Static | ZeroBOX

PE Compile Time

2022-05-02 20:51:30

PE Imphash

09d0478591d4f788cb3e5ea416c25237

PEiD Signatures

PECompact 2.xx --> BitSum Technologies

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00048000 0x00019400 7.99821672658
.rsrc 0x00049000 0x00002000 0x00001600 7.5204613337
.reloc 0x0004b000 0x00000200 0x00000200 0.24044503451

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00049058 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library kernel32.dll:
0x4491d0 LoadLibraryA
0x4491d4 GetProcAddress
0x4491d8 VirtualAlloc
0x4491dc VirtualFree

!This program cannot be run in DOS mode.
PEC2~O
.reloc
CQ2l5b
>fR&u.
kW]9cy
Dr3?th
]WZQ^G
LKzIkK*
O?daYBm*
1Ti#0m
FNN7>L
<i{G '$
MkYpjWu
Rxai6GGhKm
Ny%a4\
x{?@xB
C=s77hL
"FLVX{
wR,$9+
QP3yuJ
|R7VbZ
Y6*#H2I5A
f(B5:RF:CPn
i\6fw^
`id}0
UD[{]]M
j[39]AB:Kj
2]@:b
H>Ia+B
IQ/]I>p
wnKQ-%
ElrT5;
4=,:;^5/
gr&~%'h
CI~N8,f
w;38\2
~gf|QdT
#Z1>O0
-pV\AZ~
24NF*s
@zw["s4dyR
}2LXjE*
,6<WVjo
3Vn[Y:.
~^ )xI
d5E8:qZ.7
0R/ND({
m7XTr
c5>D*z
y<KYV@
=LM694
Xk!}S]
tY WtO(
[Qjc&=
#t*w?b?M
Vzl$&'
wK'["
c8mFPaK
p^tT5(!
-nGy8$^_
TS%F0U
Z`:9c7
J}mIbXFF
?$C(!C
X/(vu
G2.&Mi
_9ZHyx
l3;VT
>%|_8.{xJ
<WK7w}
/B!TP
u}?L@
uO+:Hj^
n|4%@g
LJdrPw7x
/X?7=R
|ML zr
BgFbk.
Jx!ve*
TD6fhaZ
}O7D $6
B=-['+
xQ&XF+
O,.2}r
kIaDsaZ
E*p=h3
csml0p(
"q:v5hzn
q74~%3
-*;}R3\4
<7$Z_;
x7h7YxS
zO9QT#
3z8~p=
`N<~/g
#dVC]<
Y,L'Huf
F,^&}`9
Wr{y_^-
Lq]U=x
R>]~$b
X4Gp&
l[g 6J
)2z/!
H 46ks
nezFoR
dQ&MQ:[|
FqA-A^X
(0lQPFGA
UE'aJq
PaaJL!
:NJooC
\0Of`]
er/`*k
F(1I\\
fZ>BOw
IN1bI,
L7oS$3
SomRnG
3HcUw u
x^)nHS
]`Af\$
qf|yE=
u>cnT0`
\@x#Aq
7$c%BU
1anp.x
J'@Zb
o%Cr.(
Wu)G2{
6V&L!D
z8KRr~a
pI^Ve0
>nHq27
*dTRN%m
Nxbm"w
c,E8n~
6v+od;u
,"]Q[N_8
k=OE5j
#Lg!OV
j!I=uM4
3KH:~o
Y4)TLg
O;|dG$-%
${P n
K[T9C"
9JKptw
,1KlwV
/H_L&\
fQ`}b_b
u [+T+
]%rA+<M7w7
cdox2(
232zCn
hH)>)W
7}z72.HE
$yBj@Z
W:S0|A
~5"zRQR
R)?g/%
ux[epR
oN?/!>g
d>y-_b
V]9r"v
$e/GIb
4y`K+*
Gk44X8
/`kDTr
y\%\lpn
nk}myMq`
J?b|$hD
ggF5:"8
PECompact2
"[%)^2
iR}:QC
J>}r+`
K`htJ)
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kernel32.dll
LoadLibraryA
GetProcAddress
VirtualAlloc
VirtualFree
t4yVy~?
k!3HkFl
2;#$yM
kernbl32
yu&!6
w8I)R|
t5;u*X0
-I-@<H!VWBx
1ttv*u
d,7al z3W
BoxpA{w
USQWVR
Z^_Y[]
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.NetWiredRC.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Generic.Malware.SPVPk!.E723D6C4
ClamAV Clean
FireEye Generic.mg.a6a9abf50eb980d1
CAT-QuickHeal Clean
ALYac Generic.Malware.SPVPk!.E723D6C4
Malwarebytes Spyware.KeyLogger
VIPRE Generic.Malware.SPVPk!.E723D6C4
Sangfor Spyware.Win32.KeyLogger.Vpey
CrowdStrike win/malicious_confidence_70% (W)
BitDefender Generic.Malware.SPVPk!.E723D6C4
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Spy.KeyLogger.RJA
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Backdoor.Win32.NetWiredRC.maf
Alibaba TrojanSpy:Win32/KeyLogger.f88464c0
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Backdoor.NetWiredRC!8.2AF (CLOUD)
Emsisoft Generic.Malware.SPVPk!.E723D6C4 (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.cc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Clean
Ikarus Trojan-Spy.Win32.KeyLogger
GData Generic.Malware.SPVPk!.E723D6C4
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Spy.KeyLogger.fvubr
MAX malware (ai score=83)
Antiy-AVL Trojan[Spy]/Win32.KeyLogger
Gridinsoft Clean
Xcitium Malware@#3i2kt6cvp1358
Arcabit Generic.Malware.SPVPk!.E723D6C4
ViRobot Clean
ZoneAlarm Backdoor.Win32.NetWiredRC.maf
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic PWS.y
TACHYON Clean
VBA32 BScope.TrojanSpy.Win64.AntiAV
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DCK23
Tencent Win32.Backdoor.Netwiredrc.Zmhl
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat.RF
BitDefenderTheta Gen:NN.ZexaF.36344.gmWfamFS1kki
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.