Static | ZeroBOX

PE Compile Time

2025-02-24 19:00:11

PE Imphash

3318a4310235d39fc3cad1d3c7dfd161

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0004d000 0x00000000 0.0
UPX1 0x0004e000 0x00036000 0x00036000 7.93573994413
.rsrc 0x00084000 0x00005000 0x00004a00 3.53146012881

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00086034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00086034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00086034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x00086034 0x000025a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007c5cc 0x000004e3 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000885e0 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x488724 RegCloseKey
Library GDI32.dll:
0x48872c BitBlt
Library gdiplus.dll:
0x488734 GdipFree
Library KERNEL32.DLL:
0x48873c LoadLibraryA
0x488740 ExitProcess
0x488744 GetProcAddress
0x488748 VirtualProtect
Library ole32.dll:
0x488750 CoGetObject
Library SHELL32.dll:
0x488758 ExtractIconA
Library SHLWAPI.dll:
0x488760 StrToIntA
Library urlmon.dll:
0x488768 URLDownloadToFileW
Library USER32.dll:
0x488770 DrawIcon
Library WININET.dll:
0x488778 InternetOpenW
Library WINMM.dll:
0x488780 PlaySoundW
Library WS2_32.dll:
0x488788 WSAGetLastError

!This program cannot be run in DOS mode.
5\InC
x (h.6
,B&dH0
'ToSPL
}SgO&RQ
\$,j08UP
NDK<*<
VR:k%]
5t*WG8
o <PG8_
^M-SA(
9>$Gd;JIY0
=-'X<
^|9^xv
8FYHZhh
Dm<&hx
g{jD^VS
+@dXUY
.U.<sp
\+GiwM,Q
E^@#|O
6Z&">X
W;[6"H\
C<PPWS
|zWhdvc
@ws;{G
{UK!JFq
p5bXk)
9Wh$/
dsi*&G
.uBh>d
}xX@?-.*
y|tH:<
Y87Xr4t
ejxOyh
sjdOxK
xu3_e7
D98u,:
}L^$z
32NsT
@+Ch]0q
we~jnGz
/pwVtE.t1-t
6%XA^H^
Z@&H-s
cuL4H*
~#S3&"
L!@,hz
]|iH)$
8xZ98y
Fy <`P}k
8N89RykC,
d@x`#h
j.kL{<
k(K4;O
-4?aq5
&e]PwK!
$4oU)t$
9V?g~Q
9{Lt:V
]kF hD
(bvQSti
SBK,*
_hWd0#&
`4V(PoH
PY<9X8t
XP4+S4
V'xGyi\l=0
`wGy$
(fCXl
.jd}P
d >4_h
0WXCK7
VU[4,z
2x,F;H
Jje?|,0
yrl4m,
,jQ-;wR
I&9Ijf
tx9HM[
@$@P1^
WSP7~~
`?S)Gz'
aRyM1L
4GXk"<3
((^%*cU,
o/C+h3
T@$@Fd
K&=RQl]
 !"#$%&'()*+,-N.
/N01N2N34N
5678j9:;N<=>?@AB
JCDNEFGHIJK
jd<XT"
]Ia=4x (
VuC0swA
Dhi-m0p
!FPWv5
#Uell1
3oW`Dg
D$WkW0=p
x@Bv_|
Bp1u[B
xVV+c&
6(]AU?
J.40vD
{4(D1
PLs4w@
<(a*!4
$C<_KE;{
ZGh(~t
X8feza
\O 6bs
Yt'v+4p
D03^_[+
Dw23Y5
X3?_8h
,&]"R
a$WlbW
qf:o r
o+y02I3I
aYu4GW
2^3f"f$f'
Ffj Rb{3jG
~T$,=$"
)A-!g
K4084P
W$0<0t
mW"RhT
+w*c42\
:i<*u?
t%<.tHFm
NLjHYb<
k6fxAp
_{%40D:
:zQ$:/
SF/@tpB
h'<Kl
xud\,o
[^ZiBn
Lj $AF>
!cB|f@4X
B6.<F
9F)4d)/
#*T'vK
Nh\4+AV
hvd$X
2fc5"_
a5wu"'
z]F^%T
`,EZ_2
/]1<Hf9
7~+0r
\SR+B14H7
d>j3j,i
Drb* 8f
g2}IbZ
WV,<8R
PImb*
IxJRD(
zry^[d?
X8w/O
mS60kM
;'@S8:
#0ZR^@8H
H9s._m
_R^a$R
I^qYM;
=/|`>&d
49;D*<
^7Z;.:D(l~
'`c<^4
V^v@Vh
UrH1det
wNtE\Et6
87UPS%
F O|.)
g[w-EVa
0tQmuI+
V~eTfQ
6T!lXy;
;}[;'P
N=69b`
|}'t}p
5G&vDw
hj %SU
4J(@,/
$*XVTfF
~F43$<
'$Tt3gy
b]c(2~
|64l<Wnb
v9008@08:'A
@`6Ku9
#>[B#6(%
jk`2fUf
!@<:f0
dQPUJ4>;
z98r1A
jBKjPe
m,#!MM)DO
6Sj\nI
hi;$SI3
;90u,zP`
ZR~f43
P%1{PP
ax7p8<
(M <~0
t.7777
spuqj@Y;
WYj=f5}
` 6 'i
.n)j&f
{9+zCD8
~$FTPTCQ9
j90y$=
$"(9)Hu
kx&WP=
l@Q{:E
\V-O"
fPJDzp2
A_"%oL
GCbA0L02
\=)8%}
Db(\%Zn
}"f\$X
=AuFFI
u{CJ7 C
T:H(uB2U9
>T}:`
Sxj5A;
lP[H 2
9$b=\.W0 9
D0$H$A
j 4nfc
C<hlS=L
)q-^+Q
b:KY0;-
d4HPLh)
5ntel3
a!)Z0'
TL$P.Cr
E$WW9v
CA8l?R
F ,n00
X"xK/'
V ^0f@nP
|>v`~p
dodo|^gVto
p]RC.x6
r-%ARo
Vr> 'k'
jg[cKf
2grWl-T
w[0@u|%
A A\03
W4r49z
t)u(>(
8Wk")C
~?rf7@
p+b"1[
](*^);
hU4HMx
ibeu ~
Hn=Ak
Lt>Tt-h
]PKPlt*
TNSB1jhZ;
^$+^8+
tjAZjX
q>Y{k1;
kYYkO7
JlLn3D
PMv8E3
b0?]"W
zzz0{r QL+8
WdP<h:
.0z~EcO
bjO>]%
P8@6>d
:@$,`iF
!1MRP
lmTk]Q~
WkR\.<
vjA[jZ^8
V]j;vr
@Vn7OV
v*]0PT
wPrhxW
/UjSW@Pp
M4d),E
:=p7Nt
7,g\Z?
2g<j7Ky
}O$IV%
nK5+:P:#0
*u0"q~<Y9'K
],PkHx
q8C&#V
i$(5>(
1'HvEw
zjA^f(l
N-<6'M
6@59ZB.6
`@)|>dnU
ZZ$jjd
9&/vrZ
vqJ;9E
59q jj
HA9\0j
L:jCxFu
8v5i]X
pM@1tJU
=$WJ.6"
C62QW"
C_8k}0
NHeuDi&
!PuD.D
(Azm)f
%6H- E^p
p[s<y"
hwPfLr
mB8[qn
,c80
BRP9aT6
:JZU.S3
9wqgA
94(nVQ
O4@8JwL
]}!E(j
hrYYfit
rE` 1@]
-b+xAu
P(-((X
X [^e<|
|L$<l`
Od,,l;5
^vZp#E
2Rico0:
&-`W.,R
+/S864k
&EtX.
oSY]p$
!FXN"{
$naCiCet
E0TK`#
5F\[-)
N6$hgAx5
R7|]{6PZ
IAlp,*T4
V9|^oQHu
?.SerQWic
$nnd83YRi!ir
Yhs$t0
2,A!7`
|[n@tJYx6
48.vd8
*;<p
'2)]`-
]*K%+/R
a4*hd(F
K/]EO,
p<Z=F9F
ppHu6
v'Eb`t
FPjF`jF)
z@B$+d
WVU<>A
8s<Bt4)u
V}2jP&
]mhTxhf
E<ia(v/
b<c;Tc'
.8J\y
yl\P@*
4$4HVzy
B0h= a
45Kaw
InitializeCond
mmblZS
akeAlli
locasT<
_rray new
!unknown e
Pj\gp=
8uHvXw<
8sO&By
ytDuCv
address famil
ot supporte
in useQavaf
connecy
argumenPlis
cripzr'm8ag
s'5i\A
d'"t&b
6$Hn)_
`quirg[
AeAmovO
s[achT 1
? tw0kF
-x+j(k
s'u" O
raBl('
ueQ$lG2u
Ex7OhE
JePEv`
orkubBEj
oN/F124<
fghijklmnhq
h#p$x%y
y(J0K8
PVXW`ZZ6
'()4*@<
<+L,X-
y<EHFT
0;<?$4
L$X$d*M
Si*M<(<4@JSyJ@
&'nOfi
vnpp_r/
l_f}xmm*i
ooiOs?k
uGhw*L
cyph7H
UeYK[t
R?-BNG
NM>6Zxv
]m_McgG
P/fGCo
7mEssgY6'Hn
0B_OgnXr
H?LGAvmvpU7/B_P/o_k
vwt7eu{
V7uGupBr
}vH.PX\`
#7calstd
lrgeab
wift_N
rerict)
lignph
s_`||6*+
\6guard/
N.pyQ`ud
*rx:/CA0U
'qP_tYm
_awO T
!hoObj
xwpwpp
(nuD)D
[aO0*{
eLK(w?
@b;zO]
v2!L.2
./m:;<=
vr!5AC
ZVi.at7day
v('Ja^
M,J@-m
PMM/dd/y
(,HH:mm:rk
<,048^@
<L`p<Oy
t>*e;5* B? FldS
t+b7wlk2{Sm wl
q8xfoCB
ApisANSI
~EnumY5Y
/IDToeg+
VccUTF-
16LEUNICODE
V%~ep
ggsvG|
bVl#C,i
ca_?8#
Fog'A#dj/s
w4mzqg
wu;jooOk
?mxx.Rz
<4U\Yf
sqrtMtK
9E=cei
fabwmod
_c1_hypo
f@or?y0
1nf]'a
y"x#|$
,@-H/Py
y6X7`8
<!D"P#
y(94:@
d@pA|Cy
0W<ZLe<
<\kll|W
,$;<>H>
H;`O p
JSi84D4P*
!=oJ5c
'nP'F\
?Dj0Q:W~
5s3R6/
09;N@ /
Fq/H!
^IO4g'
_nNNNN[H5#
]vQ<)8
74>U".
|)P!?Ua0
?x+sW~
uIJzR8
A@>O=o
;:8o7n''
6431o0
N.-+o*
vr;)'&o$
~~}o||Nn''{z?yy
NNNxwvov
utt?s;999rqqpovrrroonm?
gfed'''
docbbaNNNn?`__^
N]o]\[99
Z?ZYXrr;9WWoVU
vrUT?SR
ON?MM'
LKJoJIW
?5Od%
?|I7Z#
>,'1B
/pg)([{Us
G~U`K
&?~YK|
O#w_j+
Bfe9?0
CqTR;?L
?#%X.y
?5Wg4p
#{ ~`~R=
%S#[k
#.X'HBO
d %H.%Mnw
VEfmt
?E}<T>H{)
`edNQ T
F?key/l
6sha^.
d8Xg3Nfk
?R'g:)
WDisYm
gcmdy5
s NT\c
g SucB
/vUCCESS7-FAIL
2:4bBa
~ ADD H<\
G_DWORk
fflT,Key
&AltPaXF
EscgUg
/RighI/Pro
234rrrr5678
|r910]1
gC(l+V
=%v=PP
\r3.dbm
Fold<
@aPwce_
J7&e.p
Rigoj)
DSWWam
DsSxm{l
7I&group
}&geVi
%OK_eof-x
G.WfWD
AdmRPb
pPxivTf;\
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
=j&&LZ66l
OL\44h
}{))R>
f""D~**T
V22dN::t
o%%Jr..V
aa,55j
HA256wECDS
rvJ&n_0
zNg},8S*:#
)U[/t|
SECP1>R
7C2ABF62E35E668076B
EAD208B
$W8659EF
A043916EEDE8
1702B22
7628DFAC6561C5
94872
B55F9,F09
FF77500
E8757|0
$A30D1B9038A4QW
CF5AC8
?U1C97BE
54BYm7
>(23A*553
t0E70FA7E9AB743
:8DE|C1
$7$1\*A
D7$DPa
E8&3E1
PRIMEV]
#rBR38\
9Db5`&
1A9DB2F
J5dTO'
rmz]1`LE1N
,:F23Pt|jm4
E0~BbDB
dr8F6l<lh
:0zd6N
4%)+/
yOSYae
y9=KQ[
KQWY_ey
)+57;<
<=GUY[
yCEIOU
y=AGIMe
watchdog
l/'laun
FoxMl@Ab
pi.dll
ws2_32
%I64u.Yo
&^XcU/
DeHk8!
*nDISPLAY
l4ssI
r(lxWQu
B+6=L5
q}< Pa6\
$kfGDu
%ovtFnTC+X
CONOUT$6H
BzkK)k
-BEGIN CERTIFIC,
ATE+7END3o[
DH PARAMERS?w
_[-;wX509
.@$diw
.00cf%
@T\'O|J
'ZZ$O2
ldT('O,
$4Zg8:j9
ngLvBN
GTr, (c)
4.LtdJALL RIGHTS
SERVED.v
CzC#PST0Q
hP@@/ZC
_of_?z
= )_YWEt
C?U_Cr
*~/?$C@Dw6
?f:^7J
a EnvDonu
u)4i'LNgP
(Heap[
IdY) A"
QosF|#
AE$*Qp
>+e!.Q
VoBu,G
:U8p@R:1#,
hu+DP1
4HS:Ha
!_NoTf(c*
rxpCnslF!-
XPTPSW
33333333tQQ
33333333
ADVAPI32.dll
GDI32.dll
gdiplus.dll
KERNEL32.DLL
ole32.dll
SHELL32.dll
SHLWAPI.dll
urlmon.dll
USER32.dll
WININET.dll
WINMM.dll
WS2_32.dll
RegCloseKey
BitBlt
GdipFree
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoGetObject
ExtractIconA
StrToIntA
URLDownloadToFileW
DrawIcon
InternetOpenW
PlaySoundW
SETTINGS
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Remcos.m!c
Elastic malicious (moderate confidence)
ClamAV Win.Trojan.Remcos-9841897-0
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.174172283846c097
Skyhigh BehavesLike.Win32.Generic.dc
ALYac Dump:Generic.Remcos.F1511AFA
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:Win32/Remcos.d955cdd8
K7GW Trojan ( 0053ac2c1 )
K7AntiVirus Trojan ( 0053ac2c1 )
huorong Backdoor/Remcos.k
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Rescoms.B
APEX Malicious
Avast Win32:RATX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.Win32.Remcos.gen
BitDefender Dump:Generic.Remcos.F1511AFA
NANO-Antivirus Trojan.Win32.Remcos.kvsovm
ViRobot Clean
MicroWorld-eScan Dump:Generic.Remcos.F1511AFA
Tencent Trojan.Win32.Remcos.16001234
Sophos Mal/Remcos-B
F-Secure Backdoor.BDS/Backdoor.Gen
DrWeb BackDoor.Remcos.491
VIPRE Dump:Generic.Remcos.F1511AFA
TrendMicro Backdoor.Win32.REMCOS.YXFCLZ
McAfeeD Real Protect-LS!444C83A662CC
Trapmine malicious.high.ml.score
CTX exe.backdoor.remcos
Emsisoft Dump:Generic.Remcos.F1511AFA (B)
Ikarus Trojan.Win32.Remcos
FireEye Generic.mg.444c83a662cc3f05
Jiangmin Clean
Webroot Clean
Varist W32/ABApplication.ODWR-9196
Avira BDS/Backdoor.Gen
Fortinet W32/Rescoms.U!tr
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft malware.kb.b.972
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Dump:Generic.Remcos.FD5E7AFA
SUPERAntiSpyware Clean
ZoneAlarm Mal/Remcos-B
Microsoft Backdoor:Win32/Remcos!rfn
Google Detected
AhnLab-V3 Trojan/Win.RATX-gen.R625809
Acronis Clean
McAfee Artemis!444C83A662CC
TACHYON Clean
VBA32 BScope.Backdoor.Remcos
Malwarebytes Malware.AI.2088537425
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.REMCOS.YXFCLZ
Rising Backdoor.Remcos!8.B89E (TFE:5:AyOt9ijbbiR)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Dump:Generic.Remcos.F1511AFA
AVG Win32:RATX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Backdoor:Win/Remcos
No IRMA results available.