Static | ZeroBOX

PE Compile Time

2083-08-20 14:01:20

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003bb74 0x0003bc00 7.98677942093
.rsrc 0x0003e000 0x000046b8 0x00004800 2.26732868773
.reloc 0x00044000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003e130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00042158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004216c 0x0000035e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000424cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Hyjgyn
Hyjgyn.exe
<Module>
VisitorMapping
WindowsFormsApp1.Maps
Object
System
mscorlib
Resources
WindowsFormsApp1.Properties
Settings
ApplicationSettingsBase
System.Configuration
AssemblyLoader
Costura
InvocationCollectionTask
Hyjgyn.Tasks
.cctor
SelectProccesor
Stopwatch
System.Diagnostics
Double
Boolean
WebClient
System.Net
DateTime
TimeSpan
Thread
System.Threading
ClassLibrary
set_Bytes1
Console
WriteLine
String
set_Bytes2
Serial
get_Now
get_Ticks
ToString
Concat
DownloadData
IDisposable
Dispose
get_Elapsed
get_TotalSeconds
ReadLine
UpdateProccesor
Enumerable
System.Linq
System.Core
IEnumerable`1
System.Collections.Generic
ReadKey
ConsoleKeyInfo
proccesor
ResourceManager
System.Resources
_Container
CultureInfo
System.Globalization
get_ResourceManager
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
System.Reflection
get_Culture
set_Culture
get_Kfcwqcvvz
GetObject
get_Bzqkhe
Culture
Kfcwqcvvz
Bzqkhe
defaultInstance
get_Default
SettingsBase
Synchronized
Default
nullCacheLock
nullCache
Dictionary`2
assemblyNames
symbolNames
isAttached
CultureToString
culture
get_Name
ReadExistingAssembly
AssemblyName
AppDomain
get_CurrentDomain
GetAssemblies
GetName
Equals
StringComparison
get_CultureInfo
CopyTo
Stream
System.IO
source
destination
LoadStream
fullName
DeflateStream
System.IO.Compression
MemoryStream
GetExecutingAssembly
EndsWith
GetManifestResourceStream
CompressionMode
set_Position
resourceNames
TryGetValue
ReadStream
stream
get_Length
ReadFromEmbeddedResources
requestedAssemblyName
ToLowerInvariant
IsNullOrEmpty
ResolveAssembly
sender
ResolveEventArgs
Monitor
ContainsKey
op_Inequality
op_Equality
set_Item
get_Flags
AssemblyNameFlags
Attach
Interlocked
Exchange
ResolveEventHandler
IntPtr
add_AssemblyResolve
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
WindowsFormsApp1.Properties.Resources.resources
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
WrapNonExceptionThrows
FileZilla FTP Client
Tim Kosse
FileZilla
$31b65928-d44d-4a7b-8348-33f127ee3a7c
3.48.1.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
,qfSjG
?_Q/+U
(8B?3'
U$fl|<
Hvf?S
Bs>6]i
c=c0q,!<
H^)wxma*#
6!tNW\;*
XB*]Ig_j
R&!{i^
j"@rb
zwVBA1
dVFUMa5xo
X%-W}
^r{oO`,
jJg+D}A!
uzGo|6]47
fD+dRd.
zNnJVv^vE
F9g0jS.1
y[!TagL3|
Ctcz7~
h]@nn
i-zo>c[Iu
G&SMXr
s{[;}J
WuEMM>
hY-b]:n
u]!k6P
ed)kXmYL
E>{&+!
ok<hI=}
]D-WB/8
&Y,b`
_.-cU%
}&;R*[
4'h'J;
/!CZR-uHY
-tFortM
?D-WB-
;@<_@=6
W4*2},d
Lc|&;
q@HhHQ
j("("(
aLMAMfV
8dTEuh
BZ`lXXiJW
UUrPTl+*
>WR^Y2
+=73&=3=+/>)
OS3jR3R
N*WE%S
SSRbb\\a
<:^RRH
9x<u65^#
zlZ\|l
J[MWHO
2667364w
b&vn.N
rfOOwO
-3SYMC{
>6+./5-;.}z
ANig;Y'
JRAjfzT
DX`Wh$;
3-&'$~[=
;FFTK^
m)!!uR
$8ytU$U
SSCwC~
UAa}tJiz
Z_;(*N
&zfZvfz#'k
rZVQ2?
62zR:7
7WR03=2
^'zqQ^C#V.~q
;7Z*+'
Z:bcZ
hGz__WO_
z6;W:)]
n||x`zjo{?
xPWZ<3
-59:(s
`vfd`z
][NF6!<
Wl4<(28
N:V*U*f*z%VP
&:6}9Hn
;a(=:A
;a|EK,
@$+2^"
"X_b)V
;IL!E7U
@eE\eaL
24Jn,hy
23isa
C<n+`H
5B,fM$
WJT'Dc(
-m9-m(
ZNEZJ/
H%l.I[
AHrAHQ
~6r~6X
h/"9/"(
8VB&)K
tIGD<V8e
+xl5PEu~
Le'3*+
P<4A[<
Ew,F?V
0DyiE,
tMoI[`
eI]%.k
2-A|{x
XC\C?3F
\PN$KR8Mg
Z-8"3Pc[au
$y.<Ggx
Ats9Ev
S$xBuqB
Pw, 2h
#UE%xu
~QUOdn3
)50KDh
Hx.C!e
jBu{^9w
zr$-Fb
]b(u: 2
_jG*jF
iCb=Kw
JoXyKO
|2 {cNw
]*5iM3
G[P3%!
pYReT'E
y Q+G%[wE
Y/]n7N+
^YQ6$_^}
cq62jVg
!7h0Ju
%:P>s\
^pT?(H Nx
%7DRA[
WM%.@5a$
wnV4"=
CjH99P
48s%Xb
P!qJPx
n f`5j
}cGfrM
7x/?|@
R/L77*
7|z6[H
OP`;a
MgfSm1
}G5SZm
Vjn}Sc
TSVUEuQ
:US@+6{q
v6bu8~
1c\P$c
XxY~[\]
Kt{#dE
#!*~XY
)&UIm,
=#y=N
UH>seT
#;RLj<
`F2`@d
ZBou{4
xuy4ZK
+X^)P^
YVZ|28
/@3ka5
${EE.G
z6\)#`3
;'PZ43w6
&=^6Sp
jHle;^14
Rp[Bcy
-qQHVd
2QmOsb
&&Bl^Tx
vKV+2m
^PZBY/
W}5R;D
IceOj1Y
6[ui r
h 9U_@
~6]p>Y
k[|yUP
gfZ/lo
_$?.#
EJFb~.
~Yw+ML
%&jc4
;P}3s+\
V..[4B
DY(%|=
x}1=Pd`
8i}oH<0.
8U.gg}++.h
_Hoh0Yev
WW*Qjw
DbDO?x
mRGg?g
|po9Z}_
RQY|&o
|d1Z~[
<M;^%u
%fb9x0?
Gi~L.1L
RB2%&3
zJ|CSs
>S8Z3l
r_)88&
1ETKXT
U*_2\&4
AD*V^[
9z:?YB
r:[05
5G{38{
%3>.3L3R6
EN|^#g
D=,nBx
BTgDpO3
aNcz]>
xep+&^9
{uL>4"R
kM=<m[U
`wopLa
RV?*v\k
3C|&s/S6U
\JDzmq
Vg6_S~
s2EsN5
Hss7quZ
&3vZgfj
(|fg`
ei00Re
UZcgMH
wi$i\EJ
H-+=[o,Q
uZfoEe
Q}?S;f7
z8}?L4j
m@e/"z
-+]LN!
2Q}gS
Ky:)m.
k[zW X
f*_GyRT
U-ZulVO
Dq]#B?b1
")}BOv
R_C*[+
e:#5$)
phX,s
J`t3 Gh
wa-$.E%_s%8
,NXhZA
li5sbO
e>9@|O
!KYwM6n;!7
R6x6@_
RV|&.b?d
CjSf^6;
>o$*5;
JJD#>`L
de%uiH
Tm{%}<+
ig_oRZ
JW%NSw
tTdb.D
MQ#h,5
(A>>CN2
6f(Ra3P
#L_PTY
yi:/q:.
XTxjxAc
R}Zl?:
:9|XaQ
=sc^<Qy
cja-G-j
d`pc[;
->hfd\D
3*,68,~Pbb|dpRbX
n@P}2
,m5n6&h
fHR||X\
I^8Tyna!
1@w'C0
2J!#O{S<7
nn_:DU3
.v</>$
0!:yn[
hkiJE_
fu)}HN
u^t1S?9
q#LxY7W
L;r&uy@s
->00rvL
aNIDP
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
F%QST#JBH"K$J#
i/6>Zp8
w-u0*X
E6+rVH
<<}zEh
m3>$e[
R'h\~r8-Oj
SVSq}N
4m*YvXU
i9g]8L
j;W<:n`j
O09{</
vUS28
}lO9>Zd
gE#|<[
X,;N?]^gQ
y8,9KM~
ivDRrN
d~RQ^VKV
@o|3`$
Wo$nO*FG=
g`gNf@
dAi%+(
TsRGsA-V
rG8I`<
g'iiEi
"F}am4
FQ9oNEp
V2+U&w
hftVzX
`m,gD}
R0l`UL
{_Qo/a
]?}iOu
yo>YnW
)8;xapQ
[!%|U8
2e!tt1v
PZQ.EY
TBtwfFG
-y_GJ
n07U_q
xFI%V
xvlC[f
vR`E,r
vqxm6[,
$bP.G/w
z/U\aMi
4j)*+T,
k*"G$9
{5B5fq3Q
42cCEC
4jlyFM
"O$v76
A`Coh$4
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Downloading file....
http://dl.google.com/googletalk/googletalk-setup.exe?t=
Download duration: {0}
File size: {0}
Speed: {0} bps
Press any key to continue...
https://www.yoursite.com
bytes / S
WindowsFormsApp1.Properties.Resources
Kfcwqcvvz
Bzqkhe
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
Bzqkhe
Kfcwqcvvz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FileZilla FTP Client
CompanyName
Tim Kosse
FileDescription
FileZilla FTP Client
FileVersion
3.48.1.0
InternalName
Hyjgyn.exe
LegalCopyright
Tim Kosse
LegalTrademarks
OriginalFilename
Hyjgyn.exe
ProductName
FileZilla
ProductVersion
3.48.1.0
Assembly Version
3.48.1.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!1CEAE4D45ED0
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
FireEye Generic.mg.1ceae4d45ed09a9e
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.34678.qm0@aGJHI6o
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet Clean
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.