VirSCAN VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.
4, If your browser cannot upload files, please download VirSCAN uploader to upload.

Language
Server load
Server Load
VirSCAN
VirSCAN

1, You can UPLOAD any files, but there is 20Mb limit per file.
2, VirSCAN supports Rar/Zip decompression, but it must be less than 20 files.
3, Aplikace VirSCAN může skenovat komprimované soubory s heslem 'infected'nebo'virus'.

00晴雅集    Threatbook file behavior analysis report

Basic Information

file name: 00晴雅集
file type: EXEx86
Threat level: suspicious
MD5: 5afe62cb993a235809986f95fe516105
sha256: b071357ab8f96b5bed1fe5af3f302001d96ad9165a33322b1c36e10420a1986c

Document Threat Intelligence IOC Report

No intelligence IOC detected

Intelligence decision system

Undetected intelligence determination system

Network behavior report

domains: 0

Document release report

File release report not detected

File process number report

nofind

Document behavior signature report

No file behavior report detected

Static information

Section name: .text
Virtual address: 0x00001000
Physical address: 0x00000400
Physical size: 0x00037200
Section permissions: R-E
Section name: .rdata
Virtual address: 0x00039000
Physical address: 0x00037600
Physical size: 0x0000e800
Section permissions: R--
Section name: .data
Virtual address: 0x00048000
Physical address: 0x00045e00
Physical size: 0x00002800
Section permissions: RW-
Section name: .rsrc
Virtual address: 0x0004f000
Physical address: 0x00048600
Physical size: 0x00045200
Section permissions: R--
import_hash: 4e0725ea9736e576b35d614e08e6ad58
time_stamp: 2020-01-15 23:31:13
entry_point_section: .text
image_base: 0x400000
entry_point: 0x1d20f
name: QTHFF
language: LANG_ENGLISH
filetype: ASCII text, with very long lines, with no line terminators
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0004fbec
size: 0x00040430
name: RT_CURSOR
language: LANG_ENGLISH
filetype: Hitachi SH big-endian COFF object file, not stripped, 0 section, symbol offset=0x20000000, 1073741824 symbols, optional header size 256
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009001c
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090150
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090284
size: 0x000000b4
name: RT_CURSOR
language: LANG_ENGLISH
filetype: AmigaOS bitmap font
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090338
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009046c
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000905a0
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000906d4
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090808
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009093c
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090a70
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090ba4
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090cd8
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090e0c
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: AmigaOS bitmap font
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00090f40
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00091074
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000911a8
size: 0x00000134
name: RT_CURSOR
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000912dc
size: 0x00000134
name: RT_BITMAP
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00091410
size: 0x000000b8
name: RT_BITMAP
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000914c8
size: 0x00000144
name: RT_ICON
language: LANG_ENGLISH
filetype: GLS_BINARY_LSB_FIRST
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009160c
size: 0x00000568
name: RT_DIALOG
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00091b74
size: 0x0000030c
name: RT_DIALOG
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00091e80
size: 0x000003f0
name: RT_DIALOG
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092270
size: 0x000000e8
name: RT_DIALOG
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092358
size: 0x00000034
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009238c
size: 0x00000050
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000923dc
size: 0x00000082
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092460
size: 0x0000002a
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009248c
size: 0x00000184
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092610
size: 0x000004e6
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092af8
size: 0x00000264
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00092d5c
size: 0x000002da
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093038
size: 0x0000008a
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000930c4
size: 0x000000ac
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093170
size: 0x000000de
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093250
size: 0x000004a8
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000936f8
size: 0x00000228
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093920
size: 0x0000002c
name: RT_STRING
language: LANG_ENGLISH
filetype: data
sublanguage: SUBLANG_ENGLISH_US
offset: 0x0009394c
size: 0x00000042
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093990
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x2
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000939a4
size: 0x00000022
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000939c8
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000939dc
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x000939f0
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a04
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a18
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a2c
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a40
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a54
size: 0x00000014
name: RT_GROUP_CURSOR
language: LANG_ENGLISH
filetype: Lotus unknown worksheet or configuration, revision 0x1
sublanguage: SUBLANG_ENGLISH_US
offset: 0x00093a68
size: 0x00000014