VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load
VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

00霍去病    Threatbook file behavior analysis report

Basic Information

file name: 00霍去病
file type: EXEx86
Threat level: malicious
MD5: 3930edb9e2badf80062a7574d0655f99
sha256: 3237900e6dc76edc95e891619fb404ea036fe680bc14348f9dfb192c3bde52eb

Document Threat Intelligence IOC Report

No intelligence IOC detected

Intelligence decision system

Undetected intelligence determination system

Network behavior report

domains: 0

Document release report

File release report not detected

File process number report

nofind

Document behavior signature report

Low risk behavior 0
Low risk behavior
Reverse Engineering: {"en": "The binary likely contains encrypted or compressed data indicative of a packer", "cn": "这个二进制可能包含被加密或被压缩的数据,可能被加壳"}
High risk behavior 0

Static information

Section name: .text
Virtual address: 0x00001000
Physical address: 0x00000400
Physical size: 0x00002600
Section permissions: R-E
Section name: .rdata
Virtual address: 0x00004000
Physical address: 0x00002a00
Physical size: 0x00000600
Section permissions: R--
Section name: .data
Virtual address: 0x00005000
Physical address: 0x00003000
Physical size: 0x00000e00
Section permissions: RW-
import_hash: b1849d2465169bfbbe428cc3d8379f06
time_stamp: 2008-01-24 04:15:55
entry_point_section: .text
image_base: 0xa30000
entry_point: 0x1d40
PE resource information 0