Static | ZeroBOX

PE Compile Time

2009-05-20 11:06:55

PE Imphash

25b3acc640473b6fce722f16eff93149

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0000d000 0x00000000 0.0
UPX1 0x0000e000 0x0000b000 0x0000a800 7.97349609588
.rsrc 0x00019000 0x00001000 0x00000a00 3.35225962772

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001905c 0x00000768 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x41983c FreeSid
Library KERNEL32.DLL:
0x419844 LoadLibraryA
0x419848 ExitProcess
0x41984c GetProcAddress
0x419850 VirtualProtect
Library MSVCRT.dll:
0x419858 _iob
Library WS2_32.dll:
0x419860 WSARecv
Library WSOCK32.dll:
0x419868 WSAGetLastError

!This program cannot be run in DOS mode.
`91T"u@
=ilTj'
5~.jpH\R
5+;1:x
?Yd&'O
e4,0\C
?@x(^Q
>2lCgn
NQ'5#E
'\032#7e
,UKmb5+]
\nD)O>
5m,t<F@
xFY@8
j0,_XRwq
W6&[/G
cP^zwJ=E
L f(x{
L&l=M/Z
l8UE>O
op`uAWu
dEtuD-
SqL$5=
8mkrNm
i3g>!"
AtPH)GG
dFpb=%j
6|cpX
9-toeq8
KbXpbD
7/6gsRDUZ
tV#|<Q
@X8g~1
TyT3lq
9Lpn^\b
<IhwQt
Yp|E#ro
e3)uxF[
x;Fk_)
ig1d!a
kAKJ}~
t/*@BG
~F]@ZX
'Dt@!w
^Hx"hj
KviGnJFC
US!RS?
e:L&9.
Fx^Sd8
R W'lM
nn51~w
s@mGV4W1K
{yTr8>
'Cq4.2
L+hSJ7
"Ie8i%
8%--e'
Uq^*:)R`]br
r'kcu3
$]ruS/
H|v)G,
Hc6V0V
k78=z|?
U#n&7q
udL"{Mlb
FFShKW
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
ADVAPI32.dll
KERNEL32.DLL
MSVCRT.dll
WS2_32.dll
WSOCK32.dll
FreeSid
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
WSARecv
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
CompanyName
Apache Software Foundation
FileDescription
ApacheBench command line utility
FileVersion
2.2.14
InternalName
ab.exe
LegalCopyright
Copyright 2009 The Apache Software Foundation.
OriginalFilename
ab.exe
ProductName
Apache HTTP Server
ProductVersion
2.2.14
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Jorik.lrUS
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Swrort.A
ALYac Generic.ShellCode.Marte.H.4B7582C4
Cylance unsafe
Zillya Trojan.Generic.Win32.1122612
Paloalto generic.ml
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Meterpreter.e73743cc
K7GW Trojan ( 001172b51 )
K7AntiVirus Trojan ( 001172b51 )
Baidu Clean
VirIT Clean
Cyren W32/Swrort.D.gen!Eldorado
Symantec Meterpreter
tehtris Clean
ESET-NOD32 a variant of Win32/Rozena.BJG
APEX Malicious
Avast Win32:Meterpreter-C [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Generic.ShellCode.Marte.H.4B7582C4
NANO-Antivirus Trojan.Win32.Shellcode.ewfvwj
ViRobot Clean
MicroWorld-eScan Generic.ShellCode.Marte.H.4B7582C4
Tencent Win32.Trojan.Generic.Kajl
TACHYON Clean
Sophos ATK/SwrortPk-A
F-Secure Trojan.TR/Crypt.ZPACK.Gen
DrWeb Trojan.Swrort.1
VIPRE Generic.ShellCode.Marte.H.4B7582C4
TrendMicro Clean
McAfee-GW-Edition Swrort.d
Trapmine malicious.high.ml.score
FireEye Generic.mg.092c3991693cf8e0
Emsisoft Generic.ShellCode.Marte.H.4B7582C4 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.PSE.10KKVZ1
Jiangmin Trojan.Generic.hnqyj
Webroot W32.Trojan.Swrort
Avira TR/Crypt.ZPACK.Gen
Antiy-AVL Clean
Gridinsoft Clean
Xcitium TrojWare.Win32.Rozena.A@4jwdqr
Arcabit Generic.ShellCode.Marte.H.4B7582C4
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Meterpreter.O
Google Detected
AhnLab-V3 Backdoor/Win32.Bifrose.R12476
Acronis Clean
McAfee GenericRXAA-AA!092C3991693C
MAX malware (ai score=81)
VBA32 Trojan.Swrort
Malwarebytes Malware.Heuristic.1003
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Crypto!8.364 (TFE:5:qRUE1u5wYD)
Yandex Trojan.GenAsa!O0/tdGI4TGA
Ikarus Trojan.Win32.Swrort
MaxSecure Trojan.Malware.7164915.susgen
Fortinet W32/Rozena.ABV!tr
BitDefenderTheta Gen:NN.ZexaF.36164.cmKfa4rf30ji
AVG Win32:Meterpreter-C [Trj]
DeepInstinct MALICIOUS
No IRMA results available.