Static | ZeroBOX

PE Compile Time

2010-12-20 20:38:55

PE Imphash

98ce7b6533cbd67993e36dafb4e95946

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005234 0x00005400 5.79136178315
.data 0x00007000 0x0000005c 0x00000200 1.18392471514
.rdata 0x00008000 0x00001050 0x00001200 4.97061703548
.bss 0x0000a000 0x0000019c 0x00000000 0.0
.idata 0x0000b000 0x00000b50 0x00000c00 4.64668887482
.CRT 0x0000c000 0x00000018 0x00000200 0.114463381259
.tls 0x0000d000 0x00000020 0x00000200 0.22482003451

Imports

Library KERNEL32.dll:
0x40b228 CloseHandle
0x40b22c CreatePipe
0x40b230 CreateProcessA
0x40b234 CreateThread
0x40b23c DisconnectNamedPipe
0x40b240 DuplicateHandle
0x40b248 ExitProcess
0x40b24c ExitThread
0x40b250 FreeConsole
0x40b254 FreeLibrary
0x40b258 GetCurrentProcess
0x40b25c GetLastError
0x40b260 GetModuleHandleA
0x40b264 GetProcAddress
0x40b268 GetStdHandle
0x40b274 LoadLibraryA
0x40b278 PeekNamedPipe
0x40b27c ReadFile
0x40b284 Sleep
0x40b288 TerminateProcess
0x40b28c TerminateThread
0x40b290 TlsGetValue
0x40b294 VirtualProtect
0x40b298 VirtualQuery
0x40b2a0 WriteFile
Library msvcrt.dll:
0x40b2a8 _close
0x40b2ac _dup
0x40b2b0 _itoa
0x40b2b4 _kbhit
0x40b2b8 _open
0x40b2bc _read
0x40b2c0 _strcmpi
0x40b2c4 _strnicmp
0x40b2c8 _write
Library msvcrt.dll:
0x40b2d0 __getmainargs
0x40b2d4 __p__environ
0x40b2d8 __p__fmode
0x40b2dc __set_app_type
0x40b2e0 _cexit
0x40b2e4 _errno
0x40b2e8 _iob
0x40b2ec _isatty
0x40b2f0 _onexit
0x40b2f4 _setjmp
0x40b2f8 _setmode
0x40b2fc _sleep
0x40b300 _winmajor
0x40b304 abort
0x40b308 atexit
0x40b30c atoi
0x40b310 calloc
0x40b314 exit
0x40b318 fflush
0x40b31c fprintf
0x40b320 fputc
0x40b324 free
0x40b328 fwrite
0x40b32c getenv
0x40b330 gets
0x40b334 longjmp
0x40b338 malloc
0x40b33c memcmp
0x40b340 memcpy
0x40b344 memset
0x40b348 rand
0x40b34c signal
0x40b350 sprintf
0x40b354 srand
0x40b358 strcat
0x40b35c strchr
0x40b360 strcmp
0x40b364 strcpy
0x40b368 strlen
0x40b36c strncmp
0x40b370 strncpy
0x40b374 time
0x40b378 vfprintf
Library WSOCK32.DLL:
0x40b380 WSACleanup
0x40b384 WSAGetLastError
0x40b388 WSASetLastError
0x40b38c WSAStartup
0x40b390 __WSAFDIsSet
0x40b394 accept
0x40b398 bind
0x40b39c closesocket
0x40b3a0 connect
0x40b3a4 gethostbyaddr
0x40b3a8 gethostbyname
0x40b3ac getservbyname
0x40b3b0 getservbyport
0x40b3b4 getsockname
0x40b3b8 htons
0x40b3bc inet_addr
0x40b3c0 inet_ntoa
0x40b3c4 listen
0x40b3c8 ntohs
0x40b3cc recv
0x40b3d0 recvfrom
0x40b3d4 select
0x40b3d8 send
0x40b3dc setsockopt
0x40b3e0 shutdown
0x40b3e4 socket

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.idata
(UNKNOWN)
sent %d, rcvd %d
0123456789abcdef
libgcj-11.dll
_Jv_RegisterClasses
POSIXLY_CORRECT
%s: option `%s' is ambiguous
%s: option `--%s' doesn't allow an argument
%s: option `%c%s' doesn't allow an argument
%s: option `%s' requires an argument
%s: unrecognized option `--%s'
%s: unrecognized option `%c%s'
%s: illegal option -- %c
%s: invalid option -- %c
%s: option requires an argument -- %c
Failed to create shell stdout pipe, error = %s
Failed to create shell stdin pipe, error = %s
Failed to execute shell
Failed to create ReadShell session thread, error = %s
WaitForMultipleObjects error: %s
Failed to execute shell, error = %s
SessionReadShellThreadFn exitted, error = %s
INTR
BADF
ACCES
FAULT
INVAL
MFILE
WOULDBLOCK
INPROGRESS
ALREADY
NOTSOCK
DESTADDRREQ
MSGSIZE
PROTOTYPE
NOPROTOOPT
PROTONOSUPPORT
SOCKTNOSUPPORT
OPNOTSUPP
PFNOSUPPORT
AFNOSUPPORT
ADDRINUSE
ADDRNOTAVAIL
NETDOWN
NETUNREACH
NETRESET
CONNABORTED
CONNRESET
NOBUFS
ISCONN
NOTCONN
SHUTDOWN
TOOMANYREFS
TIMEDOUT
connection refused
LOOP
NAMETOOLONG
HOSTDOWN
HOSTUNREACH
NOTEMPTY
PROCLIM
USERS
DQUOT
STALE
REMOTE
DISCON
SYSNOTREADY
VERNOTSUPPORTED
NOTINITIALISED
HOST_NOT_FOUND
TRY_AGAIN
NO_RECOVERY
NO_DATA
unknown socket error
punt!
spurious timer interrupt!
Hmalloc %d failed
DNS fwd/rev mismatch: %s != %s
gethostpoop fuxored
Can't parse %s as an IP address
%s: forward host lookup failed: h_errno %d
Warning: inverse host lookup failed for %s: h_errno %d
%s: inverse host lookup failed: h_errno %d
Warning: forward host lookup failed for %s: h_errno %d
Warning: port-bynum mismatch, %d != %d
loadports: no block?!
loadports: bogus values %d, %d
Can't get socket
nnetfd reuseaddr failed
retrying local %s:%d
Can't grab %s:%d with bind
Warning: source routing unavailable on this machine, ignoring
UDP listen needs -p arg
local listen fuxored
local getsockname failed
listening on [
] %d ...
post-rcv getsockname failed
invalid connection to [%s] from %s [%s] %d
connect to [%s] from %s [%s] %d
udptest first write failed?! errno %d
oprint called with no open fd?!
%8.8x
ofd write err
select fuxored
net timeout
Preposterous Pointers: %d, %d
too many output retries
Cmd line:
all-A-records NIY
invalid hop pointer %d, must be multiple of 4 <= 28
too many -g hops
invalid interval time %s
invalid local port %s
invalid wait-time %s
nc -h for help
ade:g:G:hi:lLno:p:rs:tuvw:z
can't open %s
invalid port %s
no connection
no destination
no port[s] to connect to
%s [%s] %d (%s) open
%s [%s] %d (%s)
sent %d, rcvd %d
[v1.11 NT www.vulnwatch.org/netcat/]
connect to somewhere:
nc [-options] hostname port[s] [ports] ...
listen for inbound:
nc -l -p port [options] [hostname] [port]
options:
detach from console, background mode
-e prog
inbound program to exec [dangerous!!]
-g gateway
source-routing hop point[s], up to 8
-G num
source-routing pointer: 4, 8, 12, ...
this cruft
-i secs
delay interval for lines sent, ports scanned
listen mode, for inbound connects
listen harder, re-listen on socket close
numeric-only IP addresses, no DNS
-o file
hex dump of traffic
-p port
local port number
randomize local and remote ports
-s addr
local source address
answer TELNET negotiation
UDP mode
verbose [use twice to be more verbose]
-w secs
timeout for connects and final net reads
zero-I/O mode [used for scanning]
port numbers can be individual or ranges: m-n [inclusive]
mingwm10.dll
__mingwthr_remove_key_dtor
__mingwthr_key_dtor
Mingw runtime failure:
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
CloseHandle
CreatePipe
CreateProcessA
CreateThread
DeleteCriticalSection
DisconnectNamedPipe
DuplicateHandle
EnterCriticalSection
ExitProcess
ExitThread
FreeConsole
FreeLibrary
GetCurrentProcess
GetLastError
GetModuleHandleA
GetProcAddress
GetStdHandle
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
PeekNamedPipe
ReadFile
SetUnhandledExceptionFilter
TerminateProcess
TerminateThread
TlsGetValue
VirtualProtect
VirtualQuery
WaitForMultipleObjects
WriteFile
_close
_kbhit
_strcmpi
_strnicmp
_write
__getmainargs
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_isatty
_onexit
_setjmp
_setmode
_sleep
_winmajor
atexit
calloc
fflush
fprintf
fwrite
getenv
longjmp
malloc
memcmp
memcpy
memset
signal
sprintf
strcat
strchr
strcmp
strcpy
strlen
strncmp
strncpy
vfprintf
WSACleanup
WSAGetLastError
WSASetLastError
WSAStartup
__WSAFDIsSet
accept
closesocket
connect
gethostbyaddr
gethostbyname
getservbyname
getservbyport
getsockname
inet_addr
inet_ntoa
listen
recvfrom
select
setsockopt
shutdown
socket
KERNEL32.dll
msvcrt.dll
msvcrt.dll
WSOCK32.DLL
Unizeto Sp. z o.o.1
Certum CA0
090303125815Z
240303125815Z0
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1'0%
Certum Time-Stamping Authority0
http://crl.certum.pl/ca.crl0
http://tsa.certum.pl0
Unizeto Sp. z o.o.1
Certum CA0
090303125356Z
240303125356Z0x1
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1
Certum Level III CA0
\K|.IG
*j^XhM
Unizeto Sp. z o.o.1
Certum CA
http://crl.certum.pl/ca.crl0:
https://www.certum.pl/CPS0
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1
Certum Level III CA0
100831145611Z
110901145611Z0
Open Source Developer1
'Jernej Simoncic - Open Source Developer1
jernej@ena.si0
http://crl.certum.pl/l3.crl0Z
http://ocsp.certum.pl0'
http://www.certum.pl/l3.cer0
https://www.certum.pl/CPS0
Unizeto Technologies S.A.0
Usage of this certificate is strictly subjected to the CERTUM Certification
Practice Statement (CPS) incorporated by reference herein and in the repository
at https://www.certum.pl/repository.0
'lGuL8$
n>f+Hh
PL1"0
Unizeto Technologies S.A.1'0%
Certum Certification Authority1
Certum Level III CA
`OyIiM
Unizeto Sp. z o.o.1
Certum CA
101226122634Z0#
1g0e0c0a
Unizeto Sp. z o.o.1
Certum CA
<<<Obsolete>>
Antivirus Signature
Bkav Clean
Lionic Riskware.Win32.NetCat.1!c
Elastic malicious (high confidence)
DrWeb Tool.Netcat.395
MicroWorld-eScan Application.Generic.3167874
ClamAV Win.Trojan.Generic-9878071-0
FireEye Generic.mg.e0db1d3d47e312ef
CAT-QuickHeal HackTool.Netcat.E1
ALYac Misc.HackTool.NetCat
Malwarebytes Clean
VIPRE Application.Generic.3167874
Sangfor Clean
K7AntiVirus Hacktool ( 000047b11 )
BitDefender Application.Generic.3167874
K7GW Hacktool ( 000047b11 )
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/S-d35e0370!Eldorado
Symantec NetCat
tehtris Clean
ESET-NOD32 a variant of Win32/RemoteAdmin.NetCat.AM potentially unsafe
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky not-a-virus:RemoteAdmin.Win32.NetCat.bnm
Alibaba Clean
NANO-Antivirus Riskware.Win32.Netcat.ebbxjp
ViRobot NetTool.NetCat.36528
Rising Hacktool.NetCat!8.7CA (CLOUD)
Sophos NetCat (PUA)
F-Secure Clean
Baidu Clean
Zillya Adware.BrowseFox.Win32.194079
TrendMicro HKTL_NETCAT
McAfee-GW-Edition NetCat
Trapmine Clean
CMC Clean
Emsisoft Application.Generic.3167874 (B)
Ikarus PUA.Tool
GData Application.Generic.3167874
Jiangmin RemoteAdmin.NetCat.s
Webroot Pua.Remoteadmin.Netcat
Avira Clean
MAX malware (ai score=99)
Antiy-AVL Trojan/Win32.SGeneric
Gridinsoft Risk.NetCat.sd!c
Xcitium Clean
Arcabit Application.Generic.D305682
SUPERAntiSpyware Hack.Tool/Gen-RemoteAdmin
ZoneAlarm not-a-virus:RemoteAdmin.Win32.NetCat.bnm
Microsoft HackTool:Win32/NetCat
Google Detected
AhnLab-V3 HackTool/Win.Netcat.C5350697
Acronis Clean
McAfee NetCat
TACHYON Trojan/W32.Cometer.36528
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall HKTL_NETCAT
Tencent Clean
Yandex Riskware.RemoteAdmin!I48oIyZSh24
SentinelOne Clean
MaxSecure Trojan.Malware.4320.susgen
Fortinet Riskware/NetCat
AVG Clean
Avast Clean
CrowdStrike win/grayware_confidence_100% (W)
No IRMA results available.