Static | ZeroBOX

PE Compile Time

2023-07-19 17:12:00

PE Imphash

e623cecc3195834a15144a4d38dde690

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00002e94 0x00003000 6.04843714378
.data 0x00004000 0x0000001c 0x00000200 0.222389470473
.rdata 0x00005000 0x00000380 0x00000400 4.62987699996
/4 0x00006000 0x000009b4 0x00000a00 4.75638770628
.bss 0x00007000 0x00000070 0x00000000 0.0
.idata 0x00008000 0x00000714 0x00000800 4.36537400449
.CRT 0x00009000 0x00000018 0x00000200 0.0980041756627
.tls 0x0000a000 0x00000020 0x00000200 0.22482003451
/14 0x0000b000 0x00000038 0x00000200 0.21620690744
/29 0x0000c000 0x00001cff 0x00001e00 5.76798971325
/41 0x0000e000 0x0000012f 0x00000200 3.04408429956
/55 0x0000f000 0x000001c8 0x00000200 4.31030910284
/67 0x00010000 0x00000038 0x00000200 0.678482794849

Imports

Library KERNEL32.dll:
0x408170 CloseHandle
0x408174 CreateProcessA
0x408180 ExitProcess
0x408184 FindClose
0x408188 FindFirstFileA
0x40818c FindNextFileA
0x408190 FreeLibrary
0x408194 GetCommandLineA
0x408198 GetLastError
0x40819c GetModuleHandleA
0x4081a0 GetProcAddress
0x4081ac LoadLibraryA
0x4081b4 TlsGetValue
0x4081b8 VirtualProtect
0x4081bc VirtualQuery
0x4081c0 WaitForSingleObject
Library msvcrt.dll:
0x4081c8 _strdup
0x4081cc _stricoll
Library msvcrt.dll:
0x4081d4 __getmainargs
0x4081d8 __mb_cur_max
0x4081dc __p__environ
0x4081e0 __p__fmode
0x4081e4 __set_app_type
0x4081e8 _cexit
0x4081ec _errno
0x4081f0 _fpreset
0x4081f4 _fullpath
0x4081f8 _iob
0x4081fc _isctype
0x408200 _onexit
0x408204 _pctype
0x408208 _setmode
0x40820c abort
0x408210 atexit
0x408214 calloc
0x408218 free
0x40821c fwrite
0x408220 malloc
0x408224 mbstowcs
0x408228 memcpy
0x40822c memset
0x408230 puts
0x408234 realloc
0x408238 setlocale
0x40823c signal
0x408240 strcoll
0x408244 strlen
0x408248 tolower
0x40824c vfprintf
0x408250 wcstombs
Library WS2_32.dll:
0x408258 WSACleanup
0x40825c WSAConnect
0x408260 WSASocketA
0x408264 WSAStartup
0x408268 closesocket
0x40826c htons
0x408270 inet_addr
0x408274 recv

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.idata
t(<{t?
</t&<\t"
libgcc_s_dw2-1.dll
__register_frame_info
__deregister_frame_info
libgcj-16.dll
_Jv_RegisterClasses
3.22.15.135
[!] Connecting...
[!] Connected
[!] Creating process...
cmd.exe
[!] Failed to create process
[!] Process successfully created
[!] Exiting
[!] Failed to Connect
Mingw runtime failure:
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
glob-1.0-mingw32
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (MinGW.org GCC-6.3.0-1) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
CloseHandle
CreateProcessA
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileA
FindNextFileA
FreeLibrary
GetCommandLineA
GetLastError
GetModuleHandleA
GetProcAddress
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
WaitForSingleObject
_strdup
_stricoll
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_fpreset
_fullpath
_isctype
_onexit
_pctype
_setmode
atexit
calloc
fwrite
malloc
mbstowcs
memcpy
memset
realloc
setlocale
signal
strcoll
strlen
tolower
vfprintf
wcstombs
WSACleanup
WSAConnect
WSASocketA
WSAStartup
closesocket
inet_addr
KERNEL32.dll
msvcrt.dll
msvcrt.dll
WS2_32.dll
../../../src/gcc-6.3.0/libgcc/config/i386/cygwin.S
/home/keith/src/mingw/gcc-build/gcc-6.3.0-mingw32-cross-native/mingw32/libgcc
GNU AS 2.28
GNU C11 6.3.0 -mtune=generic -march=i586 -g -g -g -O2 -O2 -O2 -fbuilding-libgcc -fno-stack-protector
../../../src/gcc-6.3.0/libgcc/libgcc2.c
/home/keith/src/mingw/gcc-build/gcc-6.3.0-mingw32-cross-native/mingw32/libgcc
unsigned int
short unsigned int
long long int
long double
long int
_iobuf
_charbuf
_bufsiz
_tmpfname
short int
long unsigned int
__mb_cur_max
_sys_nerr
_sys_errlist
_osver
_winver
_winmajor
_winminor
_fmode
sizetype
optind
optopt
opterr
optarg
_daylight
_timezone
_tzname
daylight
timezone
tzname
hashval_t
htab_hash
htab_eq
htab_hash_pointer
htab_eq_pointer
unsigned char
stringop_alg
no_stringop
libcall
rep_prefix_1_byte
rep_prefix_4_byte
rep_prefix_8_byte
loop_1_byte
unrolled_loop
vector_loop
last_alg
unspec_strings
unspecv_strings
stringop_strategy
noalign
stringop_algs
unknown_size
processor_costs
shift_var
shift_const
mult_init
mult_bit
divide
large_insn
move_ratio
movzbl_load
int_load
int_store
fp_move
fp_load
fp_store
mmx_move
mmx_load
mmx_store
sse_move
sse_load
sse_store
mmxsse_to_integer
l1_cache_size
l2_cache_size
prefetch_block
simultaneous_prefetches
branch_cost
memcpy
memset
scalar_stmt_cost
scalar_load_cost
scalar_store_cost
vec_stmt_cost
vec_to_scalar_cost
scalar_to_vec_cost
vec_align_load_cost
vec_unalign_load_cost
vec_store_cost
cond_taken_branch_cost
cond_not_taken_branch_cost
ix86_cost
ix86_size_cost
ix86_tune_indices
X86_TUNE_SCHEDULE
X86_TUNE_PARTIAL_REG_DEPENDENCY
X86_TUNE_SSE_PARTIAL_REG_DEPENDENCY
X86_TUNE_SSE_SPLIT_REGS
X86_TUNE_PARTIAL_FLAG_REG_STALL
X86_TUNE_MOVX
X86_TUNE_MEMORY_MISMATCH_STALL
X86_TUNE_FUSE_CMP_AND_BRANCH_32
X86_TUNE_FUSE_CMP_AND_BRANCH_64
X86_TUNE_FUSE_CMP_AND_BRANCH_SOFLAGS
X86_TUNE_FUSE_ALU_AND_BRANCH
X86_TUNE_REASSOC_INT_TO_PARALLEL
X86_TUNE_REASSOC_FP_TO_PARALLEL
X86_TUNE_ACCUMULATE_OUTGOING_ARGS
X86_TUNE_PROLOGUE_USING_MOVE
X86_TUNE_EPILOGUE_USING_MOVE
X86_TUNE_USE_LEAVE
X86_TUNE_PUSH_MEMORY
X86_TUNE_SINGLE_PUSH
X86_TUNE_DOUBLE_PUSH
X86_TUNE_SINGLE_POP
X86_TUNE_DOUBLE_POP
X86_TUNE_PAD_SHORT_FUNCTION
X86_TUNE_PAD_RETURNS
X86_TUNE_FOUR_JUMP_LIMIT
X86_TUNE_SOFTWARE_PREFETCHING_BENEFICIAL
X86_TUNE_LCP_STALL
X86_TUNE_READ_MODIFY
X86_TUNE_USE_INCDEC
X86_TUNE_INTEGER_DFMODE_MOVES
X86_TUNE_OPT_AGU
X86_TUNE_AVOID_LEA_FOR_ADDR
X86_TUNE_SLOW_IMUL_IMM32_MEM
X86_TUNE_SLOW_IMUL_IMM8
X86_TUNE_AVOID_MEM_OPND_FOR_CMOVE
X86_TUNE_SINGLE_STRINGOP
X86_TUNE_MISALIGNED_MOVE_STRING_PRO_EPILOGUES
X86_TUNE_USE_SAHF
X86_TUNE_USE_CLTD
X86_TUNE_USE_BT
X86_TUNE_USE_HIMODE_FIOP
X86_TUNE_USE_SIMODE_FIOP
X86_TUNE_USE_FFREEP
X86_TUNE_EXT_80387_CONSTANTS
X86_TUNE_VECTORIZE_DOUBLE
X86_TUNE_GENERAL_REGS_SSE_SPILL
X86_TUNE_SSE_UNALIGNED_LOAD_OPTIMAL
X86_TUNE_SSE_UNALIGNED_STORE_OPTIMAL
X86_TUNE_SSE_PACKED_SINGLE_INSN_OPTIMAL
X86_TUNE_SSE_TYPELESS_STORES
X86_TUNE_SSE_LOAD0_BY_PXOR
X86_TUNE_INTER_UNIT_MOVES_TO_VEC
X86_TUNE_INTER_UNIT_MOVES_FROM_VEC
X86_TUNE_INTER_UNIT_CONVERSIONS
X86_TUNE_SPLIT_MEM_OPND_FOR_FP_CONVERTS
X86_TUNE_USE_VECTOR_FP_CONVERTS
X86_TUNE_USE_VECTOR_CONVERTS
X86_TUNE_SLOW_PSHUFB
X86_TUNE_VECTOR_PARALLEL_EXECUTION
X86_TUNE_AVOID_4BYTE_PREFIXES
X86_TUNE_AVX256_UNALIGNED_LOAD_OPTIMAL
X86_TUNE_AVX256_UNALIGNED_STORE_OPTIMAL
X86_TUNE_AVX128_OPTIMAL
X86_TUNE_DOUBLE_WITH_ADD
X86_TUNE_ALWAYS_FANCY_MATH_387
X86_TUNE_UNROLL_STRLEN
X86_TUNE_SHIFT1
X86_TUNE_ZERO_EXTEND_WITH_AND
X86_TUNE_PROMOTE_HIMODE_IMUL
X86_TUNE_FAST_PREFIX
X86_TUNE_READ_MODIFY_WRITE
X86_TUNE_MOVE_M1_VIA_OR
X86_TUNE_NOT_UNPAIRABLE
X86_TUNE_PARTIAL_REG_STALL
X86_TUNE_PROMOTE_QIMODE
X86_TUNE_PROMOTE_HI_REGS
X86_TUNE_HIMODE_MATH
X86_TUNE_SPLIT_LONG_MOVES
X86_TUNE_USE_XCHGB
X86_TUNE_USE_MOV0
X86_TUNE_NOT_VECTORMODE
X86_TUNE_AVOID_VECTOR_DECODE
X86_TUNE_AVOID_FALSE_DEP_FOR_BMI
X86_TUNE_BRANCH_PREDICTION_HINTS
X86_TUNE_QIMODE_MATH
X86_TUNE_PROMOTE_QI_REGS
X86_TUNE_ADJUST_UNROLL
X86_TUNE_ONE_IF_CONV_INSN
X86_TUNE_LAST
ix86_tune_features
ix86_arch_indices
X86_ARCH_CMOV
X86_ARCH_CMPXCHG
X86_ARCH_CMPXCHG8B
X86_ARCH_XADD
X86_ARCH_BSWAP
X86_ARCH_LAST
ix86_arch_features
x86_prefetch_sse
_dont_use_tree_here_
x86_mfence
reg_class
NO_REGS
AD_REGS
CLOBBERED_REGS
Q_REGS
NON_Q_REGS
INDEX_REGS
LEGACY_REGS
GENERAL_REGS
FP_TOP_REG
FP_SECOND_REG
FLOAT_REGS
SSE_FIRST_REG
NO_REX_SSE_REGS
SSE_REGS
EVEX_SSE_REGS
BND_REGS
ALL_SSE_REGS
MMX_REGS
FP_TOP_SSE_REGS
FP_SECOND_SSE_REGS
FLOAT_SSE_REGS
FLOAT_INT_REGS
INT_SSE_REGS
FLOAT_INT_SSE_REGS
MASK_EVEX_REGS
MASK_REGS
ALL_REGS
LIM_REG_CLASSES
dbx_register_map
dbx64_register_map
svr4_dbx_register_map
x86_64_ms_sysv_extra_clobbered_registers
processor_type
PROCESSOR_GENERIC
PROCESSOR_I386
PROCESSOR_I486
PROCESSOR_PENTIUM
PROCESSOR_LAKEMONT
PROCESSOR_PENTIUMPRO
PROCESSOR_PENTIUM4
PROCESSOR_NOCONA
PROCESSOR_CORE2
PROCESSOR_NEHALEM
PROCESSOR_SANDYBRIDGE
PROCESSOR_HASWELL
PROCESSOR_BONNELL
PROCESSOR_SILVERMONT
PROCESSOR_KNL
PROCESSOR_SKYLAKE_AVX512
PROCESSOR_INTEL
PROCESSOR_GEODE
PROCESSOR_K6
PROCESSOR_ATHLON
PROCESSOR_K8
PROCESSOR_AMDFAM10
PROCESSOR_BDVER1
PROCESSOR_BDVER2
PROCESSOR_BDVER3
PROCESSOR_BDVER4
PROCESSOR_BTVER1
PROCESSOR_BTVER2
PROCESSOR_ZNVER1
PROCESSOR_max
ix86_tune
ix86_arch
ix86_preferred_stack_boundary
ix86_incoming_stack_boundary
regclass_map
signed char
UQItype
long long unsigned int
complex float
double
complex double
complex long double
__float128
__unknown__
__popcount_tab
__clz_tab
func_ptr
__CTOR_LIST__
__DTOR_LIST__
../../../src/gcc-6.3.0/libgcc/config/i386
cygwin.S
""YK0g=YY0/>""
/home/keith/mingw32-gcc-6.3.0/include
../../../src/gcc-6.3.0/libgcc/../include
../.././gcc
../../../src/gcc-6.3.0/libgcc/../gcc/config/i386
../../../src/gcc-6.3.0/libgcc
stdio.h
stdlib.h
getopt.h
time.h
hashtab.h
insn-constants.h
i386.h
i386-opts.h
libgcc2.h
gbl-ctors.h
libgcc2.c
_atexit
__onexit0
cygming-crtbegin.c_obj
.rdata
reverse.c
.rdata
.idata$5t
.idata$6
.idata$5p
.idata$6
.idata$5l
.idata$6
.idata$5h
.idata$6
.idata$5d
.idata$6
.idata$5`
.idata$6
.idata$5\
.idata$6
.idata$5X
.idata$6
.idata$4L
.idata$5X
___main
.CRT$XDZ
.CRT$XDA
.CRT$XLA
.tls$ZZZ
.tls$AAA
.rdata
libgcc2.c
.rdata
.rdata
.idata$5P
.idata$6v
.idata$5L
.idata$6j
.idata$5H
.idata$6`
.idata$5D
.idata$6V
.idata$5@
.idata$6L
.idata$5<
.idata$6B
.idata$58
.idata$66
.idata$54
.idata$6,
.idata$50
.idata$6$
.idata$5,
.idata$6
.idata$5(
.idata$6
.idata$5$
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$6
.idata$6
.idata$5
.idata$6
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6v
.idata$5
.idata$6l
.idata$5
.idata$6L
.idata$5
.idata$6<
.idata$6,
.idata$5
.idata$6
.idata$4
.idata$5
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6z
.idata$5
.idata$6^
.idata$5
.idata$6L
.idata$5
.idata$68
.idata$5
.idata$6(
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5
.idata$6
.idata$5|
.idata$6
.idata$5x
.idata$6
.idata$5t
.idata$6
.idata$5p
.idata$6|
.idata$4d
.idata$5p
.idata$5
.idata$6
.idata$5
.idata$6
.idata$4
.idata$5
cygming-crtend.c
.idata$5
.idata$6
.idata$5
.idata$6Z
__cexit
__errno
_recv@16
___xl_c
___xl_z
_strcoll
__dll__
_fwrite
_memcpy
_memset
__argc
_tolower
___xl_a
___xl_d
__CRT_MTd
_strdup
__argv
_calloc
__fmode
_realloc(-
__end__
_signal
_malloc
_abort
_htons@4,
_strlen
.eh_frame
.debug_aranges
.debug_info
.debug_abbrev
.debug_line
.debug_frame
__mingw32_init_mainargs
_mainCRTStartup
_WinMainCRTStartup
_deregister_frame_fn
___JCR_LIST__
___gcc_register_frame
___gcc_deregister_frame
.eh_frame
.rdata$zzz
__setargv
___cpu_features_init
___do_global_dtors
___do_global_ctors
___dyn_tls_init@12
___tlregdtor
____w64_mingwthr_add_key_dtor
____w64_mingwthr_remove_key_dtor
___mingw_TLScallback
__pei386_runtime_relocator
.debug_info
.debug_abbrev
.debug_line
.debug_aranges
.debug_frame
_fesetenv
___mingw_glob
___mingw_globfree
___mingw_dirname
___mingw_opendir
___mingw_readdir
___mingw_closedir
___mingw_rewinddir
___mingw_telldir
___mingw_seekdir
___FRAME_END__
___JCR_END__
_register_frame_ctor
.text.startup
.ctors.65535
__imp__FindFirstFileA@8
_VirtualProtect@16
___RUNTIME_PSEUDO_RELOC_LIST__
__imp___fullpath
_FindFirstFileA@8
__imp___setmode
__imp__CloseHandle@4
__data_start__
_FreeLibrary@4
___DTOR_LIST__
__imp__VirtualProtect@16
__imp__recv@16
__imp___onexit
___p__fmode
__imp__GetLastError@0
_SetUnhandledExceptionFilter@4
__imp__VirtualQuery@12
__imp__FindNextFileA@8
___tls_start__
__imp__TlsGetValue@4
__libmsvcrt_a_iname
__imp__InitializeCriticalSection@4
_DeleteCriticalSection@4
__rt_psrelocs_start
__imp__abort
__dll_characteristics__
__size_of_stack_commit__
__size_of_stack_reserve__
__major_subsystem_version__
___crt_xl_start__
_CreateProcessA@40
___crt_xi_start__
___crt_xi_end__
__imp__stricoll
__imp____mb_cur_max
_GetLastError@0
_WSAConnect@28
__imp____p__environ
__imp___pctype
_VirtualQuery@12
_mingw_initltsdrot_force
__imp__CreateProcessA@40
__imp___iob
_GetModuleHandleA@4
___register_frame_info
__libmoldname_a_iname
_hmod_libgcc
.weak.___register_frame_info.___EH_FRAME_BEGIN__
__imp__strdup
_WSASocketA@24
__imp___isctype
__bss_start__
__head_libws2_32_a
___RUNTIME_PSEUDO_RELOC_LIST_END__
__fpreset
__size_of_heap_commit__
__imp___errno
___p__environ
__imp__GetProcAddress@8
_GetProcAddress@8
___crt_xp_start__
__imp__wcstombs
_GetCommandLineA@0
___crt_xp_end__
__imp__signal
__imp__puts
__minor_os_version__
__imp__atexit
__imp__mbstowcs
__head_libmsvcrt_a
__image_base__
__isctype
__section_alignment__
_LoadLibraryA@4
_wcstombs
__imp__FreeLibrary@4
__IAT_end__
__head_libmoldname_a
__RUNTIME_PSEUDO_RELOC_LIST__
__imp__htons@4
_setlocale
__imp____p__fmode
__tls_start
_ExitProcess@4
__imp__strcoll
__data_end__
___getmainargs
_FindClose@4
__CTOR_LIST__
_mbstowcs
___set_app_type
__bss_end__
__CRT_fmode
__imp__WaitForSingleObject@8
___crt_xc_end__
__imp__WSASocketA@24
__tls_index
___crt_xc_start__
__imp__closesocket@4
___CTOR_LIST__
__rt_psrelocs_size
_WSAStartup@8
_WaitForSingleObject@8
__imp__memcpy
_FindNextFileA@8
__imp__inet_addr@4
__file_alignment__
__imp__LeaveCriticalSection@4
__imp__malloc
___EH_FRAME_BEGIN__
__major_os_version__
_CloseHandle@4
__imp__realloc
__IAT_start__
_stricoll
__tls_end
__imp__GetModuleHandleA@4
__DTOR_LIST__
__imp___fpreset
.weak.___deregister_frame_info.___EH_FRAME_BEGIN__
_EnterCriticalSection@4
__imp__memset
__fullpath
__size_of_heap_reserve__
___crt_xt_start__
___ImageBase
__subsystem__
__imp__strlen
.weak.__Jv_RegisterClasses.___EH_FRAME_BEGIN__
__CRT_fenv
__imp__calloc
__Jv_RegisterClasses
__imp____getmainargs
___tls_end__
__imp__ExitProcess@4
_mingw_initltssuo_force
__imp__WSACleanup@0
_InitializeCriticalSection@4
___cpu_features
__imp__free
__imp__SetUnhandledExceptionFilter@4
___deregister_frame_info
__major_image_version__
__loader_flags__
__imp__tolower
__CRT_glob
__setmode
___chkstk_ms
_inet_addr@4
__head_libkernel32_a
__rt_psrelocs_end
__imp___cexit
__minor_subsystem_version__
__imp__FindClose@4
__minor_image_version__
__imp__vfprintf
_closesocket@4
__imp____set_app_type
_mingw_initltsdyn_force
_TlsGetValue@4
__imp__DeleteCriticalSection@4
_LeaveCriticalSection@4
__imp__WSAStartup@8
__imp__GetCommandLineA@0
__imp__LoadLibraryA@4
_WSACleanup@0
__imp__WSAConnect@28
__imp__setlocale
__RUNTIME_PSEUDO_RELOC_LIST_END__
__libkernel32_a_iname
___dyn_tls_init_callback
__tls_used
___crt_xt_end__
__libws2_32_a_iname
_vfprintf
__imp__EnterCriticalSection@4
__imp__fwrite
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.80cc187a15b6b634
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Reverseshell.Vtf3
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.36318.c0Y@aSjvDyg
VirIT Clean
Cyren W32/ReverseShell.B.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/ReverseShell.CB
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/ReverseShell.876844da
NANO-Antivirus Clean
ViRobot Clean
Rising Exploit.ShellCode!8.2A (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Worm.pm
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.68274196 (B)
Ikarus Win32.Outbreak
GData Trojan.GenericKD.68274196
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/ReverseShell.CB!tr
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.