VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load
VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

00鬼作秀    Threatbook file behavior analysis report

Basic Information

file name: 00鬼作秀
file type: EXEx86
Threat level: malicious
MD5: 25254f0034660028af7b1f18a2588dcb
sha256: 0180f184118e98f2bcd3eb6aacb973d3fbdd585e59c1b143ce725df2db439891

Document Threat Intelligence IOC Report

No intelligence IOC detected

Intelligence decision system

Undetected intelligence determination system

Network behavior report

domains: 0

Document release report

File release report not detected

File process number report

nofind

Document behavior signature report

No file behavior report detected

Static information

Section name: CODE
Virtual address: 0x00001000
Physical address: 0x00000400
Physical size: 0x00007400
Section permissions: R-E
Section name: DATA
Virtual address: 0x00009000
Physical address: 0x00007800
Physical size: 0x00000400
Section permissions: RW-
Section name: BSS
Virtual address: 0x0000a000
Physical address: 0x00007c00
Physical size: 0x00000000
Section permissions: RW-
Section name: .idata
Virtual address: 0x00015000
Physical address: 0x00007c00
Physical size: 0x00000a00
Section permissions: RW-
Section name: .tls
Virtual address: 0x00016000
Physical address: 0x00008600
Physical size: 0x00000000
Section permissions: RW-
Section name: .rdata
Virtual address: 0x00017000
Physical address: 0x00008600
Physical size: 0x00000200
Section permissions: R--
Section name: .reloc
Virtual address: 0x00018000
Physical address: 0x00008800
Physical size: 0x00000600
Section permissions: R--
Section name: .rsrc
Virtual address: 0x00019000
Physical address: 0x00008e00
Physical size: 0x00001400
Section permissions: R--
import_hash: 9f4693fc0c511135129493f2161d1e86
time_stamp: 1992-06-20 06:22:17
entry_point_section: CODE
image_base: 0x400000
entry_point: 0x80e4
name: RT_ICON
language: LANG_RUSSIAN
filetype: data
sublanguage: SUBLANG_RUSSIAN
offset: 0x00019150
size: 0x000010a8
name: RT_RCDATA
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x0001a1f8
size: 0x00000010
name: RT_RCDATA
language: LANG_NEUTRAL
filetype: data
sublanguage: SUBLANG_NEUTRAL
offset: 0x0001a208
size: 0x000000ac
name: RT_GROUP_ICON
language: LANG_RUSSIAN
filetype: data
sublanguage: SUBLANG_RUSSIAN
offset: 0x0001a2b4
size: 0x00000014