Static | ZeroBOX

PE Compile Time

2016-07-10 21:59:43

PE Imphash

52753d226ff5a8a88caf9829928cd5d1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000b2a 0x00000c00 5.8595801677
.rdata 0x00002000 0x000021c2 0x00002200 6.35228955674
.data 0x00005000 0x00000194 0x00000200 3.57820168851
.rsrc 0x00006000 0x000001e8 0x00000200 4.7522401822
.reloc 0x00007000 0x0000020c 0x00000400 3.9945878611

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00006060 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x402024 WriteFile
0x402028 CloseHandle
0x40202c lstrcmpA
0x402030 lstrcmpW
0x402034 LoadLibraryA
0x402038 GetModuleFileNameW
0x40203c GetCommandLineW
0x402040 Sleep
0x402044 SetPriorityClass
0x40204c Process32FirstW
0x402050 Process32NextW
0x402054 GlobalAlloc
0x402058 GlobalFree
0x40205c lstrlenW
0x402060 GetCurrentThreadId
0x402064 CreateThread
0x402068 ExitProcess
0x40206c GetCurrentProcess
0x402070 OpenProcess
0x402074 LocalFree
0x402078 LocalAlloc
0x40207c CreateFileA
0x402080 GetProcAddress
Library USER32.dll:
0x4020a4 GetWindowRect
0x4020a8 MessageBoxW
0x4020ac SetCursorPos
0x4020b0 GetCursorPos
0x4020b4 GetDesktopWindow
0x4020b8 EnumChildWindows
0x4020bc CallNextHookEx
0x4020c0 LoadIconW
0x4020c4 ReleaseDC
0x4020c8 UnhookWindowsHookEx
0x4020cc MessageBoxA
0x4020d0 GetSystemMetrics
0x4020d4 CreateWindowExA
0x4020d8 RegisterClassExA
0x4020dc DefWindowProcW
0x4020e0 ExitWindowsEx
0x4020e4 DispatchMessageW
0x4020e8 TranslateMessage
0x4020ec GetWindowDC
0x4020f0 DrawIcon
0x4020f4 SendInput
0x4020f8 SendMessageTimeoutW
0x4020fc GetMessageW
0x402100 SetWindowsHookExW
Library GDI32.dll:
0x402018 BitBlt
0x40201c StretchBlt
Library ADVAPI32.dll:
0x402000 OpenProcessToken
0x402010 CryptGenRandom
Library SHELL32.dll:
0x402090 CommandLineToArgvW
0x402094 ShellExecuteW
0x402098 ShellExecuteA
0x40209c ShellExecuteExW
Library WINMM.dll:
0x402108 PlaySoundA
Library PSAPI.DLL:

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
SSSSjdjdSSSSVS
j4WhH7@
Pj2j2V
Yf9<Vu
*Y': &*
E~'~'pI
'h(p)pihH
h(~'L&
p)~GLF^
HpIhH]
hHYour computer has been trashed by the MEMZ trojan. Now enjo_
Nyan Cat.../
YOUR COMPUTER HAS BEEN FUCKED BY THE MEMZ TROJAN.
Your computer won't boot up again,
so use it as long as you can!
Trying to kill MEMZ will cause your system to be
destroyed instantly, so don't try it :D
http://google.co.ck/search?q=best+way+to+kill+yourself
http://google.co.ck/search?q=how+2+remove+a+virus
http://google.co.ck/search?q=mcafee+vs+norton
http://google.co.ck/search?q=how+to+send+a+virus+to+my+friend
http://google.co.ck/search?q=minecraft+hax+download+no+virus
http://google.co.ck/search?q=how+to+get+money
http://google.co.ck/search?q=bonzi+buddy+download+free
http://google.co.ck/search?q=how+2+buy+weed
http://google.co.ck/search?q=how+to+code+a+virus+in+visual+basic
http://google.co.ck/search?q=what+happens+if+you+delete+system32
http://google.co.ck/search?q=g3t+r3kt
http://google.co.ck/search?q=batch+virus+download
http://google.co.ck/search?q=virus.exe
http://google.co.ck/search?q=internet+explorer+is+the+best+browser
http://google.co.ck/search?q=facebook+hacking+tool+free+download+no+virus+working+2016
http://google.co.ck/search?q=virus+builder+legit+free+download
http://google.co.ck/search?q=how+to+create+your+own+ransomware
http://google.co.ck/search?q=how+to+remove+memz+trojan+virus
http://google.co.ck/search?q=my+computer+is+doing+weird+things+wtf+is+happenin+plz+halp
http://google.co.ck/search?q=dank+memz
http://google.co.ck/search?q=how+to+download+memz
http://google.co.ck/search?q=half+life+3+release+date
http://google.co.ck/search?q=is+illuminati+real
http://google.co.ck/search?q=montage+parody+making+program+2016
http://google.co.ck/search?q=the+memz+are+real
http://google.co.ck/search?q=stanky+danky+maymays
http://google.co.ck/search?q=john+cena+midi+legit+not+converted
http://google.co.ck/search?q=vinesauce+meme+collection
http://google.co.ck/search?q=skrillex+scay+onster+an+nice+sprites+midi
http://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning/memz-malwarevirus-trojan-completely-destroying/268bc1c2-39f4-42f8-90c2-597a673b6b45
http://motherboard.vice.com/read/watch-this-malware-turn-a-computer-into-a-digital-hellscape
http://play.clubpenguin.com
http://pcoptimizerpro.com
http://softonic.com
notepad
regedit
explorer
taskmgr
msconfig
mspaint
devmgmt.msc
control
YOU KILLED MY TROJAN!
Now you are going to die.
REST IN PISS, FOREVER MISS.
I WARNED YOU...
HAHA N00B L2P G3T R3KT
You failed at your 1337 h4x0r skillz.
YOU TRIED SO HARD AND GOT SO FAR, BUT IN THE END, YOUR PC WAS STILL FUCKED!
HACKER!
ENJOY BAN!
GET BETTER HAX NEXT TIME xD
HAVE FUN TRYING TO RESTORE YOUR DATA :D
|\/|3|\/|2
BSOD INCOMING
VIRUS PRANK (GONE WRONG)
ENJOY THE NYAN CAT
Get dank antivirus m9!
You are an idiot!
HA HA HA HA HA HA HA
#MakeMalwareGreatAgain
SOMEBODY ONCE TOLD ME THE MEMZ ARE GONNA ROLL ME
Why did you even tried to kill MEMZ?
Your PC is fucked anyway.
SecureBoot sucks.
gr8 m8 i r8 8/8
Have you tried turning it off and on again?
<Insert Joel quote here>
Greetings to all GAiA members!
Well, hello there. I don't believe we've been properly introduced. I'm Bonzi!
'This is everything I want in my computer'
- danooct1 2016
'Uh, Club Penguin. Time to get banned!'
- danooct1 2016
SystemHand
SystemQuestion
SystemExclamation
The software you just executed is considered malware.
This malware will harm your computer and makes it unusable.
If you are seeing this message without knowing what you just executed, simply press No and nothing will happen.
If you know what this malware does and are using a safe environment to test, press Yes to start it.
DO YOU WANT TO EXECUTE THIS MALWARE, RESULTING IN AN UNUSABLE MACHINE?
THIS IS THE LAST WARNING!
THE CREATOR IS NOT RESPONSIBLE FOR ANY DAMAGE MADE USING THIS MALWARE!
STILL EXECUTE IT?
\\.\PhysicalDrive0
\note.txt
RtlAdjustPrivilege
NtRaiseHardError
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
GetProcAddress
LocalAlloc
LocalFree
OpenProcess
GetCurrentProcess
ExitProcess
CreateThread
GetCurrentThreadId
WriteFile
CloseHandle
lstrcmpA
lstrcmpW
LoadLibraryA
GetModuleFileNameW
GetCommandLineW
CreateFileA
SetPriorityClass
CreateToolhelp32Snapshot
Process32FirstW
Process32NextW
GlobalAlloc
GlobalFree
lstrlenW
KERNEL32.dll
GetMessageW
TranslateMessage
DispatchMessageW
ExitWindowsEx
DefWindowProcW
RegisterClassExA
CreateWindowExA
GetSystemMetrics
MessageBoxA
SetWindowsHookExW
UnhookWindowsHookEx
SendMessageTimeoutW
SendInput
DrawIcon
GetWindowDC
ReleaseDC
GetWindowRect
MessageBoxW
SetCursorPos
GetCursorPos
GetDesktopWindow
EnumChildWindows
CallNextHookEx
LoadIconW
USER32.dll
BitBlt
StretchBlt
GDI32.dll
OpenProcessToken
AdjustTokenPrivileges
LookupPrivilegeValueW
CryptAcquireContextW
CryptGenRandom
ADVAPI32.dll
ShellExecuteA
ShellExecuteW
CommandLineToArgvW
ShellExecuteExW
SHELL32.dll
PlaySoundA
WINMM.dll
GetProcessImageFileNameA
PSAPI.DLL
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0,080@0Z0`0f0m0u0
1*11191@1e1p1
272D2K2U2\2k2t2
3-3:3D3K3\3f3n3|3
44.464@4Q4V4^4r4
5$5L5R5X5^5{5
656A6g6m6s6y6
8.868E8K8Q8W8p8
9 9.9I9b9
:":O:Z:l:r:~:
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,10181@1H1P1X1`1h1p1x1
/watchdog
SeShutdownPrivilege
Still using this computer?
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.DiskWriter.tnbd
Elastic malicious (high confidence)
ClamAV Win.Malware.Diskwriter-6914536-0
CMC Clean
CAT-QuickHeal Trojan.Mauvaise.S2299117
ALYac Trojan.Diskwriter.gen
Cylance unsafe
Zillya Trojan.DiskWriter.Win32.211
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.AgentWDCR.PKD
K7GW Riskware ( 0040eff71 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.KillMBR.BKSD
Cyren W32/Diskwriter.RJSJ-6696
Symantec Deltree Trojan
tehtris Clean
ESET-NOD32 Win32/Zmem.A
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.DiskWriter.ez
Alibaba Trojan:Win32/DiskWriter.ded37607
NANO-Antivirus Trojan.Win32.DiskWriter.ekeock
SUPERAntiSpyware Trojan.Agent/Gen-Crypt
MicroWorld-eScan Trojan.AgentWDCR.PKD
Rising Trojan.DiskWriter!8.87FB (KTSE)
TACHYON Trojan/W32.DiskWriter.14848
Sophos Mal/EncPk-YG
F-Secure Trojan.TR/Rozena.AP
DrWeb Trojan.KillMBR.24807
VIPRE Trojan.AgentWDCR.PKD
TrendMicro TROJ_MEMZWIPER.A
McAfee-GW-Edition BehavesLike.Win32.Generic.lh
Trapmine malicious.high.ml.score
FireEye Generic.mg.19dbec50735b5f2a
Emsisoft Trojan.AgentWDCR.PKD (B)
Ikarus Trojan.Win32.Zmem
Jiangmin Trojan.DiskWriter.aa
Webroot W32.Trojan.Gen
Avira TR/Rozena.AP
Antiy-AVL Trojan/Win32.TSGeneric
Kingsoft Win32.Troj.DiskWriter.ez
Microsoft Trojan:Win32/Dynamer!bit
Gridinsoft Trojan.Win32.Agent.dg
Xcitium Malware@#azw7fthdwxzq
Arcabit Trojan.AgentWDCR.PKD
ViRobot Trojan.Win32.S.Agent.14848.MW
ZoneAlarm Trojan.Win32.DiskWriter.ez
GData Win32.Trojan.Agent.TLUCQP
Google Detected
AhnLab-V3 Trojan/Win32.DiskWriter.C1514156
Acronis Clean
McAfee RDN/Generic.grp
MAX malware (ai score=100)
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.Boot
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/WLT.D
Zoner Trojan.Win32.73166
TrendMicro-HouseCall TROJ_MEMZWIPER.A
Tencent Malware.Win32.Gencirc.10b18ce5
Yandex Trojan.Igent.bUFeyO.12
SentinelOne Clean
MaxSecure Trojan.Malware.9751253.susgen
Fortinet W32/Zmem.I!tr
BitDefenderTheta AI:Packer.E0B41D791F
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.