Static | ZeroBOX

PE Compile Time

2022-02-15 13:15:37

PE Imphash

6ed4f5f04d62b18d96b26d6db7c18840

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00044000 0x00000000 0.0
UPX1 0x00045000 0x0001d000 0x0001c200 7.78143587073
UPX2 0x00062000 0x00001000 0x00000200 1.38215794943

Imports

Library KERNEL32.DLL:
0x462028 LoadLibraryA
0x46202c ExitProcess
0x462030 GetProcAddress
0x462034 VirtualProtect

!This program cannot be run in DOS mode.
RichMdy
<32.dl
"R<r3l
ssHeapvj
6xfHPQn
irtua<
A0IsBaU
i\KERN
4MEL32.d
C`_a$w
Wl{mY=D$
rt.;t$$t(
x*nXZU
1-i*R/
N_t."$
`l7+H
vmI70#(
b@vo$h
1VC20XC00
tAYC8I^
3cGmf*1
Q`/~MED
9R!\*C
-8zJo+
5M.ipdz
"rI?j
t#>D}4"
"79iup
H}Bhi3
=CwWt1j
< 69Ly
L7Ociae
(>rWSVrN
!Ta.lh
Vzh^tD
!.~HX2Ft%
g2lMpR
AHI{Y8
yE}~a|
C``I`#'
S9[Ej!%
yE5:B^
y2@\hz
mlock.c/b
bgdelHpp
_BLOCK_TYPE_IS_VA
LID(pHead->nBUse)
tidtable
stlnvpu
{yargva_,
ioinit
_HEAP_SELE]@~
CTED/MSVCRT_r
un4me error
f$#R6028
to !ializ
poO7notz
spacFf
wiqa0B
"o5purVvir
tuBfJcG c
Hc|kxh
m#vb0l_09
TV`\w4B
W8DuQOP
isUC++ RALibr
!".s:AP
n>6CD.
ookWfail`
DM]()'IsVO
~,^HNP
7IGNORE_L
& =lReque
Ew-0x%@X
oBADPTR
aks(As
kof!'`X
zpt_^Str
F#s, L
`32.d7$8`
2M,ag~!=
veM0{7
pup'W^
P9 (8?{
_T('\0'OgetB
wg3wEhFa
Th$s'W0
wo_OG?&
%@\2"
y3w.xy9.
8x}qmay%M
pj"2`M
Cj@$q/h
#}TJ~0
a!6Dtp
Ee1]"E9Q:
,h_)q&
-U)7#B
v8|{h;
fO.wH7trn
wt_Y-B
jiB$a:
;Pzd-9"6@
**9H;E
A:'H8F
F~ u30
)UzF`t
)DA"G`
/<NeSd_(N
NudRs\^
[|8[.:
?i:>$>
h3hhN<
(;Ep[F+
#$=gfF
x3y{#6
&;Y<Je
*|(5#Y
![;m\!
)v1&/:
&k*8i
#=Es"s
5ECZn
UZS|$|
$SEz^)
74[=>@>:;\
;+.'Bq
-VWXjy
\% ot.
*AAd?:I
Q4s^I>q
29z-!l
<[aVP_
rfKZ\}/q
:12^rFpK
3F=g!~
+D5GrM
+:HtDF
yN*7-+
H(6f h|a
\ea1}&
X5<Lf4OMq
Rz7'7p
AK'C;>5
dD)=q.
ps+\{
L &85u
E:nZl~
?T?+GC
YQ9OWw
drzNCx*nd
[3./lt
SSu(L[
#|OwTt
/dp'~n,
A`z`v=
(k,=5d
P2Rf`
wH&4p
)gB*c:n
7'3-Y!
rX(3onW
y5)>\U
e|evP7
#-#(|D{
?t5"7}
j! P@5
wkBknq
h(fx%bS2
;BW,SR
S7",!-r
=frBccT1
8D6sAE
|1pc[NJ
Gh-}TOK
8$e36,
e.a/)z
y0c;r1
u42{J$
ab9Qz-
ATMIei
i4d!`od
MyW"EL
-g_#8U
,-\xTE
"0utNC
qC|El
d-La@bF
xp2#S/
9dceo\e
qv^UJ_M
#P*/_H
rgPSq5r
ZYw-@J@C
@*6eQfG
!2q*sj@
< @StudyHard
kernel
KERNEL
.H?AV
ld\]HZ
v;9CPgR/S
TH@40,<
!Comm>
nCV=8h
+LeavW
((k,>n
F2sh?-Y
XPTPSW
KERNEL32.DLL
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.loFa
Elastic malicious (moderate confidence)
MicroWorld-eScan DeepScan:Generic.Malware.Lco.C9305D62
CMC Clean
CAT-QuickHeal Trojan.Farfli
ALYac DeepScan:Generic.Malware.Lco.C9305D62
Malwarebytes Clean
Zillya Trojan.Kryptik.Win32.3717602
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00562edc1 )
BitDefender DeepScan:Generic.Malware.Lco.C9305D62
K7GW Trojan ( 00562edc1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/Trojan.LBET-0583
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HCAH
APEX Malicious
Paloalto generic.ml
ClamAV Win.Dropper.Farfli-9950039-0
Kaspersky HEUR:Backdoor.Win32.Farfli.gen
Alibaba Backdoor:Win32/Farfli.3bff50a1
NANO-Antivirus Trojan.Win32.Kryptik.jmvgmk
SUPERAntiSpyware Clean
Rising Trojan.Kryptik!1.E27A (CLOUD)
TACHYON Trojan/W32.Agent.385024.ADI
Emsisoft DeepScan:Generic.Malware.Lco.C9305D62 (B)
F-Secure Clean
DrWeb Trojan.Siggen11.63246
VIPRE DeepScan:Generic.Malware.Lco.C9305D62
TrendMicro TROJ_GEN.R002C0DCH23
Trapmine malicious.high.ml.score
FireEye Generic.mg.f1ec2cf6256a7c85
Sophos Troj/Farfli-EA
Ikarus Trojan.Win32.Injector
GData DeepScan:Generic.Malware.Lco.C9305D62
Jiangmin Backdoor.Farfli.eqx
Webroot Clean
Google Detected
Avira TR/Crypt.XPACK.Gen
Antiy-AVL GrayWare/Win32.Kryptik.ffp
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Backdoor.Win32.Farfli.FK@7jqjxo
Arcabit DeepScan:Generic.Malware.Lco.C9305D62
ViRobot Trojan.Win.Z.Kryptik.116736.D
ZoneAlarm Clean
Microsoft Trojan:Win32/Farfli.CT!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.OX.C4976986
Acronis Clean
McAfee Artemis!F1EC2CF6256A
MAX malware (ai score=88)
VBA32 Trojan.Farfli
Cylance unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DCH23
Tencent Backdoor.Win32.farfli.zf
Yandex Trojan.GenAsa!gBhknYBDYco
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Generic.AP.322A94!tr
BitDefenderTheta Gen:NN.ZexaF.36344.hmGfa84CnWm
AVG Win32:BackdoorX-gen [Trj]
Avast Win32:BackdoorX-gen [Trj]
No IRMA results available.