Static | ZeroBOX

PE Compile Time

2075-07-06 11:33:51

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003f0c4 0x0003f200 7.9874748114
.rsrc 0x00042000 0x00004778 0x00004800 2.30601307826
.reloc 0x00048000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00042100 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00046138 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004615c 0x0000041a LANG_NEUTRAL SUBLANG_NEUTRAL ARC archive data, squeezed
RT_MANIFEST 0x00046588 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
b%,RE/
*^S~[<
fT`FoL
G1va?T
URUG=L
n,~(~'
|Ww%\
V_`Cr{f
UQUeRU}
u9TqR)
N}]T])
*VS^Ut
{s74>3
P7P_PD
99y~B9
@DT@hD
;9%/;(3
",Osvl3
1e:OUy
^uv?)y9
~pt\hl
eDu.On
T\bNIr@iR
:AD"""
Ts}cA<
ER}$hQ
2l#{zG
s9rd7!+
)maw(f
]|$ul"wGQ<
kb\co:
Lt|[WV
VCon-T
}=${Is
9se(wR
c%79E~
XCI="{b
hox_jk
K0>08`
DZ50_j
v[_;+o
|W;?~~
n6$hXh
!N!^!n)|
n`L`T`|@O*`
L=<B}_
T"YcC/
?b2Dwu|>
:H[:HZ
Y%I@Y!
H`fH9(
E=Y'IC$
@/IK%&
?Z!"PT
rA_Y'IMD
d-%;rAS2:
ATdDJ?
d|J:$j
n67pJV$:
%3rA'7
Qw$ip:o
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
hvZ%aCN
t%Q,vU
pECBWR
SmCwm?
0z c]b
}3q'.q
At qfJ
,-%9&C
2V`oBQ
)_;vm6}
~s8W(m
`[;XgF
'oQxcz
baFfji
qJI})E
?:hX`m
mmHb>(
AH}[TOX
^jcqD,
nARWBO
n*IS8)
#\m%<G
LHYvh*
MMml0S;
53J`<.&
qyJG=O
fOZ0}ft?k
,8( .9I
LZW!cG+
wf<$\I
Z,:cE{
7BpfO;
kK%\?w
eo9RyI
^:% Xq
Z?ML/pG
:{gc3B
qR,bGJ
6*6E1=u
Y=B}>?
S+{0n]
Z,|fO]=
9D*g4"
a&oI7`
h4\4<n
wc3le,
b)`3LG;\*
uWWWWWUWU
,i>H2;
r_n0eGZ
)7-<j/
}t_{[,c
lc[1X~
HpE4`
rSF#klv!w
8{C0|4
JyOiiy
dg'oOT
A^a@XG
m2Nt<GB
ZNk<k-A;
wr@^cd
BJ_at#
%46<i
Ux8r*%
*SN\k3
.bs5yx
s/htt*
Q"vnA3~
,gfz"N
5ubSHP\-
0awn8%
}4}#ii
q|*r^B
&H'6n+W
;Y,pJI
]C~>ft
1JZEp>h
'0=Q!,
"_E:EL
zw.C>VR
iyLmz;
i_Od=u
PHRvCHnmd
b1c)f$<
T:iH$Z
-PCHc@
C6S)G?
w^2I;/)y
l_JJ(c
J-\?u1v
C>CQ>F
jh0[XN
~vq:Vi8~t
LJo>$N
JoJ*@{
W=E\?Nc@
*"<?m
@+)XFML
x<%~^+s
3 y_@o
x\[YZ 8
)b','o/1
h=_F0Oh
EGB0H'
%tQzS!)B
S 6g#~
Iyy'[~/
yhLzvX
]bv'.1Ga5
&_%aV5
Me5(YV
`%c2t*
#3$I&B5
=[7p)39
`vCST
[yzaNq
|%y2'D,
fKgk:a
=vuQgkfm
5RW{hFl
A+ttZ&
uie<~p
nnJY~
w47Sjh#6
6^S+p
0ab2fc4`1
trr07tv
:n ]Oz
"18g;
fSaE.u
!Wn]1G\N
'_p:Vu
z>n<)2C}H
S@N#&G~lf
(O^%:B
vDwfU,
9`BDLo
w>s^2k?nj
.Hoxxh
qrH/Fs
/\J6N4
n]weS!
 Ko7c
Mo=/7~
:{7vgq
yr\{\<
D!w"#P
>=-<8
sS{FcQg
|jz M[k+(S
K#)::S
3FE=Ls
K!Se2|E
O+vt;"
.zWBx\h:
um7k>N
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
T|pv{Q
Hnx>l<
\e,p3&2
=CK+>9C[
x}2R|4
[,O>_:
[<ngKu
,}~.dP
[1^8<6u
+RKcmz
9*Zf)l
4:-,eg
,x11mq
nSBYKZ
,wx>!b'4h"
1Xn8E
)eykpAv1
3k>9K&
exay(~
[cISm(
nqqF"J'
EQ`+CI
qvR2_i,
OZlA'<
,0d7i<
BYRh>8
J4X"Xx
qL($"$x
df2I&8`P
E?#i$w
ZI'!-D
>I/qZ{
AAz79aP
s$WR!P
j#-H?%
OyO7!4
f94WR&
.V;Wxrg
%5s:*i
jw^bi6
9H9*K`
*K 5Kj
uIb@i
joQB{o
yIo$X>?
JsL-Xb
LA_}7;
O:<^x2
Bdzc(6jd^1T
5"/2mAMQ4
d8cq8XS
ciCU02
,&KH3i
l"%Ary
h%YTIb
+IS%Y\I
t2~QS0
b4-T_-
pKV>"]
egpqP9`C
'<)PC:
&j#LzX#
98-M0_O
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
IEnumerable`1
WindowsFormsApp1
set_Bytes1
Dictionary`2
set_Bytes2
<Module>
System.IO
Costura
DownloadData
mscorlib
System.Collections.Generic
Thread
isAttached
Interlocked
get_Elapsed
costura.costura.dll.compressed
costura.classlibrary.dll.compressed
Synchronized
defaultInstance
source
CompressionMode
Exchange
nullCache
Enumerable
IDisposable
Double
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
fullName
GetName
requestedAssemblyName
DateTime
ReadLine
WriteLine
System.Core
get_Culture
set_Culture
resourceCulture
culture
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
add_AssemblyResolve
Zeqenylvg.exe
System.Threading
System.Runtime.Versioning
CultureToString
get_Xuymbiwygaxwng
Zeqenylvg
Attach
Stopwatch
get_Felqcpznlvirh
get_Length
EndsWith
nullCacheLock
Serial
System.ComponentModel
ReadStream
LoadStream
GetManifestResourceStream
DeflateStream
MemoryStream
stream
Program
set_Item
System
resourceMan
TimeSpan
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
destination
System.Configuration
System.Globalization
System.Reflection
set_Position
StringComparison
CopyTo
get_CultureInfo
ConsoleKeyInfo
System.Linq
AssemblyLoader
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
.cctor
Monitor
System.Diagnostics
get_TotalSeconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
ReadFromEmbeddedResources
WindowsFormsApp1.Properties.Resources.resources
DebuggingModes
GetAssemblies
WindowsFormsApp1.Properties
resourceNames
symbolNames
assemblyNames
get_Flags
AssemblyNameFlags
Settings
ResolveEventArgs
get_Ticks
Equals
Concat
GetObject
System.Net
get_Default
ToLowerInvariant
WebClient
get_Now
ProcessedByFody
ReadKey
ContainsKey
get_Assembly
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
ClassLibrary
op_Equality
op_Inequality
IsNullOrEmpty
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$debfe631-4550-49f4-85a9-47eb523fa6c2
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Felqcpznlvirh
Xuymbiwygaxwng
Downloading file....
http://dl.google.com/googletalk/googletalk-setup.exe?t=
Download duration: {0}
File size: {0}
Speed: {0} bps
Press any key to continue...
https://www.yoursite.com
bytes / S
WindowsFormsApp1.Properties.Resources
Xuymbiwygaxwng
Felqcpznlvirh
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Zeqenylvg.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Zeqenylvg.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!D20D0D39B52C
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.119d41
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34678.qm0@aSTdgid
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Miner.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet Clean
MaxSecure Trojan.Malware.300983.susgen
AVG Win32:MalwareX-gen [Trj]
Paloalto Clean
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 Clean
No IRMA results available.