Static | ZeroBOX

PE Compile Time

2100-06-03 23:43:36

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003b2a4 0x0003b400 7.98634665984
.rsrc 0x0003e000 0x00004770 0x00004800 2.30594785103
.reloc 0x00044000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003e100 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00042138 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004215c 0x00000412 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00042580 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
JL)/R6
{(vRo_
?"?"R4Cl
YzNzY4
'+_+vS>P>R^V)_)4
6?QX(g
iokOi;R
kJU!Z[zH
. \Y|V8
@S@3@s@
n?(n~~
FhxVi|
qjP^\BLa`O
LH-201
;*Xn%Qq
D@d0FBC
rz~F\C
O:}l2`R
JP^BT`
EAM""(
***(J1$
/3KdIZ}eV{
Zme?6;<`
-%wJf'
]dXyY
m[0omU
0Md\kY
u0<W;(
}B%Z5,
hw/<Op
hox_jk
K0>08`
DZ50_j
v[_;+o
|W;?~~
n6$hXh
!N!^!n)|
n`L`T`|@O*`
L=<B}_
T"YcC/
?b2Dwu|>
:H[:HZ
Y%I@Y!
H`fH9(
E=Y'IC$
@/IK%&
?Z!"PT
rA_Y'IMD
d-%;rAS2:
ATdDJ?
d|J:$j
n67pJV$:
%3rA'7
Qw$ip:o
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
iW*nEQ<
6:HO3c
,UfUH|
`*WY]&
WT"WkjIr
~C2]Jp
Ry/"~n
i|$%9M
7>G+RkgG
W:-i6c
KP!oD!
O0!!E#
VN"5nc}9
:4OX-ec
BGS'/oXoQP?0
sdDC!"lC
TO-PM1
qnel,
AyCH(Zc.f
lv*F6{)R
'6t]PR
"<]izD
#'&e%]
1['>T+3
a8kbv=^
X+(a!y
8;$jaN_
6jmbZd
Gu D:X
M!u(In
OF(|a%,
7IWq,r(
,F\lu`v
wE7|~I
&akxa[3
xS*7{gy
SfysWXC
@t*vga
X1'.mZ
q<&gTe
~%w^l'
KNI{_{
ya\fZg
u}NJ>\
jfXr`:z
\N_gJc
S}Q}t
"}Hzd-
x8Z:w:
h*m))
v)u8J]!5
5]|#_9
(R>4hx
xpt=rUt}
n(9rPm
|f%B!B
yY^o72
Z90pN|/
p~)^4sIsFO
x3i|&RJ
t]^&kS<.
E#CS"C
+"<iT
x-7]y}j
xk6j=V
,%rn?!
Cz18c<;
h~(VR8'G}
jz!Z>(
2X3;1${
xI%'b2f
kV?S&l
G`0nOeC}
zr@Pl.
W+,]._n
kPc3m
Org${u
7Ht#K/b
,`!WG!
3X4`|T
|tHm>E
7pQ>p@
wwvvvvwvvf
/)^LLE
r"/IT"
Y&3|Eq
N"\A@!hNn
&:50do
lSey`O
?9dyT_p
7_1`JM
-`u7Eh
uq`"4'4
W_:mtm
!nY,Km
yy$DO+)8
3G_'E;
;[uVyg
`0z8A
wqp]av7
>'5m:g
/?OUSW
@\=Z@afu
p1db.0
V_`n`j
/O?^?wOg
hbd,$*
"~pEVo
{MI4gt
m:7Ko*
^FpmJx
[K.Hn;
_'l8j+
i+3+f
j+s%nl+
g)ou/zs
_x`V{d
C!E2j;<U
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
KlnWGDXMIP
:n*u8z~
]MNy>}
om^iUY
mx%`_R
33'/eF
-Lz5{j}
LyxBM^e
C]^l2.
/Uo9vwS
$;8thi
S*U/G'
]P}~j[
/*=\S_r
O3N.$r
[Vx~;De
$&UDrv
t`i1"1O
<e bxz
:Em+e
@f`5Q"
.Pdw5a#
Y'PoJB
d4i'P,
%P_Q&Y#
Q'Df<Y#r
H_p:)K4p
"G0A S
]HQu8^
znD<5"J
SoD%?pva
3$;c|
g{<v9s
"xrDDL
SGDU<Y"r
$D&S9rG
TD9<MCd
mDE<%s:_~-
>#"VsT
)QELY>
P:/pe9Q
%X~PYG5
:5A '*
: P,QJ
(M\/rF
<=gi5-5
!l;oXi#
L<yU+Kc
HmG4:?t
4z~(p"
;S_I}#
#- -"-!
z>&NzE^
UVJ0C
vu[u%T
&f0e=X
]kVuu6pJ:
YVc+B@I
*wD.$]s
?aX}yKFIU
]"!/3P
gZ'y,8
_S05YE
:4sw|@
]KM9g-9Y
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
IEnumerable`1
WindowsFormsApp1
set_Bytes1
Dictionary`2
set_Bytes2
<Module>
System.IO
Costura
DownloadData
mscorlib
System.Collections.Generic
Thread
isAttached
Interlocked
get_Elapsed
costura.costura.dll.compressed
costura.classlibrary.dll.compressed
Synchronized
defaultInstance
source
CompressionMode
Exchange
nullCache
get_Jmalmpwqyeuke
Enumerable
IDisposable
Double
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
fullName
GetName
requestedAssemblyName
DateTime
ReadLine
WriteLine
System.Core
get_Culture
set_Culture
resourceCulture
culture
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
add_AssemblyResolve
Zzsvkpq.exe
System.Threading
System.Runtime.Versioning
CultureToString
Attach
Stopwatch
get_Length
EndsWith
nullCacheLock
Serial
System.ComponentModel
ReadStream
LoadStream
GetManifestResourceStream
DeflateStream
MemoryStream
stream
Program
set_Item
System
get_Nuvwrdgkijyvm
resourceMan
TimeSpan
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
destination
System.Configuration
System.Globalization
System.Reflection
set_Position
StringComparison
CopyTo
get_CultureInfo
ConsoleKeyInfo
System.Linq
Zzsvkpq
AssemblyLoader
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
.cctor
Monitor
System.Diagnostics
get_TotalSeconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
ReadFromEmbeddedResources
WindowsFormsApp1.Properties.Resources.resources
DebuggingModes
GetAssemblies
WindowsFormsApp1.Properties
resourceNames
symbolNames
assemblyNames
get_Flags
AssemblyNameFlags
Settings
ResolveEventArgs
get_Ticks
Equals
Concat
GetObject
System.Net
get_Default
ToLowerInvariant
WebClient
get_Now
ProcessedByFody
ReadKey
ContainsKey
get_Assembly
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
ClassLibrary
op_Equality
op_Inequality
IsNullOrEmpty
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$c1461415-1ae9-4fad-b12b-46ceaa6eea6c
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Jmalmpwqyeuke
Nuvwrdgkijyvm
Downloading file....
http://dl.google.com/googletalk/googletalk-setup.exe?t=
Download duration: {0}
File size: {0}
Speed: {0} bps
Press any key to continue...
https://www.yoursite.com
bytes / S
WindowsFormsApp1.Properties.Resources
Nuvwrdgkijyvm
Jmalmpwqyeuke
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Zzsvkpq.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Zzsvkpq.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefenderTheta Gen:NN.ZemsilF.34678.qm0@ae71zO
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Miner.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Packed2.43029
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
CMC Clean
Sophos Clean
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Miner.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!542F3EA693D6
MAX Clean
VBA32 Clean
Malwarebytes Malware.AI.2879811223
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.c8c6ea
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.