2024-12-19 05:50:31
2eabe9054cad5152567f0699947a2c5b
Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
---|---|---|---|---|
\x00 | 0x00001000 | 0x00729000 | 0x00283400 | 7.98923240237 |
.rsrc | 0x0072a000 | 0x000002b0 | 0x00000200 | 6.03851573435 |
.idata | 0x0072b000 | 0x00001000 | 0x00000200 | 1.15896851661 |
0x0072c000 | 0x0037c000 | 0x00000200 | 0.260771276048 | |
wasfhoet | 0x00aa8000 | 0x001b4000 | 0x001b3600 | 7.95466087122 |
ygjteyur | 0x00c5c000 | 0x00001000 | 0x00000400 | 6.24879608436 |
.taggant | 0x00c5d000 | 0x00003000 | 0x00002200 | 0.767924920543 |
Name | Offset | Size | Language | Sub-language | File type |
---|---|---|---|---|---|
RT_MANIFEST | 0x00c5b2ec | 0x00000256 | LANG_NEUTRAL | SUBLANG_NEUTRAL | ASCII text, with CRLF line terminators |
Antivirus | Signature |
---|---|
Bkav | W32.AIDetectMalware |
Lionic | Trojan.Win32.Themida.l!c |
Elastic | malicious (high confidence) |
ClamAV | Win.Packed.Zusy-10040002-0 |
CMC | Clean |
CAT-QuickHeal | Trojan.Ghanarava.1734884564e61725 |
Skyhigh | BehavesLike.Win32.Generic.rc |
ALYac | Gen:Variant.Zusy.568294 |
Cylance | Unsafe |
Zillya | Trojan.Themida.Win32.125511 |
Sangfor | Spyware.Win32.Themida.V0fs |
CrowdStrike | win/malicious_confidence_100% (W) |
Alibaba | TrojanSpy:MSIL/Themida.58def23f |
K7GW | Trojan ( 00587f0f1 ) |
K7AntiVirus | Trojan ( 00587f0f1 ) |
huorong | HEUR:TrojanSpy/Stealer.ay |
Baidu | Clean |
VirIT | Trojan.Win32.Genus.XLS |
Paloalto | generic.ml |
Symantec | ML.Attribute.HighConfidence |
tehtris | Clean |
ESET-NOD32 | a variant of Win32/Packed.Themida.HZB |
APEX | Malicious |
Avast | Win32:Evo-gen [Trj] |
Cynet | Malicious (score: 99) |
Kaspersky | Trojan-Spy.MSIL.Phpw.bhs |
BitDefender | Gen:Variant.Zusy.568294 |
NANO-Antivirus | Trojan.Win32.Phpw.kudzfv |
ViRobot | Clean |
MicroWorld-eScan | Gen:Variant.Zusy.568294 |
Tencent | Malware.Win32.Gencirc.1495ace1 |
Sophos | Mal/Generic-S |
F-Secure | Trojan.TR/Crypt.TPM.Gen |
DrWeb | Trojan.PWS.Amadey.227 |
VIPRE | Gen:Variant.Zusy.568294 |
TrendMicro | TROJ_GEN.R002C0DDG25 |
McAfeeD | Real Protect-LS!17830E6496A4 |
Trapmine | malicious.high.ml.score |
CTX | exe.trojan.themida |
Emsisoft | Gen:Variant.Zusy.568294 (B) |
Ikarus | Trojan.Win32.LummaStealer |
GData | Gen:Variant.Zusy.568294 |
Jiangmin | Clean |
Webroot | Clean |
Varist | W32/ABTrojan.GQCW-8531 |
Avira | TR/Crypt.TPM.Gen |
Antiy-AVL | Trojan[Packed]/Win32.Themida |
Kingsoft | Win32.HeurC.KVMH008.a |
Gridinsoft | Trojan.Heur!.038120A1 |
Xcitium | Malware@#likbmv8vig3z |
Arcabit | Trojan.Zusy.D8ABE6 |
SUPERAntiSpyware | Clean |
ZoneAlarm | Clean |
Microsoft | Trojan:Win32/StealC.BN!MTB |
Detected | |
AhnLab-V3 | Trojan/Win.Generic.C5700273 |
Acronis | Clean |
VBA32 | TScope.Malware-Cryptor.SB |
TACHYON | Clean |
Malwarebytes | Trojan.MalPack |
Panda | Trj/Chgt.AD |
Zoner | Probably Heur.ExeHeaderL |
TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9f |
Rising | Trojan.Agent!1.126F4 (CLASSIC) |
Yandex | TrojanSpy.Phpw!5d0oE0MP98o |
TrellixENS | Artemis!17830E6496A4 |
SentinelOne | Static AI - Malicious PE |
MaxSecure | Trojan.Malware.316620789.susgen |
Fortinet | W32/Themida.HZB!tr |
AVG | Win32:Evo-gen [Trj] |
DeepInstinct | MALICIOUS |
alibabacloud | PWS:Win/Multiverze.Gen |
IRMA | Signature |
---|---|
Trend Micro SProtect (Linux) | Clean |
Avast Core Security (Linux) | Win32:Evo-gen [Trj] |
C4S ClamAV (Linux) | Win.Packed.Zusy-10040002-0 |
Trellix (Linux) | Clean |
Sophos Anti-Virus (Linux) | Mal/Generic-S |
Bitdefender Antivirus (Linux) | Gen:Variant.Zusy.568294 |
G Data Antivirus (Windows) | Virus: Gen:Variant.Zusy.568294 (Engine A) |
WithSecure (Linux) | Trojan.TR/Crypt.TPM.Gen |
ESET Security (Windows) | a variant of Win32/Packed.Themida.HZB trojan |
DrWeb Antivirus (Linux) | Trojan.PWS.Amadey.227 |
ClamAV (Linux) | Win.Packed.Zusy-10040002-0 |
eScan Antivirus (Linux) | Gen:Variant.Zusy.568294(DB) |
Kaspersky Standard (Windows) | HEUR:Trojan-Spy.MSIL.Generic |
Emsisoft Commandline Scanner (Windows) | Gen:Variant.Zusy.568294 (B) |