Static | ZeroBOX

PE Compile Time

2023-09-07 19:23:27

PE Imphash

bc4f8e98d1041d53dd63bfb91ed10d0a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0004e000 0x00000000 0.0
UPX1 0x0004f000 0x00036000 0x00035600 7.93799843694
.rsrc 0x00085000 0x00005000 0x00004a00 3.53266392767

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007d5cc 0x000004f6 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000895e0 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x489724 RegCloseKey
Library GDI32.dll:
0x48972c BitBlt
Library gdiplus.dll:
0x489734 GdipFree
Library KERNEL32.DLL:
0x48973c LoadLibraryA
0x489740 ExitProcess
0x489744 GetProcAddress
0x489748 VirtualProtect
Library ole32.dll:
0x489750 CoGetObject
Library SHELL32.dll:
0x489758 ExtractIconA
Library SHLWAPI.dll:
0x489760 StrToIntA
Library urlmon.dll:
0x489768 URLDownloadToFileW
Library USER32.dll:
0x489770 DrawIcon
Library WININET.dll:
0x489778 InternetOpenW
Library WINMM.dll:
0x489780 waveInOpen
Library WS2_32.dll:
0x489788 socket

!This program cannot be run in DOS mode.
~Rich
/ SzhSv
X[+hY0
Kx (hb
TF>n`
JHMBj)
Hu\hw2
0-~p^;4v
K&@P[-
mPgVkk
w!k98t
)%?B3B
=t$(2|X>$V
,2(V8(K
;|8tK{
_[$K\-
AtDR)6
%`7"w7Ri%
T)8,zc
(,0aY/"
_3mM+pP,R+
HjA+sgO
\R968!
b&VPV-
T$L'}|,
;+(4;jQ
XIw1d@
Oz9~z
\U|\b
@OW$8 W[
IFZBr0
@wi3MB
NT[$&t
Cys\jC^
`8f8e2
r#D@hb
Y@R$D-
MUQIWz
RWi_ R
o3`f-$
"*X=YI
8@' )SS2[
Vj2e+sX8
p*onh/
'-?t>S
FjpE`g%
pwVtE.t1-t
q1x;D|j"=Q@
.E@p!H
70kuI%
vb'c0Se
tX_cPP
JRiN[B0
tWh09c
pWUUF|R
8M FB85
hDrUh\
b\j.v?K
0S11ab
h,",*K8
8PYj5!
*8%eYY
nj V"^
a83 D!
S2Xx%4T
shT-Tm
`9{Lt:V
|wex'^
tI4b7z
ZRJCE$
qF#A2(
UEVZ{r
yD[I-v!
{C`d 6V*
`Y<9X8t
F*pW^y
j~-`]MM
,<,TOSj@Z
P4+S4t
K0<p{a
<,ZxmU
NtF*,[c
ji%<YX9
l0uQVi
PItj[=
6=`PYNP
\U\6vY
5l N(V
u#h Y*%
NN]S+*<
;{MN+nd
za,g8k
rrrV`V
I*R,5h
L2T<$I
,kDh,8
_50;N
?^vR[n
 !"#$%&'(
)*+,-L.L
1L2L34L5678j9:;L<=>?@A
<BCDLEFGHIJK
p0jE.X
DB&dbw(
VuC~:NQW
lnPGSW
U +vW`/
]0qV3k
7$pFPW
'MuISbPh,x
7Bylk6p'/V
m,`Vi$
=~VU_gYs
ex{,V|
_sI:$`w
P_-*(6XA+J
j4w#$
Q%-E2$
#(PUQj
3<*l3U
kEe3)SO
JGh,~t
=tv4Cjn
E|G60yP
P}WV0<M
_9t'~+&
X<3^_[
4~(qF;
}?Pxo#
JQ@'w6
7UNB@=
r2.u%Y
2^3f"f$
Ffj Rb
~T$,=$
[kK6JP
~0Y mE
KP8d<h
@$(~Yy"
]<*u?N>~
:Tt%<.t<GR
qk0>n*
<jHCp4
!HlLK0R
W4{YB*d
^8{`Rc
J@<x@<D
'8%ujut,m
B1J22T
eR)Ih(
FDPW{m
s2y!ND
@/&HH|
3fhuu$
><2}I:rN
n&2tJ5-
1 32b'
9^ni$m4IlZ{
Bx{t"S
[f%g,s-<
VjPj+P
w4 .V@
:<9gsT
xVK)BQ
mF(RnG
Z#l U`
P$WEoa}G@
>)pllWRh
N;`Aw<oW
[Y'Z_#e
SzwF_8D
r,84O
Et6;t*F
H<xdty
Wv> OM)
`FY8S
qHZF~:
GBIeK\
Z*X&h_,b
t&Rh~Hu
~FOWB8
<>P[:E
0j0k&X
e.6}"
b$j ot
S?y FG
UMar!S$"P
+GH_-,u
O3<: D
h|F ;F
Xza4Y0W
c#>[B#
U,UN8M`
Yh~0<j
dQPUJp
bdleh9
3H>8/~
.+T3/6Sj\
\S@kg$
<9[JIjav6&
-HW=2t
OT())lz@
qwx7p8< 7
$NE ~$w
5kKH?3d
s =c<&
GZHI-
e9/I6<
$FL4t@
j [Cbpu
P~A\t9#Ha
2R\H`%
S6Fd58
9|t'*}#OC
PwR.h5
u''-=u
=wLw2,k
0(u|` ,|
+0EjLa
bAN]ZAf
WF]fE+
-3xD'+S
$iYMac
u(SO'D
!oBV9]F
*B+A\v
xXp6^VNfS
ut!0cU}
|WC{4`
wSj0>"
8x80bud&
`0QRin
r9$,$(#
s "C`Z
j@^+s`;
K`j8^;
TiC:32OA
|2PRJm
,5(=$f
H(QiCF
G(z.@/
7xE$WW9
^]|"")b
X"x/'
V ^0f@nPv`>
32[5
&iCNS-
;Oc1a|
@eJZWt
aum.V1
X1^MOC
ft%fOB
lRpGX:
wVVnW{
Fr!$[d
5]q-j`
k"]|0t
`/2f9W
XWHxbB
@hV)JM
u@tJxN
gJw0xH
i7M $(
-XssLt>Tt-h
uNx Xu
W*B1jhZ;
0xOjln
ACMD~
F^$+^8+
"ytjAZjX>_
$kW~X
8<,@@JiR
);v8E3J
E+8"@U
-`ayj
jN&<0dO/
#(zA9f
!.fA<Au
:@$,,!i0i"X8
$cN$T]K
C8VD06
,[!p'#
^b{#)R
,Qt#Vh
6t-p#J
EE8@G`
uwhl?
&, <"0
95{n-%
&0\Z8(
;}+Ml
>Cu4<6
\QV $0.
|*8O-$
5pq\>T
QACJ8
~%@r48t V
U|jA^f
D$F@AA
PRzHho
wxYgf{`m
v1!Ss Q
>dn-D/U
``pck'
SPB.8E
3BHN}b/h
Mtu(xu$B
<'mC-;
<TTphX
wjHpY@
X:uB[<
4z''$=dUT
B(&GHC
*S=:Rc
$E%VK
AVmf<Ih
;)<.N/
|*d&=!
jWlI,H
/Q0tzu
pPh"3\
-7W|@D
2}xYJm
q@IuUlU
li5ffV&
48hzE^
YSx_u@+
%FFSFk0
d|z<r:
d=umh#
to4Sq7
_#Xt:f
mEV3It8+
].q8*,+|
%a24+c
tmI444
[Cp``N
nDt|L2
K`4f#O
77Y00H
zNndJ_
0$,,l;5
cu4)w%
dml<Xi
%+ih9"
~r8yT@
-`W.,R
*;xC|R
F5NiD0
j%]rfT;T
-JA.EI
748ti;
%a{S\#
JTa.,nY
ZBF\[-)i
b S hN
{|jfXZ
_)CA)m
_s04LX
ZVRIO{
C6D Q&
H7P.];
rg9).R(V
:A4~6/Q
(%=Cx@
'dl+d3
`(} Iz;%a
FHu63
SW(5,m
9<Ij(@v1-
tVkXNa
urjpDK
9<gU67
,:HRdvy
4DVd&v
l7InitializeC
Var"blZS
-CSoWakeAlli7\
VKCbad
locas^
7rray n
>*TCs
+invr_*
pgumRt'stk
\rect yVmessagevk
tw0kDown
tun"achY
ttol op]
n^evi
't4mcour
'u"GZNi
dr17ckx
a~nn\ed
^n?\tu
rnwv|_
g@dAe?y
8sO&Bty
yDuCvG
mp&$Hn#
&uns:a
SEEx7h
m;|PEv
Fp/C+(D
s(ByHandl|#vp
eAs]!g5>
aSRWL
orkubP
0123449
c~fghijklm
</(607
>P?X@`=
<AhCpD
<!H"T<
<#`$l%
8,98:y
yD;P>\
Pe`kpl
>XCdk|
p {JSi
$/000i*M
<0H4TU
JS4`4l8i*M
of<76/
t{gf<V
hCFS/s
pp_r/r
noiOs?k
/anol
R?-BNGO
e//sYM
rwsmZ<
|_McgG
P/fGCo
M[sgY6'B5
5_Ogn>
+?LGAU
7/B_P/Q
V\kC>H
iK.saw#
]2uvwt7e
m+q:o/
Bnok?jj
7uGpw
<DPX`l
$(4@H=
rcl&pcalstd5
Fftns$
tr64nre
.^_`||6*+
l T.guf
ard/s/
mFirtu
N.pyQ`1$
K2K--}7
xwpwpp(nu
\rE=Kd
mWMN"TX
sY/&U6
qk{|}~
~ $s%r
@b;zO]
v2!L.2
;J#M :%_n
Thu~i.a
novv('Ja
ec_Xygr
PMM/dd/3
HH:mm:
i_7o[{oEr
lGo/C
<(,048
<^@DLX
dKrot>
0s+Zh8
ApisANSI
.UserD
IsVFI7kk
LCIDToEG
ccUTF-F
EUNICODE7
-xca_?
=c/**[
{sn;Fjkh
u;jooOX
Od'i{kT
s2,NPn
sqrtME=cei
wmod!ld=}
_c1_hypo
'0`T@Q
?Dj0Q:W~
5s3R6/
}N@ =9
{`2!/s/G
NNNn_n[H5
]vQ<)8h
[|)P!?Ua0
y1~?|"
?x+s7
k>? #J
o;:8o7
6431on'
0.-+o*
N)'&o$vrr;#!
yxwvovn'''utt?sNNNNrqqp
ooonm;99
?llkjovrrrjihg?
a?`__''
^]o]\[NNn'Z?ZYX
NNWWoVU9
UT?SRrr;9RQoPP
vrON?MM
?5Od%
?|I7Z#
>,'1B
([|X>H1
G~U`K
AxuN}*
r7Yr7]D
&?~YK|
ow_sU0
Bfe9?0
8bunz8r
1WY$?]
?#%X.y
<@En[vP
?5Wg4p
#{ ~`~
n,|RIFF
+data%Y-%m
d %H.%M*h4o0.
Op:a,a@(a0
ed>I TLda
fF?key/0
2Auth{H
q_R'g:
WDis6Xg
oft\Wj
NT\cVR
'LdrlL+h
N-OJPX
'vUCCESS7-
?!FAILU
4:6.'0
2:4bB~w}
fX'DTn"+
~On5U0y
BckSpT
FEscgUg
q[I/Righ
;#I/Pr
2NNNN3456ONNN78910 x
(!]'3@
`3D^x\
FoldV
}p<GIE
oc.k+.
DS6I+}'W
.9.2 .
4fVQNK
hs1.3
='9-6d
_jbF~T
11#?*0
t\lHBW
)Djxky
y{sKU
=j&&LZ66lA??~
}{))R>
""D~**T
V22dN::t
o%%Jr..
aa,55j
SHA256
wECDS)U
Ng},8S*:#
DB7C2ABF62E35E668076A
BEAD208B
8659EF
A043916EEDE8
1702B22
7628DFAC6561C5f
#H94872
B55F9,F09A{
FF7750
E8757|0
$A30D1B9038A
HCF5AC8
1C97BE
1D4QD7
AD0"FA4
"Ch8RU
BN8*|PT[23A*
/Rjt0E70FA7E9AB743
9:8DE|C1
E8&3Z (
p E$ CA
PRIMED%.hV
p9F@GrB
1A9DB2F
Uh,8nBE
<~j8 3
J5dNfu
1`LE1'
|70aGfp
,3&``f2
IOSYae<
79=KQ[<
<]agou
<-39;A
[_mqswy
?CEIOU<
/=AGIML5
watchdog
m{ av
FoxMlR
pi.dll
vw%uVt
ws2_32
%I64u.Y
Mi]PendJ
.VView
X/*nDISPLAY
cloHu+
.a8Jpu
10. ( M
mtC?D7
W?sH{A
s' Gs$6
s%ovtFN
FxTcpT\
ONOUT$
.LcUID
-BEGIN CERTIFICATE
+7END3o
DH PARAMERS?wm
;wX509
BPhCA
y%/9CM
~-GCTL
.00cfPm
tK'ADb
Nlsx}V.
i'2T&iV
i+yUr2
umt.LtdJALL RI
ESERVED.
9(_.?AV
of_?_F0'
MbN`@F
k@q*&_w"
<r4NPW<
TU~Z[2
CG!8Un
Zewd"~/
q{I?|9
_g@>v(Sq
j[`p32S
C7DOId
S,dalen
%btky5
L"e!AO
EE)xz<U
a"\`7Mf
"%zo%"
5A+GnR
s?|dj0
ua"uft
l -KDC
e{Po^pM u
RslJ%#D
XPTPSW
33333333tQQ
33333333
ADVAPI32.dll
GDI32.dll
gdiplus.dll
KERNEL32.DLL
ole32.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
WININET.dll
WINMM.dll
WS2_32.dll
RegCloseKey
BitBlt
GdipFree
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoGetObject
ExtractIconA
StrToIntA
URLDownloadToFileW
DrawIcon
InternetOpenW
waveInOpen
SETTINGS
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Remcos.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Generic.Dacic.A9349469.A.4712C1B7
ClamAV Win.Trojan.Remcos-9841897-0
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!9DA8F029A4EB
Malwarebytes Backdoor.Remcos
VIPRE Generic.Dacic.A9349469.A.4712C1B7
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0053ba121 )
BitDefender Generic.Dacic.A9349469.A.4712C1B7
K7GW Trojan ( 0053ba121 )
Cybereason malicious.b72301
Baidu Win32.Trojan.Kryptik.awm
VirIT Trojan.Win32.Genus.TCT
Cyren W32/Trojan.GCT.gen!Eldorado
Symantec Trojan.Remcos
tehtris Clean
ESET-NOD32 a variant of Win32/Rescoms.B
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Remcos.gen
Alibaba Backdoor:Win32/Remcos.f37c5da7
NANO-Antivirus Trojan.Win32.Remcos.kakzkh
ViRobot Trojan.Win.Z.Remcos.238592.B
Rising Trojan.Rescoms!8.100A0 (TFE:5:FKuWrtG2iWT)
Sophos Mal/Emogen-Y
F-Secure Backdoor.BDS/Backdoor.Gen
DrWeb Trojan.DownLoader46.4974
Zillya Trojan.Rescoms.Win32.1480
TrendMicro Backdoor.Win32.REMCOS.YXDJBZ
McAfee-GW-Edition BehavesLike.Win32.Remcos.dc
Trapmine malicious.high.ml.score
FireEye Generic.mg.9da8f029a4eb6277
Emsisoft Generic.Dacic.A9349469.A.4712C1B7 (B)
SentinelOne Static AI - Malicious PE
GData Generic.Dacic.A9349469.A.4712C1B7
Jiangmin Backdoor.Remcos.dwr
Webroot W32.Trojan.Remcos
Avira BDS/Backdoor.Gen
MAX malware (ai score=88)
Antiy-AVL Trojan[Backdoor]/Win32.Rescoms.b
Kingsoft malware.kb.b.974
Gridinsoft Trojan.Win32.Remcos.bot
Xcitium Clean
Arcabit Generic.Dacic.A9349469.A.4712C1B7
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Remcos.gen
Microsoft Trojan:Win32/Remcos!ic
Google Detected
AhnLab-V3 Trojan/Win.QA.C5376648
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36738.omGfaeRiNcki
ALYac Generic.Dacic.A9349469.A.4712C1B7
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Backdoor.Remcos
Cylance unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.REMCOS.YXDJBZ
Tencent Win32.Backdoor.Remcos.Vimw
Yandex Clean
Ikarus Backdoor.Remcos
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Remcos.A!tr
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.