2023-12-05 22:05:38
C:\b\s\w\ir\cache\builder\src\out\Release_x64\elevation_service.exe.pdb
d1ac62e21fbb2bfb4c997143c61f8b53
| Name | Virtual Address | Virtual Size | Size of Raw Data | Entropy |
|---|---|---|---|---|
| .text | 0x00001000 | 0x00158046 | 0x00158200 | 6.54821796246 |
| .rdata | 0x0015a000 | 0x00035448 | 0x00035600 | 5.69597431193 |
| .data | 0x00190000 | 0x0001b764 | 0x0000f800 | 1.4750278566 |
| .pdata | 0x001ac000 | 0x0000af50 | 0x0000b000 | 6.01749427142 |
| .00cfg | 0x001b7000 | 0x00000030 | 0x00000200 | 0.433980398467 |
| .gxfg | 0x001b8000 | 0x00002b80 | 0x00002c00 | 5.20055584159 |
| .retplne | 0x001bb000 | 0x0000009c | 0x00000200 | 1.18895836846 |
| .tls | 0x001bc000 | 0x00000201 | 0x00000400 | 0.20528878451 |
| _RDATA | 0x001bd000 | 0x0000015c | 0x00000200 | 3.24599466671 |
| .rsrc | 0x001be000 | 0x00001710 | 0x00001800 | 4.4656106006 |
| .reloc | 0x001c0000 | 0x00090000 | 0x0008f000 | 7.9438971878 |
| Name | Offset | Size | Language | Sub-language | File type |
|---|---|---|---|---|---|
| TYPELIB | 0x001be100 | 0x00000db4 | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_VERSION | 0x001beeb8 | 0x0000047c | LANG_ENGLISH | SUBLANG_ENGLISH_US | data |
| RT_MANIFEST | 0x001bf338 | 0x000003d2 | LANG_ENGLISH | SUBLANG_ENGLISH_US | XML 1.0 document, ASCII text, with very long lines (864) |
| Ordinal | Address | Name |
|---|---|---|
| 1 | 0x14003a730 | GetHandleVerifier |
| Antivirus | Signature |
|---|---|
| Bkav | W64.AIDetectMalware |
| Lionic | Virus.Win32.Expiro.n!c |
| tehtris | Clean |
| ClamAV | Clean |
| CMC | Clean |
| CAT-QuickHeal | W32.Expiro.R3 |
| Skyhigh | BehavesLike.Win64.Expiro.vc |
| ALYac | Win64.Expiro.Gen.7 |
| Cylance | unsafe |
| Zillya | Clean |
| Sangfor | Trojan.Win32.Save.a |
| K7AntiVirus | Virus ( 005a9e7d1 ) |
| Alibaba | Virus:Win64/Expiro.a3048946 |
| K7GW | Virus ( 005a9e7d1 ) |
| Cybereason | malicious.d8acd4 |
| Baidu | Clean |
| VirIT | Clean |
| Paloalto | Clean |
| Symantec | W64.Xpiro.J!dam |
| Elastic | malicious (high confidence) |
| ESET-NOD32 | a variant of Win64/Expiro.DP |
| APEX | Malicious |
| Avast | Win64:Expiro-AJ [Inf] |
| Cynet | Malicious (score: 100) |
| Kaspersky | Virus.Win64.Moiva.a |
| BitDefender | Win64.Expiro.Gen.7 |
| NANO-Antivirus | Clean |
| ViRobot | Clean |
| MicroWorld-eScan | Win64.Expiro.Gen.7 |
| Tencent | Virus.Win64.VirMoiva.a |
| Sophos | W64/Moiva-B |
| F-Secure | Malware.W32/Infector.Gen |
| DrWeb | Win32.Expiro.158 |
| VIPRE | Win64.Expiro.Gen.7 |
| TrendMicro | Virus.Win64.EXPIRO.SMAJC |
| Emsisoft | Win64.Expiro.Gen.7 (B) |
| SentinelOne | Static AI - Malicious PE |
| GData | Win64.Expiro.Gen.7 |
| Jiangmin | Clean |
| Webroot | Clean |
| Varist | W64/Expiro.AR.gen!Eldorado |
| Avira | W32/Infector.Gen |
| Antiy-AVL | Virus/Win32.Expiro.x |
| Kingsoft | Win32.Infected.AutoInfector.a |
| Gridinsoft | Trojan.Heur!.03050023 |
| Xcitium | Clean |
| Arcabit | Win64.Expiro.Gen.7 |
| SUPERAntiSpyware | Clean |
| ZoneAlarm | Virus.Win64.Moiva.a |
| Microsoft | Virus:Win64/Expiro.DA!MTB |
| Detected | |
| AhnLab-V3 | Virus/Win.Expiro.X2155 |
| Acronis | Clean |
| McAfee | Clean |
| TACHYON | Virus/W64.Movia |
| VBA32 | Clean |
| Malwarebytes | Virus.M0yv |
| Panda | W64/Moyv.A |
| Zoner | Clean |
| TrendMicro-HouseCall | Clean |
| Rising | Virus.Expiro!1.A140 (CLASSIC) |
| Yandex | Clean |
| Ikarus | Virus.Win64.Expiro |
| MaxSecure | Trojan.Malware.121218.susgen |
| Fortinet | W64/Expiro.CU |
| BitDefenderTheta | Clean |
| AVG | Win64:Expiro-AJ [Inf] |
| DeepInstinct | MALICIOUS |
| CrowdStrike | win/malicious_confidence_100% (W) |
| IRMA | Signature |
|---|---|
| Trend Micro SProtect (Linux) | Virus.Win64.EXPIRO.SMAJC |
| Avast Core Security (Linux) | Win64:Expiro-AJ [Inf] |
| C4S ClamAV (Linux) | C4S.MALWARE.SHA256.AUTOGEN.64078016.UNOFFICIAL |
| Trellix (Linux) | Clean |
| Sophos Anti-Virus (Linux) | W64/Moiva-B |
| Bitdefender Antivirus (Linux) | Win64.Expiro.Gen.7 |
| G Data Antivirus (Windows) | Virus: Win64.Expiro.Gen.7 (Engine A) |
| WithSecure (Linux) | Malware.W32/Infector.Gen |
| ESET Security (Windows) | a variant of Win64/Expiro.DP virus |
| DrWeb Antivirus (Linux) | Win32.Expiro.153 |
| ClamAV (Linux) | Win.Virus.Expiro-10035210-0 |
| eScan Antivirus (Linux) | Win64.Expiro.Gen.7(DB) |
| Kaspersky Standard (Windows) | Virus.Win64.Moiva.a |
| Emsisoft Commandline Scanner (Windows) | Win64.Expiro.Gen.7 (B) |