Static | ZeroBOX

PE Compile Time

2021-05-10 11:24:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00068f59 0x00069000 7.99052287176
.rsrc 0x0006c000 0x00004760 0x00004800 2.21483026427
.reloc 0x00072000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006c06c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000700d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00070120 0x0000041a LANG_NEUTRAL SUBLANG_NEUTRAL ARC archive data, squeezed
RT_MANIFEST 0x00070576 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+5+:+?
+%+*+++,+-
v4.0.30319
#Strings
Mcnzurtic.exe
Mcnzurtic
<Module>
System.Windows.Forms
mscorlib
Object
System
Settings
Xmfrmakghspjjz.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
IContainer
System.ComponentModel
EventArgs
.cctor
Assembly
System.Reflection
ResolveEventArgs
Default
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
STAThreadAttribute
.resources
Xmfrmakghspjjz.Newtonsoft.Json.dll
Xmfrmakghspjjz.Resources.Eymshtcdqjgr.dll
Xmfrmakghspjjz.Resources.Ufavmvjihwzhoz.dll
MessageBox
DialogResult
Thread
System.Threading
IDisposable
String
Contains
ResolveEventHandler
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
AppDomain
get_CurrentDomain
add_AssemblyResolve
SettingsBase
Synchronized
set_ClientSize
System.Drawing
Control
set_Name
set_Text
EventHandler
add_Load
ResumeLayout
SuspendLayout
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
Func`2
System.Core
Enumerable
System.Linq
SingleOrDefault
IEnumerable`1
System.Collections.Generic
GetManifestResourceStream
Stream
System.IO
MemoryStream
CopyTo
ToArray
GetExecutingAssembly
GetManifestResourceNames
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
Encoding
System.Text
GetBytes
WebRequest
System.Net
get_Headers
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
set_Method
set_ContentType
set_ContentLength
GetRequestStream
Newtonsoft.Json
JsonConvert
SerializeObject
Create
Concat
get_ASCII
ConvertValue
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$3989face-f140-446a-90ce-2de855175693
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
5"rot#}
7^?bpr
3ji TGe
i+|n5
Jc%5XR
~*0:/%6
f!|?4M(c:
u&Lg_6
WHhbM5
Ur~vgd
?=-Hkw
?G]fU,
;kwrh6
dWcD !
Q\_3n`3r
rkBrkD
Bn2$7)ro
{_ZOHn
3|HvHZ
m?* rH~2
,s$90h
j\y[qG
,V[1_=
LH9WQ
zYl<i9
j8 mkD
4U%H7
X<M=ExF
lpD5I]
J:Vi%RM-
K[gW{W|Pg
b:?Q?M
w8H~ZoFr
PSuc5V
Bbt-p\BI
4t>{O^
EUT:?"fL^\
x"Bt.
i?u8Y
y9[uM
6C%.'ms
sRC_QQ
s}g$OU
\{FY9?
R1zo>!
V,maN=
Fm:QFx
V<8|;H
MIz)Eo4A
JiQva;
V@'<MB
@'=]Bc[
;>ue29
ar@D&$H
)Dly^q.
QL%lBv
CTCw>(FS
e{>:s
Vms'+,
"@M9;o
_<xZkb
=^e]Z[
bOQd:?
tJJB}Hc
1fz0L^
K8y~X&
qvavk9r
xS<_=>QXPmj
%Z!Q,$
RlR,_ZT/
Dm9g^\
snc`O[
s flBsV
qF+U:,"
0yUq.*H/
Rn*^WaG
nKL|-
hbp"+2qF
@&\bo_
vMX>Qv_
w^*V*l
k#O!\u{c
op@}O}
tkuq]w
G'UMZ6U;v
tMlLz3
cc?Ls%
"-jXyz(
'(RnMd
>Z_zWt
jjT}:%
oY9UE3
I#BLwd
)LU$8:
i{~6|/U
BqQZyZ
~wi~0J
B8Ag|3
' n|"o
D"NYYm
g`im3C
>}E[{d4
Vxw- a
g^[*D,^
9#>H>l
/'@&/i
N2Yh1"Qw
1~8)FR
j;/pG~
B3v|#h
a$.D_
g3$AL
]K#)I;
Hp+^-;
P$Y-L$
{CNE.~
+>0pW*
o;Q>mP
mlo<
O#F-sp
,d0=W
-?]OI"
>c$V.;c
C>oR>{X
u0 b/
$&M655
>6WXX`,
/w8Re"R
Pic]:T\J
q1\O-d
.N6:gjX,R
}S#[b?f[b
;umhan=
@wSP|-
V+=3%e
IGp+{'
w+aAcX
(].bqz
F(LllR(8K
s[T_Br
Cb8:,^
CxbyK.U
I'aUV3
Ha_$zZq
&m`o'a
'10asMD
Pjpw>mH
sv$a:t
7CK~@s
N[Db'e
kT.'<!a
#]/C}w
Wqm{=@
#92}7U
xMB,=I
(I>K2dD`
]Pij9W
]iz|Ni
4Q;IsS
aVWOEN
/F2u3H
3MI3=K
4Gv94m
$~W:'K
O3Oa{Sf
lb(K5
+<oo)j
EjKu?X
[Pt[/D
ekm\`9qSn
2sdG|>
y+N0S|
g)}']*
+=cE p
m5!fz?
/deJ?
1/p<Jj
Z:rcmP
%R0}sm
m~iMKH[}>
o0S<9\{
1S|<G[
[y)>_h
xAXic'
e5hU|)
+X=9?Oe
7>Dng]a
&h?jE\
.W~j|]L
.0T*a
gJR3`v
\$MB^N
i}+ZV.
zyle(x
zO~ p2
3n]<Pq
5e*rX$
&WN#{G2
d3%{K(o
w;(o,
'^8yX[`>
l~sI-<
(plTS-t
8GLOM}
Eor[LoW}
~32!C{
w_U)iv*
9~cf Y
?w>pwI
p|_ssZ
Sj~B9{|
!mc!=sv
OCo2S!
n~?c>
7OH9o:
=9Ny>~
@@F
%f+.-Nh
{M>7]W2
s.yV5
I;:iG'
/V5l.V5\Q
+V5l+V5
[@?,EG
/EG(o-
qtVRn%
5L0::A
6z=L^m
ob^4Q?
6v?:x7
zy>F'a
-i[zo9e
Z2avR#}
'?x!7
pO=N'
xp'P#Y
P#Et=x1P#%t
x)P#et
Eh=P#n
Xn&nb1L
h+mTC[iK
.}7{:
%Ee%cK
j=:0<0>
?p$$$6'%
;<o[Og
ioqW{.u
^V'@+J
sf3&{T,(G
NgY~~fVqqan~nifIvVQ^Ani
Fjzv^.
wl}n$[r
"giQqiNan
+F`YV^i^~yQv
uEeT@u
;[6AQW
-}iO_4
g%=Wl:
^q;{q(l
ec]Mn}
|KCD"z><
=!cW6r
F+&IcuQ
j=s*>t
o\rk!V]b
I/9Z0GC
ht[_*NPm
B(VgY7
)cgqq+
MWg5KV
9P{C42
(,XTC?V
,OypMs
w*qB./M
56lb>)7
$O!,xP
^@Gx?<
\Tbh3oD#
*}]7M'
P6 h$=
'C'Tm&
`&c*"
Tgo)UC
LT#e|@
,C|8*9
^`/Hv
`^30@2U
%~&&V84
v&w8YI
y<u{kl
'^(_P>!
'pz~1~
9.`sRT
r)>_WG
^wAe/5?(
N9%eMFXc
nvR{E-8
Nd[|MI[9
*Y",PQ
7GkxR+~
+VO9M7
b{V}`}
7VglT3
B/ps|$
4k/[6[
jihk-
LK{ng+d
{0>y!~
UJG5I1
Yvnbx_W_nO
3@'D@7
bK_ok
Gi8WHjae
`qPf+76
N3z LGj
L><9t~
tl~fn!
@ET)WV
+fvi}}
p1FcFC
C981cH[
Swk/;w
pd3v9i
bx)4pT
>dPy8R6N
Na(DlW3
L9Bkb;LQ5
||$.+k
Wf/l}]
dO(ORg
6z1deT
ha<>KK
_(w1Vp
uT]py4
C#H{5c
%HF]]P
h.[s7[
"5FP#pp
l[-9*qzky
D%[YSK
f/OngNL>
s]Rjbn2
v2rwTP
6e#.5.
3`Q?5]
QSzeEM
?/0Bp5
'z9,?^
ZY8D49F
+mMsTnZ
)7UNv/
%Vtf)Od
>u%&x
e6/3!28[
}xrxY~
vCcO^K
?$xp{
;2c|:p
{0|8v
8y=EZZm
e}@.~:p
@x]{b7
${'j8`
&[`9?w
|4{=f<${
CGi@~r
@Vz]*-
BW:tI\
eOyX69o!
#4+C5M
_}kLb"
U2G;e/
Gds8vv
Q8y{!*
v[0dv<
fAveW_h7;^
fEU;}c
c<~BS4t
F/oNbO
l,KzdN&@
KP"|U![
vMg095
V_%e&TP
7IrV97ou
!uT]j?d
+QGemK4
G\X@{m
[RcW.E
o*,VXR
xU5m@H
vE[{db2
mbGAtSX
i@ceGo
+9LhmY
GMI&Pd
Ge"QoMoJ
>'@>%O
KO1auv,.
!sA8?V
[SgoOSlY
6<a8wz6
NTiW&^0F8
F[D.SI
?S&(7;&
QG?~#TQ
~(jgnD51
d;12+'
M8J{B%_
"s0{uc
FkBs=\fJ
uSQZ/>
@)zLsv
7bj1v&
`B)7f3
:XnpGS
F0vI>T
shGg?A<
n@*A7
SniQnb20
i"1:.!9/
=In#cs
/WN}c9
a1>$BA
cdj*ghg
mCGPZH
]Ngpk
-/''"-
RPJB1
168gl)
QJW{hu
)/?_?L
N5ifkf
XRxLD
c}S!ih
jwn};>U6
J<""*|
^%c^>o
qqM8%7W
--,*.m
Bfh.X8
eaa.e>y
2iafj`
|My!!()
Y!iyy)Qe%nYy
j:&6."
QBR3-#g
US]]SU[Y
oD/Z"<
I1%Qi[3e=Asa58
X`DDtQb6&
0\`qf.(1":
TtqL^P@PQKCL
g'=+<x
Mevf{iqx
tHdtyh1a
Tm(m"BR!
6Au1GC;qyjmno
qkhPy@
z(`*=;
FzgP@z
^jAA6W
g2B1+`
DfU"kf!Gzb
8MF$Oo
~Jw8"b=xu
J*iSL!
XZyitl
Q~E62V
2.zPPY
#"8p1SY
q@$4p)J|
BfTnV4#y
*{"x{a
3j=D7'
~ yU|('
i{tI:*g!
i]&Ui~
vQN\ K
AzeNQU
A#,Mb*<L
3ozvpM
>Cp+,?s\
^Mt<Oq
}Vn=j|
2`6R|G
rqEN\.
nx>r"
iX^e]:
7j#lZOi
g{cteI
/J]`>S<0F
1*|Sn
B=>Fas
c}NHu(U
\\52J
}Yu@>j
qSiui\
tu^]^,
uzYO@Z
sIuO1N
;,iTmr
is>N9z
vk8K3{
AA;`,G
sB'Wdpz
3}Qu5:C
QdBJ8rzG
V}>m=x3b
s"(|@1!v2nq#P
F>z;rK
If7+>$
5l\J,4V
>N=>=B
kX/}hF
yX5e%{
\\C>3/
%(j3Ro
#4im^h
k! 6)u
E/P#,B
y.LjaD
ca,tb^`
i';g4,
g`^C}~%
DUt"sk
vL#Vr^
)#gq^
> }/@
0c69RU
?btJCm
pC>?Gz
:3wyX,s|
3IuG9UT
\MJ:nF
Jq!Unp
G+!"f7
1`r1
7kh1vu
WP*fh%X
r"yEah
!! dG(
.%p;|M
iTOo>\ft$
2Tn%Ev
Cy8t \
[jO0z@
p:UXC<
kS.x.BV
"hy>Hy
%&B:,
Y CkAh
7CaSp
\pA8[\ n
=5oj>/i
O-n\$(
h_n>0v,
hXTZ9z
^I"DI$$
6Fz-:b
^YkzT
?\Ux;l
(}/YG
-e0b2b8|
z:XdT$
q14y-S5n
qg9,tz
cMs7=-Sm
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
:v}[YZ
>N5qxZ
YigUfxU^'`
^('u/H
_AQv_#
nW;Q?'
aUKt'F
rl&zg
jFbC)M
2s@!%W&
TPrA$K
8cZ"/WO
yU"P%
)yriU<
`(cJ-]
@qU&1/(MCTB
`Z*P35O
^X?L!
Byw6P
It,-e}
`VnEtu
e`9kfE
DI_vT'J
XMo1.X?J
kU.LX)
_S9.G
yr:BNa
R(.GIm
BG&a/q
9KHtyr
LG-a_q)
\bpLX#
;z+hhg
?(fZW1
YQ@frX,m
zShshw
ek|$7i
LS&:E`Z
D2K$sD2G$sD2G$sD2G$sDr
Q"9J$G
~su}`s
jT^#k0a
pA>}!R>
A$7g3J
&UqS6G!r|$
7htE^[
-dq=[:
\c#Kmd
BI>N9Om2
R2Fj3e
P~i&Z
&ZbxyR
Tq}!_{s
H\|&l5hq
>haj>8u
-$8NK<
+=!6U6
s`wJ}P
!['(k3
t :X}
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
Xmfrmakghspjjz.Newtonsoft.Json.dll
htp://test.co/tst
thing1=hello
&thing2=world
MyTestHeader
My Test Header Value
application/x-www-form-urlencoded
Ufavmvjihwzhoz
Eymshtcdqjgr
ForgotModel
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Mcnzurtic.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Mcnzurtic.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.6989acbd9d6104b5
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.MalPack.MSIL
VIPRE Clean
K7AntiVirus Trojan ( 0057be311 )
BitDefender Gen:Variant.Bulz.468878
K7GW Trojan ( 0057be311 )
Cybereason malicious.62b500
BitDefenderTheta Gen:NN.ZemsilF.34688.Bm1@a8GngOc
Cyren W32/MSIL_Kryptik.EEA.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AAVA
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Trojan:MSIL/GenKryptik.17c59c94
NANO-Antivirus Clean
ViRobot Clean
SUPERAntiSpyware Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData Win32.Trojan-Stealer.SnakeKeyLogger.P68ZY9
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
AegisLab Trojan.MSIL.Seraph.a!c
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!6989ACBD9D61
MAX malware (ai score=88)
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Seraph!8.111C6 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.AAVA!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.