Static | ZeroBOX

PE Compile Time

2021-05-22 11:19:47

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00015354 0x00015400 7.91596436694
.rsrc 0x00018000 0x00000240 0x00000400 3.53240358242
.reloc 0x0001a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00018058 0x000001e7 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
jyO7ioJ
!J0Dw%
KGX[c`
*Dpp\=
fKFhzK
b7A\E'%
!WM[V-
bP-6;<9
J][DU=dz
,CrnxE
vv#TEBg
>049AL
@"=aWq
[~p)l
z`pwy2
uo<@ieaw
O;);#"
DIh0kS
4@4g":-
r5c^2O
,qPQ)BX$
:$bUz""6jg
u8}7vf
EWig $$q
-S)^gs
|vKdQ<
]Aj2go
SkY}a#Hu
)C;kC5
f b_~bj
w`t3zV
U)1.j\o
p(Hb`}
C<!sq({
Dxj;hU
Uj'mb_
T{~Xb\
t0)p-S_
d$AA':
)dG4xP
Hp],:t!
ehNH.Ul
>O]y/-
>/*\{1
2013a?
L}v~C9
z?dAE-
1:w+%Jj!
0d7?;4],
Xxe)FR
OA/~&X%o
J+:mdy
h+`M=<
Q5=!7(
K5bD1
rm{;%u
:ETJ;]HK
lQ}8p
:n#x)x7+AL%
7f4:T\
9?-;DbZ
#2sJ{i?`E
kl-h9
.:"},s
.Ph{Qp<
M$bbR=
.\$1I<c%VZ
YIc5T/
'8gv,A
Z(~u^O
Ia)mkjMR
f(|^Iv
AJQAf_(Y
>LYzyY
q>m]4a
'iPo$Hp
m;Z-HY]
Qv0E"_
mz'-G2z
>wbc&B~RG
@IVP5T
s&1d/{
?pZ|Vh
~h:ui
qjd$Q"4
r(by90
zDo78
%V'Mfi
vqu~2#
:Z5~Yh
_bLiU-e
v4?p-6)
HOL32rY
VY7yYy
+zsE"-
mZw-!U
s2QL}?Z
C(~.Cu'`
z-u=@e
'D*\A'J
LJf68cm
>0i>6S
[grStx
"M-$3w
evr@k
\lI|!Jx
:L'LOI
,n+"[U u9
mVb:3=6awY
Z~UChN
,=MB$d
KA9}NR'Z
,V7`=!h
Bt!]nmT%
2n=Jda9
Rb7#IrH
!Z0zy8Y
#C,h^~
%~fRUD
M ]]4
bbz)KlJ
zR*@|rN
/2:TE&k4V$oh
i9&!`fLH
)!$gvf
4Vs[JC
Y_cX*n
VMDj^m
Z?_b`
_bj2
_bY*
Z_bX
v2.0.50727
#Strings
<Module>
DataField
Decrypt
mscorlib
GCHandle
System.Runtime.InteropServices
Resolve
Assembly
System.Reflection
ResolveEventArgs
System
Decompress
.cctor
DataType
ValueType
BitDecoder
Decode
BitTreeDecoder
Models
NumBitLevels
ReverseDecode
Decoder
Object
Stream
System.IO
ReleaseStream
Normalize
DecodeDirectBits
LzmaDecoder
m_IsMatchDecoders
m_IsRep0LongDecoders
m_IsRepDecoders
m_IsRepG0Decoders
m_IsRepG1Decoders
m_IsRepG2Decoders
m_LenDecoder
m_LiteralDecoder
m_OutWindow
m_PosDecoders
m_PosSlotDecoder
m_RangeDecoder
m_RepLenDecoder
_solid
m_DictionarySize
m_DictionarySizeCheck
m_PosAlignDecoder
m_PosStateMask
SetDictionarySize
SetLiteralProperties
SetPosBitsProperties
SetDecoderProperties
GetLenToPosState
LenDecoder
m_LowCoder
m_MidCoder
m_Choice
m_Choice2
m_HighCoder
m_NumPosStates
Create
LiteralDecoder
m_Coders
m_NumPosBits
m_NumPrevBits
m_PosMask
GetState
DecodeNormal
DecodeWithMatchByte
Decoder2
m_Decoders
OutWindow
_buffer
_stream
_streamPos
_windowSize
CopyBlock
PutByte
GetByte
UpdateChar
UpdateMatch
UpdateRep
UpdateShortRep
IsCharState
ConfusedByAttribute
Attribute
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
STAThreadAttribute
UInt32
GCHandleType
Module
MethodBase
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
GetParameters
ParameterInfo
Invoke
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
MemoryStream
ReadByte
ConfuserEx v1.0.0
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.633919
FireEye Generic.mg.49545f0af79ded22
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Gen:Variant.Razy.633919
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Razy.633919
K7GW Clean
Cybereason malicious.af79de
BitDefenderTheta Gen:NN.ZemsilF.34692.fmW@aqTN6tc
Cyren W32/MSIL_Kryptik.CRK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.QSE
Baidu Clean
APEX Malicious
Avast MSIL:GenMalicious-BIU [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Clean
Ad-Aware Gen:Variant.Razy.633919
Emsisoft Gen:Variant.Razy.633919 (B)
Comodo Clean
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.mc
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Razy.633919
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.Gen
MAX malware (ai score=84)
Antiy-AVL Clean
Gridinsoft Clean
Arcabit Trojan.Razy.D9AC3F
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Ditertag.A
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.RL_Generic.C3492413
Acronis Clean
McAfee Trojan-FSKC!49545F0AF79D
TACHYON Clean
VBA32 Clean
Malwarebytes Backdoor.NJRat
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Bladabindi
eGambit Clean
Fortinet MSIL/GenKryptik.CRCM!tr
AVG MSIL:GenMalicious-BIU [Trj]
Paloalto Clean
CrowdStrike win/malicious_confidence_100% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.