Static | ZeroBOX

PE Compile Time

2025-03-30 19:28:03

PE Imphash

4b2df774f65211b4962a056c4da67248

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00011000 0x00000000 0.0
UPX1 0x00012000 0x00007000 0x00006c00 7.89807199177
.rsrc 0x00019000 0x00001000 0x00000600 3.32641252087

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001905c 0x00000358 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x14001942c CryptGenRandom
Library KERNEL32.DLL:
0x14001943c LoadLibraryA
0x140019444 ExitProcess
0x14001944c GetProcAddress
0x140019454 VirtualProtect
Library msvcrt.dll:
0x140019464 atoi
Library SHELL32.dll:
0x140019474 SHGetSpecialFolderPathA
Library WS2_32.dll:
0x140019484 bind

!This program cannot be run in DOS mode.
PE&ti8
.f>n=
[^_]A\A]
H{X<;.
0|$8~X
A^A_#B
}$L56j
K.:xr
KN:dv:o
nh[_#V
I\l:J4(
}+1Pid
!/+ 7}
rbR''''B2"
I8d|pw
(;57J|
HyLHmx;{|dB\~H<
x,%xH
)TIcBs
lgid`k
C$9C(~
u4c A
l#*!O@O
SE)r[&
xz|xL^A
t8qY\V
`(D~DA.
32y/y*
Ier? e
t }Xhp
xT|f*J
B7nJ-de
6'!w`N
M#Hcgp|
q=s$hx
E^X:>Q
q!zBYs
xLC(a)
"5`ITF
zjZ9999J:*
>jsZs6
07g#)]:
(Starting opmized
TCP at.ck(n %s:%&with
reads for
Mem"ylllocvinfail
po9e mYn`
cTS3INIT1
VALID_PORT( )};
.nvPidW
eCiphl
7RG2TcpTabD
ZSpEnt
vG>errd@%lI
|0fucc|
|odq]K
Unkn@n1Glob
al\MyM
.g&axi,.
. Re`~H
fZ1. `
svchos
piQj/P
CONOUT$
aMv yh
DOMAIN
OVERFLOW@P
cZc(PF9b
0x%xO
_(n8"\
<2ZGU_
?GCC: (GNU) 9.3-w
32 20K;
0?10=>C"
4p'~(Ly
vr0?hv
(rrr2"8L^rrrrp
)$2D6m99Tn
(0rrrr:DPZrrrrdnz
CloseHandle{
FreeLibraryGtCur"n
a?Id)Last
^lBwToWidphanS
pzObjH
nR:omR
Ma~)mb
s_app_
r5"acm
msg_bmc
>wcsG_
@`Df(.
CRTi#1Z
X]_^[H
ADVAPI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
WS2_32.dll
CryptGenRandom
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
SHGetSpecialFolderPathA
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Host Process for Windows Services
FileVersion
1.2.0.0
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
svchost.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
1.2.0.0
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (moderate confidence)
MicroWorld-eScan Gen:Variant.Barys.431553
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Barys.431553
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Agent.AEK
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky HEUR:Trojan.Win64.Generic
BitDefender Gen:Variant.Barys.431553
NANO-Antivirus Clean
ViRobot Clean
Tencent Win64.Trojan.Generic.Pzfl
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Barys.431553
TrendMicro Clean
Trapmine malicious.high.ml.score
CTX exe.unknown.barys
Emsisoft Gen:Variant.Barys.431553 (B)
Ikarus Trojan.Win32.Agent
FireEye Gen:Variant.Barys.431553
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Barys.D695C1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Barys.C5743789
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Dropper
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Reconyc!8.153 (TFE:5:yWTlHXg2EDG)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Gen:Variant.Barys.431553
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.