Static | ZeroBOX

PE Compile Time

2023-09-07 19:23:27

PE Imphash

bc4f8e98d1041d53dd63bfb91ed10d0a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0004e000 0x00000000 0.0
UPX1 0x0004f000 0x00036000 0x00035600 7.93749838393
.rsrc 0x00085000 0x00005000 0x00004a00 3.53235571724

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00087034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007d5cc 0x000004b8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000895e0 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x489724 RegCloseKey
Library GDI32.dll:
0x48972c BitBlt
Library gdiplus.dll:
0x489734 GdipFree
Library KERNEL32.DLL:
0x48973c LoadLibraryA
0x489740 ExitProcess
0x489744 GetProcAddress
0x489748 VirtualProtect
Library ole32.dll:
0x489750 CoGetObject
Library SHELL32.dll:
0x489758 ExtractIconA
Library SHLWAPI.dll:
0x489760 StrToIntA
Library urlmon.dll:
0x489768 URLDownloadToFileW
Library USER32.dll:
0x489770 DrawIcon
Library WININET.dll:
0x489778 InternetOpenW
Library WINMM.dll:
0x489780 waveInOpen
Library WS2_32.dll:
0x489788 socket

!This program cannot be run in DOS mode.
~Rich
/ SzhSv
X[+hY0
Kx (hb
TF>n`
JHMBj)
Hu\hw2
0-~p^;4v
K&@P[-
mPgVkk
w!k98t
)%?B3B
=t$(2|X>$V
,2(V8(K
;|8tK{
_[$K\-
AtDR)6
%`7"w7Ri%
T)8,zc
(,0aY/"
_3mM+pP,R+
HjA+sgO
\R968!
b&VPV-
T$L'}|,
;+(4;jQ
XIw1d@
Oz9~z
\U|\b
@OW$8 W[
IFZBr0
@wi3MB
NT[$&t
Cys\jC^
`8f8e2
r#D@hb
Y@R$D-
MUQIWz
RWi_ R
o3`f-$
"*X=YI
8@' )SS2[
Vj2e+sX8
p*onh/
'-?t>S
FjpE`g%
pwVtE.t1-t
q1x;D|j"=Q@
.E@p!H
70kuI%
vb'c0Se
tX_cPP
JRiN[B0
tWh09c
pWUUF|R
8M FB85
hDrUh\
b\j.v?K
0S11ab
h,",*K8
8PYj5!
*8%eYY
nj V"^
a83 D!
S2Xx%4T
shT-Tm
`9{Lt:V
|wex'^
tI4b7z
ZRJCE$
qF#A2(
UEVZ{r
yD[I-v!
{C`d 6V*
`Y<9X8t
F*pW^y
j~-`]MM
,<,TOSj@Z
P4+S4t
K0<p{a
<,ZxmU
NtF*,[c
ji%<YX9
l0uQVi
PItj[=
6=`PYNP
\U\6vY
5l N(V
u#h Y*%
NN]S+*<
;{MN+nd
za,g8k
rrrV`V
I*R,5h
L2T<$I
,kDh,8
_50;N
?^vR[n
 !"#$%&'(
)*+,-L.L
1L2L34L5678j9:;L<=>?@A
<BCDLEFGHIJK
p0jE.X
DB&dbw(
VuC~:NQW
lnPGSW
U +vW`/
]0qV3k
7$pFPW
'MuISbPh,x
7Bylk6p'/V
m,`Vi$
=~VU_gYs
ex{,V|
_sI:$`w
P_-*(6XA+J
j4w#$
Q%-E2$
#(PUQj
3<*l3U
kEe3)SO
JGh,~t
=tv4Cjn
E|G60yP
P}WV0<M
_9t'~+&
X<3^_[
4~(qF;
}?Pxo#
JQ@'w6
7UNB@=
r2.u%Y
2^3f"f$
Ffj Rb
~T$,=$
[kK6JP
~0Y mE
KP8d<h
@$(~Yy"
]<*u?N>~
:Tt%<.t<GR
qk0>n*
<jHCp4
!HlLK0R
W4{YB*d
^8{`Rc
J@<x@<D
'8%ujut,m
B1J22T
eR)Ih(
FDPW{m
s2y!ND
@/&HH|
3fhuu$
><2}I:rN
n&2tJ5-
1 32b'
9^ni$m4IlZ{
Bx{t"S
[f%g,s-<
VjPj+P
w4 .V@
:<9gsT
xVK)BQ
mF(RnG
Z#l U`
P$WEoa}G@
>)pllWRh
N;`Aw<oW
[Y'Z_#e
SzwF_8D
r,84O
Et6;t*F
H<xdty
Wv> OM)
`FY8S
qHZF~:
GBIeK\
Z*X&h_,b
t&Rh~Hu
~FOWB8
<>P[:E
0j0k&X
e.6}"
b$j ot
S?y FG
UMar!S$"P
+GH_-,u
O3<: D
h|F ;F
Xza4Y0W
c#>[B#
U,UN8M`
Yh~0<j
dQPUJp
bdleh9
3H>8/~
.+T3/6Sj\
\S@kg$
<9[JIjav6&
-HW=2t
OT())lz@
qwx7p8< 7
$NE ~$w
5kKH?3d
s =c<&
GZHI-
e9/I6<
$FL4t@
j [Cbpu
P~A\t9#Ha
2R\H`%
S6Fd58
9|t'*}#OC
PwR.h5
u''-=u
=wLw2,k
0(u|` ,|
+0EjLa
bAN]ZAf
WF]fE+
-3xD'+S
$iYMac
u(SO'D
!oBV9]F
*B+A\v
xXp6^VNfS
ut!0cU}
|WC{4`
wSj0>"
8x80bud&
`0QRin
r9$,$(#
s "C`Z
j@^+s`;
K`j8^;
TiC:32OA
|2PRJm
,5(=$f
H(QiCF
G(z.@/
7xE$WW9
^]|"")b
X"x/'
V ^0f@nPv`>
32[5
&iCNS-
;Oc1a|
@eJZWt
aum.V1
X1^MOC
ft%fOB
lRpGX:
wVVnW{
Fr!$[d
5]q-j`
k"]|0t
`/2f9W
XWHxbB
@hV)JM
u@tJxN
gJw0xH
i7M $(
-XssLt>Tt-h
uNx Xu
W*B1jhZ;
0xOjln
ACMD~
F^$+^8+
"ytjAZjX>_
$kW~X
8<,@@JiR
);v8E3J
E+8"@U
-`ayj
jN&<0dO/
#(zA9f
!.fA<Au
:@$,,!i0i"X8
$cN$T]K
C8VD06
,[!p'#
^b{#)R
,Qt#Vh
6t-p#J
EE8@G`
uwhl?
&, <"0
95{n-%
&0\Z8(
;}+Ml
>Cu4<6
\QV $0.
|*8O-$
5pq\>T
QACJ8
~%@r48t V
U|jA^f
D$F@AA
PRzHho
wxYgf{`m
v1!Ss Q
>dn-D/U
``pck'
SPB.8E
3BHN}b/h
Mtu(xu$B
<'mC-;
<TTphX
wjHpY@
X:uB[<
4z''$=dUT
B(&GHC
*S=:Rc
$E%VK
AVmf<Ih
;)<.N/
|*d&=!
jWlI,H
/Q0tzu
pPh"3\
-7W|@D
2}xYJm
q@IuUlU
li5ffV&
48hzE^
YSx_u@+
%FFSFk0
d|z<r:
d=umh#
to4Sq7
_#Xt:f
mEV3It8+
].q8*,+|
%a24+c
tmI444
[Cp``N
nDt|L2
K`4f#O
77Y00H
zNndJ_
0$,,l;5
cu4)w%
dml<Xi
%+ih9"
~r8yT@
-`W.,R
*;xC|R
F5NiD0
j%]rfT;T
-JA.EI
748ti;
%a{S\#
JTa.,nY
ZBF\[-)i
b S hN
{|jfXZ
_)CA)m
_s04LX
ZVRIO{
C6D Q&
H7P.];
rg9).R(V
:A4~6/Q
(%=Cx@
'dl+d3
`(} Iz;%a
FHu63
SW(5,m
9<Ij(@v1-
tVkXNa
urjpDK
9<gU67
,:HRdvy
4DVd&v
l7InitializeC
Var"blZS
-CSoWakeAlli7\
VKCbad
locas^
7rray n
>*TCs
+invr_*
pgumRt'stk
\rect yVmessagevk
tw0kDown
tun"achY
ttol op]
n^evi
't4mcour
'u"GZNi
dr17ckx
a~nn\ed
^n?\tu
rnwv|_
g@dAe?y
8sO&Bty
yDuCvG
mp&$Hn#
&uns:a
SEEx7h
m;|PEv
Fp/C+(D
s(ByHandl|#vp
eAs]!g5>
aSRWL
orkubP
0123449
c~fghijklm
</(607
>P?X@`=
<AhCpD
<!H"T<
<#`$l%
8,98:y
yD;P>\
Pe`kpl
>XCdk|
p {JSi
$/000i*M
<0H4TU
JS4`4l8i*M
of<76/
t{gf<V
hCFS/s
pp_r/r
noiOs?k
/anol
R?-BNGO
e//sYM
rwsmZ<
|_McgG
P/fGCo
M[sgY6'B5
5_Ogn>
+?LGAU
7/B_P/Q
V\kC>H
iK.saw#
]2uvwt7e
m+q:o/
Bnok?jj
7uGpw
<DPX`l
$(4@H=
rcl&pcalstd5
Fftns$
tr64nre
.^_`||6*+
l T.guf
ard/s/
mFirtu
N.pyQ`1$
K2K--}7
xwpwpp(nu
\rE=Kd
mWMN"TX
sY/&U6
qk{|}~
~ $s%r
@b;zO]
v2!L.2
;J#M :%_n
Thu~i.a
novv('Ja
ec_Xygr
PMM/dd/3
HH:mm:
i_7o[{oEr
lGo/C
<(,048
<^@DLX
dKrot>
0s+Zh8
ApisANSI
.UserD
IsVFI7kk
LCIDToEG
ccUTF-F
EUNICODE7
-xca_?
=c/**[
{sn;Fjkh
u;jooOX
Od'i{kT
s2,NPn
sqrtME=cei
wmod!ld=}
_c1_hypo
'0`T@Q
?Dj0Q:W~
5s3R6/
}N@ =9
{`2!/s/G
NNNn_n[H5
]vQ<)8h
[|)P!?Ua0
y1~?|"
?x+s7
k>? #J
o;:8o7
6431on'
0.-+o*
N)'&o$vrr;#!
yxwvovn'''utt?sNNNNrqqp
ooonm;99
?llkjovrrrjihg?
a?`__''
^]o]\[NNn'Z?ZYX
NNWWoVU9
UT?SRrr;9RQoPP
vrON?MM
?5Od%
?|I7Z#
>,'1B
([|X>H1
G~U`K
AxuN}*
r7Yr7]D
&?~YK|
ow_sU0
Bfe9?0
8bunz8r
1WY$?]
?#%X.y
<@En[vP
?5Wg4p
#{ ~`~
n,|RIFF
+data%Y-%m
d %H.%M*h4o0.
Op:a,a@(a0
ed>I TLda
fF?key/0
2Auth{H
q_R'g:
WDis6Xg
oft\Wj
NT\cVR
'LdrlL+h
N-OJPX
'vUCCESS7-
?!FAILU
4:6.'0
2:4bB~w}
fX'DTn"+
~On5U0y
BckSpT
FEscgUg
q[I/Righ
;#I/Pr
2NNNN3456ONNN78910 x
(!]'3@
`3D^x\
FoldV
}p<GIE
oc.k+.
DS6I+}'W
.9.2 .
4fVQNK
hs1.3
='9-6d
_jbF~T
11#?*0
t\lHBW
)Djxky
y{sKU
=j&&LZ66lA??~
}{))R>
""D~**T
V22dN::t
o%%Jr..
aa,55j
SHA256
wECDS)U
Ng},8S*:#
DB7C2ABF62E35E668076A
BEAD208B
8659EF
A043916EEDE8
1702B22
7628DFAC6561C5f
#H94872
B55F9,F09A{
FF7750
E8757|0
$A30D1B9038A
HCF5AC8
1C97BE
1D4QD7
AD0"FA4
"Ch8RU
BN8*|PT[23A*
/Rjt0E70FA7E9AB743
9:8DE|C1
E8&3Z (
p E$ CA
PRIMED%.hV
p9F@GrB
1A9DB2F
Uh,8nBE
<~j8 3
J5dNfu
1`LE1'
|70aGfp
,3&``f2
IOSYae<
79=KQ[<
<]agou
<-39;A
[_mqswy
?CEIOU<
/=AGIML5
watchdog
m{ av
FoxMlR
pi.dll
vw%uVt
ws2_32
%I64u.Y
Mi]PendJ
.VView
X/*nDISPLAY
cloHu+
.a8Jpu
10. ( M
mtC?D7
W?sH{A
s' Gs$6
s%ovtFN
FxTcpT\
ONOUT$
.LcUID
-BEGIN CERTIFICATE
+7END3o
DH PARAMERS?wm
;wX509
BPhCA
y%/9CM
~-GCTL
.00cfPm
tK'ADb
Nlsx}V.
i'2T&iV
i+yUr2
umt.LtdJALL RI
ESERVED.
9(_.?AV
of_?_F0'
MbN`@F
k@q*&_w"
<r4NPW<
TU~Z[2
"q HQ7&BM
IsBadBP8
!AOEMCP
E<U`7E)
ais(a{
ekCdPi
!_Nonf
Po^pM u_a
TRslJc
S4]`h/
XPTPSW
33333333tQQ
33333333
ADVAPI32.dll
GDI32.dll
gdiplus.dll
KERNEL32.DLL
ole32.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
WININET.dll
WINMM.dll
WS2_32.dll
RegCloseKey
BitBlt
GdipFree
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoGetObject
ExtractIconA
StrToIntA
URLDownloadToFileW
DrawIcon
InternetOpenW
waveInOpen
SETTINGS
Antivirus Signature
Lionic Trojan.Win32.Remcos.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Generic.Dacic.A9349469.A.24A539B4
FireEye Generic.mg.2f730ad313cf99a1
CAT-QuickHeal Trojan.GenericRI.S31067642
Skyhigh BehavesLike.Win32.SpywareLyndra.dc
McAfee Artemis!2F730AD313CF
Malwarebytes Malware.AI.4238095733
Zillya Trojan.Rescoms.Win32.1480
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0053ba121 )
Alibaba Backdoor:Win32/Remcos.db6ab082
K7GW Trojan ( 0053ba121 )
Cybereason malicious.8ba1fe
Baidu Win32.Trojan.Kryptik.awm
VirIT Trojan.Win32.Genus.TCT
Symantec Trojan.Remcos
tehtris Clean
ESET-NOD32 a variant of Win32/Rescoms.B
APEX Malicious
Paloalto Clean
ClamAV Win.Trojan.Remcos-9841897-0
Kaspersky HEUR:Backdoor.Win32.Remcos.gen
BitDefender Generic.Dacic.A9349469.A.24A539B4
NANO-Antivirus Trojan.Win32.Remcos.kakzkh
SUPERAntiSpyware Clean
Avast Win32:RATX-gen [Trj]
Tencent Malware.Win32.Gencirc.10bf34ec
Emsisoft Generic.Dacic.A9349469.A.24A539B4 (B)
F-Secure Backdoor.BDS/Backdoor.Gen
DrWeb Trojan.DownLoader46.4974
VIPRE Generic.Dacic.A9349469.A.24A539B4
TrendMicro Backdoor.Win32.REMCOS.YXDJ4Z
Trapmine malicious.high.ml.score
CMC Clean
Sophos Mal/Emogen-Y
SentinelOne Static AI - Malicious PE
MAX malware (ai score=84)
Jiangmin Backdoor.Remcos.dwr
Webroot W32.Trojan.Remcos
Google Detected
Avira BDS/Backdoor.Gen
Varist W32/Trojan.GCT.gen!Eldorado
Antiy-AVL Trojan[Backdoor]/Win32.Rescoms.b
Kingsoft malware.kb.b.983
Microsoft Trojan:Win32/Remcos!ic
Gridinsoft Trojan.Win32.Remcos.bot
Xcitium Clean
Arcabit Generic.Dacic.A9349469.A.24A539B4
ViRobot Trojan.Win.Z.Remcos.238592.F
ZoneAlarm HEUR:Backdoor.Win32.Remcos.gen
GData Generic.Dacic.A9349469.A.24A539B4
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.QA.C5376648
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36792.omGfa4nx3Vpi
ALYac Generic.Dacic.A9349469.A.24A539B4
TACHYON Clean
VBA32 Backdoor.Remcos
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.REMCOS.YXDJ4Z
Rising Trojan.Rescoms!8.100A0 (TFE:5:FKuWrtG2iWT)
Yandex Trojan.Rescoms!yzloPsMaQAE
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Remcos.A!tr
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.