Static | ZeroBOX

PE Compile Time

2103-03-13 19:12:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001c134 0x0001c200 7.88878808791
.rsrc 0x00020000 0x0001dc3c 0x0001de00 4.81054985828
.reloc 0x0003e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003d164 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0003d5dc 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003d648 0x000003f4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003da4c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Func`1
Action`1
ClassLibrary1
Action`2
Func`3
<Module>
System.IO
Bzndpmprda
get_Layimbtgb
mscorlib
Odxzhrtwb
Mtdejgc
Synchronized
defaultInstance
message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
resourceName
SHowCompleteName
lastName
firstName
ReadLine
WriteLine
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
UnverifiableCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetValue
add_AssemblyResolve
CurrentDomain_AssemblyResolve
S-1.exe
System.Runtime.Versioning
String
Htxbyg
get_Length
Emyycdtxh
Sreuvfneygkoi
Oajuajk
System.ComponentModel
Bzndpmprda.ClassLibrary1.dll
Bzndpmprda.Resources.Pnltprw.dll
GetManifestResourceStream
MemoryStream
Program
System
Random
resourceMan
AppDomain
get_CurrentDomain
System.Configuration
System.Globalization
SecurityAction
System.Reflection
DisplayAddition
Xxwqmmxbppvkun
CopyTo
CultureInfo
Zlecuo
Zpfbomsbuar
ShowNumber
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Bzndpmprda.Properties.Resources.resources
DebuggingModes
Bzndpmprda.Properties
GetManifestResourceNames
Settings
ResolveEventArgs
Contains
System.Security.Permissions
MethodCollections
Czeyjhos
PrintNumbers
Czxiyzs
Format
GetObject
target
get_Default
GetEmbeddedResourceContent
PrintText
Psrjzosyesv
Dzyunvufwspmzw
Jtvqrcwkcqux
ToArray
Uzyqkagvihicy
get_Assembly
GetExecutingAssembly
ClassLibrary
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
RemoteApp Shell
Microsoft Corporation
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
$15fc7e01-ed93-44b9-aaf2-e6955cb81143
10.0.14393.3595
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
vggwggfgf
.d;bC_
^^2GY2
]iX^C>
=f`!fw
K;GIg`}9
DjCL'
A#FldO
`pTI0 h
dQ6262
p3a-GB
nRSxms
9NRGa+!
iO#T'0
'l].!sa
U~%x?Up
?lEMnwZ&
kH6LA6
8xVM@F
NbEZQ
XPebAK5
<b8\YTV
cG[E$g
BI3o WK
~,)xy9
\Ti8E2
uu!87E
*9%V?|pb
2B}>7eH
yO*+?T
X.{@Oh=
o=V<tjt
Zp:chw
+asCmH
<^Dq3U
a~~ym{
ovl\4G
Wt?f~*7e`'
]:!47a
yJ"]ok
bfG\O*
/J_{
(xwV4.
qO7z?`i
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
sr|:/x
zR9vk[
k1e7_|
\,'Su-B
n\cx0P
m1h9uD
0`oOaQ
P6/M]'s
MI^H|`
7SOw.*
i:cdbdc
t {*fz
"Q"fv`
l#d%b6
l*SF~Fr
E-qOf-9
<X&kEU
z$_(iF4
%v [a9m)8
&-8wSa
a|g?7F
nL?Q'D"
}X!phBe;
J"RID*
'<9a|
/_0+v<
[3Xlkx
~PKxurc
xp#lDK
MN>vT
JU'H0O
7pUUU4^K
|ar@U9@{
zASUBsKU
p$D'RE
RtjI/C
vdH[9}
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
buffer1
get_Bytes1
set_Bytes1
get_Text1
set_Text1
ClassLibrary1
GetValue2
buffer2
get_Bytes2
set_Bytes2
<Module>
System.IO
mscorlib
Thread
<Bytes1>k__BackingField
<Text1>k__BackingField
<Bytes2>k__BackingField
GetMethod
CreateInstance
CompressionMode
Invoke
IDisposable
get_FullName
GetType
MethodBase
Dispose
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetValue
System.Threading
System.Runtime.Versioning
ToString
get_Length
ClassLibrary1.dll
GZipStream
MemoryStream
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
MethodInfo
InvokeMember
Binder
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetExportedTypes
BindingFlags
Concat
Object
Environment
ToArray
Assembly
ClassLibrary
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
53<p$`
8!*!$c
n.wPT5
((#d4j
6IOY"%
gOA?*4
30I(dQ=a
OGjABc
J!IRG(
V>Jx+?
(DBE%Z
T&DlA6&
#9BdQ:I
zu[f73
6Ebx(S
,ztK_A
.s7JTn
"S<v3
}U494}
S|,/2;
U7/4pW
M C5&'6
~kT!g/F
M+3KQID
omI^.s
m|>$+/
o)E!+q
"y:6};
P`q{GPy
5s*LB*ST
b{N&{.P
W)x7!
zc<ba"
-BT998$
\UO%-m3s
196+?J
aRX|YZ
sM5au_
y0=L'O
f|{,3>
U5l+isLQ^
Yl!JB_
PSLeW%I
O@'Kj X@!!
,[cQa^
}.*A8q
g>O2](
&Mv+(^u
O|ASy
wj4/~S
7*1Xz`]tV
D@q`W
jnv0KBf
LtG!Uv
A.Cr'*:
k|'XtL
Z~_J8:'
_CorExeMain
mscoree.dll
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
h%8iAW
Y`*,kXV
y51bqs
T(W`G-
DvFr(b
tz'aN\P
d"IoG7
\Df_{z
b7df!4
|n+GVt{N
/p|`?
1ZD`.d
m*LRKL
AH$Ybu
1W@?)
QV7a\6
YdusNp7o
?G (]^
qPUrS(
rd_+qa!,IY)
*$/${+
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>3
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
***************** Action<> Delegate Methods ***************
Abhishek
**************** Func<> Delegate Methods *****************
Addition: {0}
Random Number is: {0}
Bzndpmprda.ClassLibrary1.dll
Text Printed with the help of Action
Pnltprw
InterruptThread
Addition of {0} and {1} is {2}
Your Name is {0} {1}
Bzndpmprda.Properties.Resources
Layimbtgb
Layimbtgb
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
RemoteApp Shell
CompanyName
Microsoft Corporation
FileDescription
RemoteApp Shell
FileVersion
10.0.14393.3595
InternalName
S-1.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
S-1.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.14393.3595
Assembly Version
10.0.14393.3595
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.483155
ClamAV Clean
CMC Clean
CAT-QuickHeal TrojanDownloader.MSIL
Qihoo-360 Clean
McAfee PWS-FCZH!5D7C5FB038AE
Malwarebytes Malware.AI.3663528369
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057cdeb1 )
BitDefender Gen:Variant.Bulz.483155
K7GW Trojan ( 0057cdeb1 )
Cybereason malicious.101111
Baidu Clean
Cyren W32/Trojan.CLEF-9003
ESET-NOD32 a variant of MSIL/Kryptik.ABAS
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/AgentTesla.2e0df5b2
NANO-Antivirus Clean
ViRobot Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.483155
Sophos Mal/Generic-S
Comodo Clean
F-Secure Trojan.TR/Kryptik.khrpv
DrWeb Clean
VIPRE Trojan.Win32.Generic!BT
TrendMicro TROJ_GEN.R03BC0WEP21
McAfee-GW-Edition PWS-FCZH!5D7C5FB038AE
FireEye Generic.mg.5d7c5fb038aec296
Emsisoft Gen:Variant.Bulz.483155 (B)
SentinelOne Static AI - Suspicious PE
GData MSIL.Trojan.BSE.XNY6ZA
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.khrpv
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Clean
AegisLab Trojan.MSIL.Seraph.a!c
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/AgentTesla.BAS!MTB
AhnLab-V3 Trojan/Win.Generic.R422795
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Gen:Variant.Bulz.483155
TACHYON Clean
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R03BC0WEP21
Tencent Clean
Yandex Clean
MAX malware (ai score=84)
eGambit Unsafe.AI_Score_94%
Fortinet W32/Seraph.ABAS!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34722.om0@aiMxnnh
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.74570710.susgen
No IRMA results available.