Static | ZeroBOX

PE Compile Time

2015-06-16 01:07:53

PE Imphash

7045005ef4130348fa4cbfc30a6f9d04

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00011000 0x00000000 0.0
UPX1 0x00012000 0x00009000 0x00008800 7.97032355435
.rsrc 0x0001b000 0x00001000 0x00000800 4.11830547786

Resources

Name Offset Size Language Sub-language File type
RT_RCDATA 0x00017634 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x00017634 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x00017634 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_RCDATA 0x00017634 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL Non-ISO extended-ASCII text, with no line terminators
RT_MANIFEST 0x0001b144 0x0000029c LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.DLL:
0x14001b4a8 LoadLibraryA
0x14001b4b0 GetProcAddress
0x14001b4b8 VirtualProtect
0x14001b4c0 VirtualAlloc
0x14001b4c8 VirtualFree
0x14001b4d0 ExitProcess
Library COMCTL32.DLL:
0x14001b4e0 InitCommonControlsEx
Library GDI32.DLL:
0x14001b4f0 BitBlt
Library msvcrt.dll:
0x14001b500 fabs
Library OLE32.DLL:
0x14001b510 CoInitialize
Library SHELL32.DLL:
0x14001b520 ShellExecuteExA
Library SHLWAPI.DLL:
0x14001b530 PathGetArgsA
Library USER32.DLL:
0x14001b540 GetDC
Library WINMM.DLL:
0x14001b550 timeBeginPeriod

!This program cannot be run in DOS mode.
iXIJ\_
F_Oy1Y
ScjHn7V
s\1`Zs
H*_3<p
Zh]XA2A
.8pUN :&
/'5jV1E6
n:6sT@
z-*w
lzBE0D
6wK]a(
9?0'Drr]
u?y}Q&
f0XFt8
w0pu )
j=ZW<xS(
(w~J'a2
! y3(E
H87K0;G
E/H74-
O)+\iUA
}O0pkc
S1wP0j
aY%!e
u9"7z\
B8"xO9{JP
[F/;d4
{5J}KBn
lM0O0J
c1A7|*
a<JHCD
>.-)VR
)=Ks>
*^<&:)+
~HAZArv5W
hR_\J"C
y{)#Kr_X
6#>i*Mr
/nH#J=
L1'=U_
L[a}I[
Z wFAS+
~q7me551
<jI8+X
`ZTu8Y
~V5a[M$
7UZ- u
\x]Iaq
CA[mag
o|#l4r
{?]xnR
p~<\x:
&`w#}Z
X`jN`}"
"[t*Yx
aCt6s#D
#<S)M1
L$sn>NIS
E58D[hUE"a
]7Rsn-
BNSSP9h z
(42O*F
[]A\A]A^A_
(]_^[H
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <dependency> <dependentAssembly> <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" /> </dependentAssembly> </dependency> <v3:trustInfo xmlns:v3="urn:schemas-microsoft-com:asm.v3"> <v3:security> <v3:requestedPrivileges> <!-- level can be "asInvoker", "highestAvailable", or "requireAdministrator" --> <v3:requestedExecutionLevel level="highestAvailable" /> </v3:requestedPrivileges> </v3:security> </v3:trustInfo> </assembly>
KERNEL32.DLL
COMCTL32.DLL
GDI32.DLL
msvcrt.dll
OLE32.DLL
SHELL32.DLL
SHLWAPI.DLL
USER32.DLL
WINMM.DLL
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
InitCommonControlsEx
BitBlt
CoInitialize
ShellExecuteExA
PathGetArgsA
timeBeginPeriod
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Bsymem.4!c
tehtris Generic.Malware
ClamAV Win.Trojan.Generic-7440302-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.RealProtect.nc
ALYac Trojan.GenericKD.65812018
Cylance Unsafe
Zillya Trojan.Bsymem.Win32.4184
Sangfor Downloader.Win64.Bsymem.V491
K7AntiVirus Trojan ( 0058ce061 )
Alibaba Trojan:Win32/Bsymem.b4bfe13f
K7GW Trojan ( 0058ce061 )
Cybereason malicious.87fd53
Baidu Clean
VirIT Backdoor.Win32.Generic.KKE
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 PowerShell/TrojanDownloader.Agent.EQN
APEX Malicious
Avast Win64:Trojan-gen
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Bsymem.ahvs
BitDefender Trojan.GenericKD.65812018
NANO-Antivirus Trojan.Win64.Bsymem.kaheck
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.65812018
Tencent Malware.Win32.Gencirc.13c013f3
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Win32.HLLW.Autoruner2.51353
VIPRE Trojan.GenericKD.65812018
TrendMicro TROJ_GEN.R002C0DH424
McAfeeD Real Protect-LS!ADB4D3F87FD5
Trapmine Clean
FireEye Generic.mg.adb4d3f87fd5378b
Emsisoft Trojan.Agent (A)
Paloalto generic.ml
GData Trojan.GenericKD.65812018
Jiangmin Trojan/PSW.Ruftar.gcx
Webroot Clean
Varist W64/ABTrojan.BSZQ-8767
Avira Clean
MAX malware (ai score=84)
Antiy-AVL Trojan/Win32.Bsymem
Kingsoft malware.kb.b.931
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D3EC3632
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Bsymem.ahvs
Microsoft Trojan:Win64/Malgent!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!ADB4D3F87FD5
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Downloader.FUM
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent/PS!8.1250D (CLOUD)
Yandex Clean
Ikarus Trojan-Downloader.PowerShell.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet W64/CoinMiner.MB!tr
BitDefenderTheta Clean
AVG Win64:Trojan-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[downloader]:Win/Malgent.Gen
No IRMA results available.