31c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000770eb 0x00077200 5.8702237863
.data 0x00079000 0x000040e0 0x00003600 4.47946257225
.idata 0x0007e000 0x00000070 0x00000200 1.07925653922
.rsrc 0x0007f000 0x00032b28 0x00032c00 6.05345655654

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x0009b1d0 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_RCDATA 0x0009bc18 0x00015f0a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0009b638 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0009b7f8 0x0000041c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0009b698 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x47e000 GetModuleHandleA
0x47e004 HeapCreate

!This program cannot be run in DOS mode.
`.data
.idata
@.rsrc
.CRT$XCU
.rdata
.rdata$voltmd
.rdata$zzzdbg
.text$di
.text$mn
.idata$5
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
HeapCreate
GetModuleHandleA
KERNEL32.dll
NOx-D7i
0/7{}
WUUTU%
d2/z-L
\/Q8:jt
1iD(XAjRa
1aF)Y}
r}f`P]{[r
zVEJI0
^SSSLMM
7{}O||6
~nllL[
wa)!Wn
l^$ ;?
et]g``
J^UUTU%
399U_F
4FYgN~
2@Pqo]
r[r9M;c
wXikp7h.
pr1!e3
RJFFFPUuM
7ofnnN
4Fr)e9
>>>>>>>>>>>>>>>>>>>>>>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
D):6=kb
mf~*C|
eMbMqC
x$&XOD
p^}UP^
K')}gw8
>]fr-2
4b.<^ 1
#Ur-l>
5K( /er
a&lk9'k
X|DBK]
iy]ADZ*
j-r.ig
IY~lo-h
v6ixnB
1FjLxfE
IKnBHNemE
]:Z>1Yv
`:MyI'
Y3V;h~
!vI1kLK5
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Blow scan explain veteran army transport
CompanyName
Prayer abortion abortion
FileDescription
Improvement veteran wage bother responsibility
FileVersion
1.2555.8847.17
InternalName
Communication thin
LegalCopyright
Copyright
Half negotiation
LegalTrademarks
Responsibility gift clarify
OriginalFilename
ProductName
Convulsion
ProductVersion
1.2555.8847.17
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Jaik.127154
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Jaik.127154
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Jaik.127154
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.GGOH
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/GenKryptik.9051f230
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Undefined!8.C (TFE:5:cXDm1r1m2sI)
Emsisoft Gen:Variant.Jaik.127154 (B)
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Jaik.127154
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Generic.mg.01d648ecf27b3e9a
Sophos ML/PE-A
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.Jaik.127154
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen
MAX malware (ai score=86)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Jaik.D1F0B2
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!01D648ECF27B
TACHYON Clean
VBA32 BScope.TrojanSpy.Zbot
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Generic.Iqil
Yandex Trojan.GenAsa!SyceT1P2laA
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet W32/GenKryptik.GGOH!tr
BitDefenderTheta Gen:NN.ZexaF.36308.Rq0@aWsJZ9pi
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.