Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

14bf2a0b2c46c28de7035254c941b6ea

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00003f34 0x00004000 5.94064991535
.data 0x00005000 0x00000380 0x00000400 0.869053061447
.rdata 0x00006000 0x0000153c 0x00001600 5.01192863671
.eh_fram 0x00008000 0x00000bcc 0x00000c00 4.57800338814
.bss 0x00009000 0x00005160 0x00000000 0.0
.idata 0x0000f000 0x00000604 0x00000800 3.76924085009
.CRT 0x00010000 0x00000018 0x00000200 0.0940979256627
.tls 0x00011000 0x00000020 0x00000200 0.210826267787

Imports

Library KERNEL32.dll:
0x40f13c CreateThread
0x40f148 ExitProcess
0x40f14c GetLastError
0x40f150 GetModuleHandleA
0x40f154 GetProcAddress
0x40f164 Sleep
0x40f168 TlsGetValue
0x40f16c VirtualProtect
0x40f170 VirtualQuery
Library msvcrt.dll:
0x40f178 __getmainargs
0x40f17c __p__environ
0x40f180 __p__fmode
0x40f184 __set_app_type
0x40f188 _cexit
0x40f18c _iob
0x40f190 _onexit
0x40f194 _setmode
0x40f198 abort
0x40f19c atexit
0x40f1a0 atoi
0x40f1a4 calloc
0x40f1a8 fprintf
0x40f1ac free
0x40f1b0 fwrite
0x40f1b4 getenv
0x40f1b8 malloc
0x40f1bc memcpy
0x40f1c0 memset
0x40f1c4 perror
0x40f1c8 printf
0x40f1cc putchar
0x40f1d0 puts
0x40f1d4 signal
0x40f1d8 strcmp
0x40f1dc strcpy
0x40f1e0 strncpy
0x40f1e4 vfprintf
Library WSOCK32.DLL:
0x40f1ec WSAStartup
0x40f1f0 __WSAFDIsSet
0x40f1f4 accept
0x40f1f8 bind
0x40f1fc closesocket
0x40f200 connect
0x40f204 gethostbyname
0x40f208 htons
0x40f20c inet_ntoa
0x40f210 listen
0x40f214 recv
0x40f218 select
0x40f21c send
0x40f220 socket

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.eh_fram
0@.bss
.idata
127.0.0.1
127.0.0.1
libgcc_s_dw2-1.dll
__register_frame_info
libgcj-13.dll
_Jv_RegisterClasses
__deregister_frame_info
WSAStartup failed!
Create Socket Failed !
Client Bind Port Failed !
Server IP Address Error!
Can Not Connect To %s!
Could not create socket
bind failed. Error
s:l:aqht:vd:e:f:g:
refhost
refport
connhost
connport
listenport
usectime
version
c is %d
ssocksd
rcsocks
rssocks
lcx_listen
lcx_tran
lcx_slave
free 1.0
VERSION : %s
VERSION : %s
./xxx ([-options] [values])*
options :
Eg: ./xxx -s ssocksd -h
-s state setup the function.You can pick one from the
following options:
ssocksd , rcsocks , rssocks ,
lcx_listen , lcx_tran , lcx_slave
-l listenport open a port for the service startup.
-d refhost set the reflection host address.
-e refport set the reflection port.
-f connhost set the connect host address .
-g connport set the connect port.
-h help show the help text, By adding the -s parameter,
you can also see the more detailed help.
-a about show the about pages
-v version show the version.
-t usectime set the milliseconds for timeout. The default
value is 1000
......
You can create a lcx_listen tunnel like this :
./ew -s lcx_listen --listenPort 1080 --refPort 8888
or ./ew -s lcx_listen -l 1080 -e 8888
You can create a lcx_slave tunnel like this :
./ew -s lcx_slave --refhost [ref_ip] --refport 1080 -connhost [connIP] --connport 8888
or ./ew -s lcx_slave -d [ref_ip] -e 1080 -f [connIP] -g 8888
You can create a lcx_tran tunnel like this :
./ew -s lcx_tran --listenport 1080 -connhost xxx.xxx.xxx.xxx --connport 8888
or ./ew -s lcx_tran -l 1080 -f [connIP] -g 8888
You can create a SOCKS5 server like this :
./ew -s ssocksd --listenport 1080
or ./ew -s ssocksd -l 1080
You can create a rcsocks tunnel like this :
./ew -s rcsocks --listenPort 1080 --refPort 8888
or ./ew -s rcsocks -l 1080 -e 8888
You can create a rssocks Server like this :
./ew -s rssocks --refHost xxx.xxx.xxx.xxx --refPort 8888
or ./ew -s rssocks -d xxx.xxx.xxx.xxx -e 8888
Earthworm is a network agent tool.
You can create a Socks5 proxy server in the Intranet or Extranet.
You can also create a N level jump Socks server with it.
The Readme file is a help document. Please read carefully.
You can get help from -h or --help parameters.
By adding the -s parameter, you can also see the more detailed help.
Eg: ./xxx -h -s ssocksd
Contributors
rootkiter : The creator
asky : <<Linux Programming by
Example>>is a great book
darksn0w : Proviede some advice
zhuanjia : Modify the Readme file
syc4mor3 : Named for this tool
http://rootkiter.com/EarthWrom/
_ooOoo_
o8888888o
88" . "88
(| -_- |)
O\ = /O
____/`---'\____
. ' \\| |// `.
/ \\||| : |||// \
/ _||||| -:- |||||- \
| | \\\ - /// | |
| \_| ''\---/'' | |
\ .-\__ `-` ___/-. /
___`. .' /--.--\ `. . __
."" '< `.___\_<|>_/___.' >'"".
| | : `- \`.;`\ _ /`;.`/ - ` : | |
\ \ `-. \_ __\ /__ _/ .-` / /
======`-.____`-.___\_____/___.-`____.-'======
`=---='
..........................................................
the recv ip is %s
Something error on read URL
the read url is %s
Tcp ---> %s:%d
--> %3d <-- (close)used tunnel %d , unused tunnel %d
ssocksd 0.0.0.0:%d <--[%4d usec]--> socks server
accept failed
ssocksd close ?????
rssocks %s:%d <--[%4d usec]--> socks server
could not create one way tunnel
may be sth wrong ~ %d reconnect now!
init cmd_server_for_rc here
start listen port here
Error on connect %s:%d [proto_init_cmd_rcsocket]
Error on send I_AM_NEW_RC_CMD_SOCK_CLIENT.
Error on recv CONFIRM_YOU_ARE_SOCK_CLIENT 1.
Error on recv CONFIRM_YOU_ARE_SOCK_CLIENT 2.
Error on send new tunnel cmd
Error on recv CONFIRM_YOU_ARE_SOCK_TUNNEL
Error on recv CONFIRM_YOU_ARE_SOCK_TUNNEL 2
rssocks cmd_socket OK!
accept failed
exit socks_port_server
rcsocks 0.0.0.0:%d <--[%4d usec]--> 0.0.0.0:%d
lcx_tran 0.0.0.0:%d <--[%4d usec]--> %s:%d
close tran ????
lcx_slave %s:%d <--[%4d usec]--> %s:%d
Mingw runtime failure:
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
%s: option requires an argument -- %c
%s: unrecognised option `-%s'
%s: invalid option -- %c
option `%s%s' doesn't accept an argument
option `%s%s' requires an argument
%s: option `%s' is ambiguous
%s: unrecognised option `%s'
POSIXLY_CORRECT
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
GCC: (GNU) 4.8.1
CreateThread
DeleteCriticalSection
EnterCriticalSection
ExitProcess
GetLastError
GetModuleHandleA
GetProcAddress
InitializeCriticalSection
LeaveCriticalSection
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
__getmainargs
__p__environ
__p__fmode
__set_app_type
_cexit
_onexit
_setmode
atexit
calloc
fprintf
fwrite
getenv
malloc
memcpy
memset
perror
printf
putchar
signal
strcmp
strcpy
strncpy
vfprintf
WSAStartup
__WSAFDIsSet
accept
closesocket
connect
gethostbyname
inet_ntoa
listen
select
socket
KERNEL32.dll
msvcrt.dll
WSOCK32.DLL
crt1.c
_atexit
__onexit
cygming-crtbegin.c
.rdata
BaseAPI.c
.rdata
EWmain.c
_mainDo
_quFun
_realDo
.rdata
SocksBase.c
.rdata
Sock_Tunnel.c
.rdata
ssocksd_pro.c
.rdata
rssocks_pro.c
.rdata
CMD_Protocol.c
.rdata
Lcx_Base.c
.rdata
.idata$7
.idata$5
.idata$4
.idata$6`
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$44
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4$
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4,
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6n
.idata$7
.idata$5
.idata$40
.idata$6
.idata$7
.idata$5
.idata$4(
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6~
fthunk
.idata$2(
.idata$4
.idata$5
.idata$48
.idata$5$
.idata$7
tlssup.c
___xd_z
___xd_a
.CRT$XLD
.CRT$XLC
.rdata
.CRT$XLZ
.CRT$XLA
.tls$ZZZ
.tls$AAA
.CRT$XDZ
.CRT$XDA
CRTglob.c
CRTfmode.c
txtmode.c
cpu_features.c
CRT_fp10.c
_fpreset
pseudo-reloc.c
.rdata
gccmain.c
_p.1761
___main
crtst.c
tlsthrd.c
usleep.c
_usleep
getopt.c
_getopt
.rdata
.idata$7X
.idata$5
.idata$4
.idata$6
.idata$7h
.idata$5
.idata$4
.idata$6
.idata$7\
.idata$5
.idata$4
.idata$6
.idata$7D
.idata$5x
.idata$4
.idata$66
.idata$7`
.idata$5
.idata$4
.idata$6
.idata$7L
.idata$5
.idata$4
.idata$6V
.idata$7H
.idata$5|
.idata$4
.idata$6F
.idata$7T
.idata$5
.idata$4
.idata$6v
.idata$7
.idata$5
.idata$4
.idata$6,
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6$
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6J
.idata$7l
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$66
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6@
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7|
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6T
.idata$7d
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7p
.idata$5
.idata$4
.idata$6
.idata$7x
.idata$5
.idata$4
.idata$6
.idata$7
.idata$5
.idata$4
.idata$6
.idata$7t
.idata$5
.idata$4
.idata$6
fthunk
.idata$2
.idata$4
.idata$5x
.idata$4
.idata$5
.idata$7
.idata$7
.idata$5`
.idata$4t
.idata$6
.idata$7
.idata$5H
.idata$4\
.idata$6h
.idata$7
.idata$5P
.idata$4d
.idata$6
.idata$7
.idata$5T
.idata$4h
.idata$6
.idata$7$
.idata$5d
.idata$4x
.idata$6
.idata$7
.idata$5<
.idata$4P
.idata$6(
.idata$70
.idata$5p
.idata$4
.idata$6&
.idata$7,
.idata$5l
.idata$4
.idata$6
.idata$7
.idata$5D
.idata$4X
.idata$6P
.idata$7(
.idata$5h
.idata$4|
.idata$6
.idata$7
.idata$5L
.idata$4`
.idata$6v
.idata$7
.idata$5\
.idata$4p
.idata$6
.idata$7
.idata$5@
.idata$4T
.idata$68
.idata$7
.idata$5X
.idata$4l
.idata$6
fthunk
.idata$2
.idata$4P
.idata$5<
.idata$4
.idata$5t
.idata$74
cygming-crtend.c
.idata$7P
.idata$5
.idata$4
.idata$6d
__cexit
_putchar8>
_strcmp
_opterr
_recv@16
___xl_c
_refPortL
___xl_z
_to_URL
_state
_bind@12
__dll__
_fwrite
_strncpy >
_memcpy
_optarg
_memset
_optopt
__argc
___xl_a
___xl_d
__CRT_MTL
_send@16
_fprintf
__argv
_calloc
__fmode
_getenv
__end__
_signal
_malloc
_strcpy
_optind
_to_portLQ
_perror
_abort
_htons@4
_refHost
_printf
_Sleep@4
___mingw_CRTStartup
__gnu_exception_handler@4
_mainCRTStartup
_WinMainCRTStartup
.eh_frame
___EH_FRAME_BEGIN__
___JCR_LIST__
___gcc_register_frame
___gcc_deregister_frame
.rdata$zzz
_API_env_init
_API_socket_connect
_API_socket_init_server
_API_socket_gethostbyname
_API_socket_read_state
_API_socket_write_state
_API_socket_send
_API_socket_recv
_API_socket_close
_API_m_itochar
_API_m_chartoi
_API_m_sleep
_API_set_usec_time
_API_get_usec_time
_getStatenum
_about_fun
_socks_build_target_socket
_socks_check_and_tunnel@4
_socks_build_rcsocks_tunnel
_tunn_init_Pool
_tunn_clean
_tunn_close
_tunn_run_now@4
_tunn_get_pool_id_and_lock_it
_tunn_set_first_pool_and_lock_it
_tunn_set_second_pool_and_run_it
_tunn_sock_to_sock
_check_and_tunnel@4
_create_ssocksd_server
_create_rssocks_server
_cleancmdbuff
_proto_init_cmd_server_for_rc
_proto_init_cmd_rcsocket
_proto_get_rcsocket
_proto_understand_and_do_it
_proto_send_rccmd_poolnum
_create_socks_port_server@4
_create_listen_port@4
_lcx_listen
_lcx_tran
_check_and_slave_tunnel@4
_lcx_slave
___dyn_tls_dtor@12
___dyn_tls_init@12
___tlregdtor
___cpu_features_init
__fpreset
___report_error
___write_memory.part.0
__pei386_runtime_relocator
_was_init.31048
___do_global_dtors
___do_global_ctors
_initialized
___mingwthr_run_key_dtors.part.0
___mingwthr_cs
_key_dtor_list
____w64_mingwthr_add_key_dtor
___mingwthr_cs_init
____w64_mingwthr_remove_key_dtor
___mingw_TLScallback
pseudo-reloc-list.c
_getopt_parse
_argind.2300
_optbase.2301
_optmark.2303
_nextchar.2302
_conventions.2258
_getopt_long
_getopt_long_only
___FRAME_END__
___JCR_END__
_register_frame_ctor
.text.startup
.ctors.65535
_VirtualProtect@16
_cmdstate
___RUNTIME_PSEUDO_RELOC_LIST__
__imp__getenv
__imp___setmode
__data_start__
___DTOR_LIST__
__imp__bind@12
__imp__VirtualProtect@16
__imp__recv@16
.weak.__Jv_RegisterClasses.___gcc_register_frame
__imp___onexit
___p__fmode
__imp__GetLastError@0
_SetUnhandledExceptionFilter@4
__imp__VirtualQuery@12
__imp__select@20
___tls_start__
__imp__TlsGetValue@4
__libmsvcrt_a_iname
__imp__InitializeCriticalSection@4
_DeleteCriticalSection@4
__rt_psrelocs_start
.weak.___register_frame_info.___gcc_register_frame
__imp__abort
__dll_characteristics__
__size_of_stack_commit__
__size_of_stack_reserve__
__major_subsystem_version__
___crt_xl_start__
___crt_xi_start__
___crt_xi_end__
_GetLastError@0
__imp____p__environ
_VirtualQuery@12
_mingw_initltsdrot_force
__imp___iob
_GetModuleHandleA@4
___register_frame_info
__bss_start__
___RUNTIME_PSEUDO_RELOC_LIST_END__
_CreateThread@24
__size_of_heap_commit__
__imp__listen@8
___p__environ
__imp__GetProcAddress@8
_GetProcAddress@8
___crt_xp_start__
__imp__putchar
_listenPort
___crt_xp_end__
_usec_for_EW
__imp__signal
__imp__puts
__minor_os_version__
__imp__atexit
__head_libmsvcrt_a
_accept@12
__image_base__
__imp__accept@12
__section_alignment__
_socket@12
__imp____WSAFDIsSet@8
__imp__CreateThread@24
__IAT_end__
__RUNTIME_PSEUDO_RELOC_LIST__
__imp__htons@4
__imp____p__fmode
__tls_start
_ExitProcess@4
__imp__inet_ntoa@4
_gethostbyname@4
__data_end__
_cmd_socket
___getmainargs
__CTOR_LIST__
___set_app_type
__imp__perror
__bss_end__
__CRT_fmode
__head_libwsock32_a
___crt_xc_end__
__tls_index
___crt_xc_start__
__imp__socket@12
__imp__closesocket@4
___CTOR_LIST__
_inet_ntoa@4
__rt_psrelocs_size
___mingw_optreset
_WSAStartup@8
__imp__memcpy
__imp__strcmp
__file_alignment__
_select@20
_from_port
_connPort
__imp__LeaveCriticalSection@4
_from_URL
__imp__malloc
__imp__atoi
__imp__strncpy
__major_os_version__
__imp__gethostbyname@4
__IAT_start__
__tls_end
_live_num
__imp__GetModuleHandleA@4
__DTOR_LIST__
__imp__fprintf
_EnterCriticalSection@4
__imp__memset
.weak.___deregister_frame_info.___gcc_register_frame
__size_of_heap_reserve__
___crt_xt_start__
___ImageBase
__subsystem__
__imp__strcpy
__imp__calloc
__Jv_RegisterClasses
__imp____getmainargs
_listen@8
___tls_end__
__imp__ExitProcess@4
_mingw_initltssuo_force
_connHost
__imp__send@16
_InitializeCriticalSection@4
___cpu_features
__imp__free
__imp__SetUnhandledExceptionFilter@4
___deregister_frame_info
__major_image_version__
__loader_flags__
__CRT_glob
__setmode
__imp__printf
___chkstk_ms
_socks_Pool
__head_libkernel32_a
__rt_psrelocs_end
__imp___cexit
___WSAFDIsSet@8
__minor_subsystem_version__
__minor_image_version__
__imp__Sleep@4
__imp__vfprintf
_optstring
_closesocket@4
__imp____set_app_type
_mingw_initltsdyn_force
_TlsGetValue@4
__imp__DeleteCriticalSection@4
_LeaveCriticalSection@4
__imp__WSAStartup@8
__RUNTIME_PSEUDO_RELOC_LIST_END__
__libkernel32_a_iname
___dyn_tls_init_callback
_connect@12
__libwsock32_a_iname
__imp__connect@12
__tls_used
___crt_xt_end__
_vfprintf
__imp__EnterCriticalSection@4
_can_write_pool
__imp__fwrite
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Hacktool.Win32.Earthworm.3!c
Elastic malicious (high confidence)
ClamAV Win.Tool.Earthworm-9875816-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Adware.GenericKD.61013633
Cylance Unsafe
Zillya Tool.NetHacker.Win32.27
CrowdStrike win/grayware_confidence_60% (W)
Alibaba NetTool:Application/SocksSevice.190603
K7GW Hacktool ( 00561aba1 )
K7AntiVirus Hacktool ( 00561aba1 )
huorong HackTool/Earthworm
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Hacktool
tehtris Clean
ESET-NOD32 a variant of Win32/HackTool.NetHacker.AC
APEX Clean
Avast Win32:Malware-gen
Cynet Malicious (score: 99)
Kaspersky HEUR:HackTool.Win32.Earthworm.gen
BitDefender Adware.GenericKD.61013633
NANO-Antivirus Trojan.Win32.NetHacker.icjkwq
ViRobot Clean
MicroWorld-eScan Adware.GenericKD.61013633
Tencent Malware.Win32.Gencirc.115c7754
Sophos Generic Reputation PUA (PUA)
F-Secure Trojan.TR/NetHacker.tivyv
DrWeb Tool.Earthworm.1
VIPRE Adware.GenericKD.61013633
TrendMicro HackTool.Win32.EarthWorm.B
McAfeeD ti!A76EAABC4E8B
Trapmine Clean
CTX exe.hacktool.generic
Emsisoft Adware.GenericKD.61013633 (B)
Ikarus PUA.Hacktool.Earthworm
FireEye Adware.GenericKD.61013633
Jiangmin HackTool.Earthworm.g
Webroot Clean
Varist W32/Earthworm.A.gen!Eldorado
Avira TR/NetHacker.tivyv
Fortinet Riskware/NetHacker
Antiy-AVL Trojan[APT]/Win32.Earthlusca
Kingsoft Win32.HackTool.Earthworm.gen
Gridinsoft Hack.Win32.Patcher.oa!s1
Xcitium Malware@#3nay66mlwbcz5
Arcabit Adware.Generic.D3A2FE81
SUPERAntiSpyware Clean
ZoneAlarm HEUR:HackTool.Win32.Earthworm.gen
Microsoft PUA:Win32/Ymacco
Google Detected
AhnLab-V3 HackTool/Win32.Earthworm.R303865
Acronis Clean
McAfee GenericRXAA-AA!D7C40C24060C
TACHYON Clean
VBA32 BScope.Exploit.CVE-2020-0601
Malwarebytes RiskWare.HackTool
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall HackTool.Win32.EarthWorm.B
Rising PUA.Presenoker!8.F608 (C64:YzY0OiS9Hx9Suwxm)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.74186752.susgen
GData Win32.Riskware.Earthworm.A
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Proxytool:Multi/EarthWorm
No IRMA results available.