Static | ZeroBOX

PE Compile Time

2098-10-14 13:12:18

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000060b4 0x00006200 6.45252608923
.rsrc 0x0000a000 0x000023c0 0x00002400 4.59386547713
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000b8e0 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0000b8e0 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0000b8e0 0x00000568 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0000be48 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000be78 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0000c1d4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
List`1
sawqdpqwldpqwld02
ToInt32
wodowqdowqdqwp2
<Module>
QWKDOWQKDOQKOD
System.IO
DQWOKDOWKDOQWDPKOZKDSP
value__
lalala
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Synchronized
Append
TrustMe
Replace
defaultInstance
set_AutoScaleMode
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
get_Culture
set_Culture
resourceCulture
Capture
ApplicationSettingsBase
Dispose
Authenticate
EditorBrowsableState
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
WriteByte
get_Value
TrustMe.exe
set_ClientSize
NewLateBinding
System.Runtime.Versioning
DownloadString
ToString
disposing
get_Setting
set_Setting
System.Drawing
get_Length
System.ComponentModel
LateCall
ToCall
ContainerControl
MemoryStream
Program
get_Item
set_Item
System
resourceMan
System.Configuration
System.Globalization
System.Reflection
MatchCollection
GroupCollection
WebHeaderCollection
Exception
CultureInfo
osakosakdoaskdwp
askodksoadkoasdkwp
sabebokowkqodkq
ToChar
StringBuilder
get_ResourceManager
System.CodeDom.Compiler
IContainer
IEnumerator
GetEnumerator
.cctor
System.Diagnostics
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
TrustMe.Properties.Resources.resources
DebuggingModes
Matches
TrustMe.Properties
Settings
System.Windows.Forms
Contains
System.Text.RegularExpressions
System.Collections
get_Groups
get_Chars
get_Headers
components
Concat
Object
LateGet
System.Net
get_Default
WebClient
InitializeComponent
get_Current
Convert
MoveNext
System.Text
set_Text
doqwkqkdoqwkodwqkodwqkodqw
ToArray
get_Assembly
Destroy
EnumeratorToIteratorAdapter`1
CMS_FILE_FLAG
AutoScaleMode
Message
System.Runtime.InteropServices.WindowsRuntime
WindowsAccountType
SettingsBase
System.Runtime.Remoting.Messaging
String
Marshal
System.Security.Principal
Control
Stream
RankException
ResourceManager
DirectoryInfoResultHandler
Container
Enumerator
.Properties.Resources.resources
ArrayWithOffset
System.Deployment.Internal.Isolation.Manifest
Assembly
4"41474
4+44+4
4)424 4+414424
4'434.4
WrapNonExceptionThrows
TrustMe
Copyright
2021
$67a252aa-dff3-492e-bebb-007f9d289457
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4@
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.6.0.0
_CorExeMain
mscoree.dll
sOX4A__p
ttttG9
=HHE25Q+S
]}TEG==
&rrprrQ|
uSccktt[O{
8^_cjqv}
Vecb_^_hpv
Jo_I5fc-9Wjs{
vuL8'om!+>^cox
X}}D)TusL"0c^_mv\
|zusojc__kv
}wtqjf__m%v
zuqkf__&W
{vqjc^&%
{uqjc/
Jj[*$`\ddddl\rt}7
((((((
'*(%*2+
==<:741-
6>>=<84$
;>>><8!'
.>>>;6(
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
totallist
LINKS_HERE
OUT_STRING<metOUT_STRINGa name="OUT_STRINGkeOUT_STRINGywOUT_STRINGorOUT_STRINGdOUT_STRINGs" OUT_STRINGcontOUT_STRINGentOUT_STRING="([\wOUT_STRING\d OUT_STRING]*)"OUT_STRING>OUT_STRING
OUT_STRING
UserAgent: OUT_STRINGMozilla/5.0 (X11;OUT_STRING Linux x86OUT_STRING_64) OUT_STRINGAppleWebKit/537OUT_STRING.36 (OUT_STRINGKHTML, lOUT_STRINGike OUT_STRINGGecko) ChromeOUT_STRING/51.OUT_STRING0.2704.OUT_STRING106 SafOUT_STRINGari/537OUT_STRING.36 OPR/OUT_STRING38.0.OUT_STRING2220.41OUT_STRING
OUT_STRINGBrOUT_STRINGeOUT_STRINGwOUT_STRINGsOUT_STRINGteOUT_STRINGr
OUT_STRINGwwOUT_STRINGw
[SPLITTER]
OUT_STRINGGeOUT_STRINGtTOUT_STRINGypOUT_STRINGeOUT_STRING
OUT_STRINGAsOUT_STRINGseOUT_STRINGmbOUT_STRINGlyOUT_STRING
OUT_STRINGLoOUT_STRINGadOUT_STRING
OUT_STRINGEnOUT_STRINGtrOUT_STRINGyPOUT_STRINGoiOUT_STRINGntOUT_STRING
OUT_STRINGInOUT_STRINGvoOUT_STRINGkeOUT_STRING
TrustMe.Properties.Resources
Setting
qTFLSlEACm
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-4F49A96AC6F3B36D6E19FA3DABB14F81.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-EB86A9B74641CA3C83702B5FFCF938E0.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-EAB9BAFC5F7E9E82AE180EFDAD75575B.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-63760867A0A2BA86953BF4C49B3AC736.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-07E38B691A0D0DF5A4AA5DD7D917D1BC.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-D7A739907814AA27BE574C07BC8A5CAC.html
http://asdcqwdwqx.gq/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-7A0F151B9D6915262056ECB168561B23.html
UserAgent:
Mozilla/5.0 (X11;
Linux x86
AppleWebKit/537
KHTML, l
Gecko) Chrome
0.2704.
106 Saf
ari/537
.36 OPR/
2220.41
VS_VERSION_INFO
StringFileInfo
040904e4
ProductName
Ad Muncher
FileDescription
Ad Muncher
CompanyName
Murray Hurps Software Pty Ltd
LegalCopyright
Copyright
Murray Hurps Software Pty Ltd
LegalTrademarks
d1161bda bf96 458b b651 b0bf48d2e09c
Comments
7bb5da5f ce7a 4e9f 8bbd 3fc0f336e354
114443af-2bec-494c-9aa3-75365644a622
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.421856
FireEye Generic.mg.b84fafbb835c20e6
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
ALYac Gen:Variant.Bulz.421856
Malwarebytes Trojan.PCrypt.MSIL.Generic
Zillya Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.421856
K7GW Clean
Cybereason Clean
Arcabit Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.ECN.gen!Eldorado
Symantec Downloader.Trojan
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HRK
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!1.D296 (CLOUD)
Ad-Aware Gen:Variant.Bulz.421856
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownloaderNET.155
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition PWS-FCSR!B84FAFBB835C
CMC Clean
Emsisoft Trojan-Downloader.Agent (A)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1142853
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/Agensla.GC!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Bulz.421856
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Generic.R417060
Acronis Clean
McAfee PWS-FCSR!B84FAFBB835C
TACHYON Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Inject
MaxSecure Clean
Fortinet MSIL/Agent.HSA!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34688.cm0@a0AfOali
Paloalto Clean
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.