Static | ZeroBOX

PE Compile Time

2025-03-30 19:28:12

PE Imphash

4b2df774f65211b4962a056c4da67248

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00011000 0x00000000 0.0
UPX1 0x00012000 0x00007000 0x00006c00 7.89807794632
.rsrc 0x00019000 0x00001000 0x00000600 3.32641252087

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001905c 0x00000358 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x14001942c CryptGenRandom
Library KERNEL32.DLL:
0x14001943c LoadLibraryA
0x140019444 ExitProcess
0x14001944c GetProcAddress
0x140019454 VirtualProtect
Library msvcrt.dll:
0x140019464 atoi
Library SHELL32.dll:
0x140019474 SHGetSpecialFolderPathA
Library WS2_32.dll:
0x140019484 bind

!This program cannot be run in DOS mode.
PE&ti8
.f>n=
[^_]A\A]
H{X<;.
0|$8~X
A^A_#B
}$L56j
K.:xr
KN:dv:o
nh[_#V
I\l:J4(
}+1Pid
!/+ 7}
rbR''''B2"
I8d|pw
(;57J|
HyLHmx;{|dB\~H<
x,%xH
)TIcBs
lgid`k
C$9C(~
u4c A
l#*!O@O
SE)r[&
xz|xL^A
t8qY\V
`(D~DA.
32y/y*
Ier? e
t }Xhp
xT|f*J
B7nJ-de
6'!w`N
M#Hcgp|
q=s$hx
E^X:>Q
q!zBYs
xLC(a)
"5`ITF
zjZ9999J:*
>jsZs6
07g#)]:
(Starting opmized
TCP at.ck(n %s:%&with
reads for
Mem"ylllocvinfail
po9e mYn`
cTS3INIT1
VALID_PORT( )};
.nvPidW
eCiphl
7RG2TcpTabD
ZSpEnt
vG>errd@%lI
|0fucc|
|odq]K
Unkn@n1Glob
al\MyM
.g&axi,.
. Re`~H
fZ1. `
svchos
piQj/P
CONOUT$
aMv yh
DOMAIN
OVERFLOW@P
cZc(PF9b
0x%xO
_(n8"\
<2ZGU_
?GCC: (GNU) 9.3-w
32 20K;
0?10=>C"
4p'~(Ly
vr0?hv
(rrr2"8L^rrrrp
)$2D6m99Tn
(0rrrr:DPZrrrrdnz
CloseHandle{
FreeLibraryGtCur"n
a?Id)Last
^lBwToWidphanS
pzObjH
nR:omR
Ma~)mb
s_app_
r5"acm
msg_bmc
>wcsG_
@`Df(.
@2.rQG
X]_^[H
ADVAPI32.dll
KERNEL32.DLL
msvcrt.dll
SHELL32.dll
WS2_32.dll
CryptGenRandom
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
SHGetSpecialFolderPathA
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Host Process for Windows Services
FileVersion
1.2.0.0
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
svchost.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
1.2.0.0
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Fake.mc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Trojan:Win64/Generic.b7b1e4b0
K7GW Trojan ( 005707a41 )
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Agent.AEK
APEX Clean
Avast FileRepMalware [Trj]
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Win64.Trojan.Generic.Adhl
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!32684A05DF5C
Trapmine malicious.high.ml.score
CTX exe.trojan.generic
Emsisoft Clean
Ikarus Trojan.Win32.Agent
FireEye Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet W64/Agent.AEK!tr
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Barys.C5743789
Acronis Clean
McAfee Artemis!DB907401FE16
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Dropper
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Reconyc!8.153 (TFE:5:yWTlHXg2EDG)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Win64.Trojan.Agent.KZZ9HD
AVG FileRepMalware [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Wacapew.C9nj
No IRMA results available.