Static | ZeroBOX

PE Compile Time

2054-09-11 11:36:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000249b8 0x00024a00 7.92936709381
.rsrc 0x00028000 0x0001ab6c 0x0001ac00 3.26021380582
.reloc 0x00044000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004208c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00042504 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00042570 0x000003fc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004297c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Func`1
Action`1
ClassLibrary1
Action`2
Func`3
<Module>
System.IO
mscorlib
Iybsdqymwc
Synchronized
defaultInstance
message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
resourceName
SHowCompleteName
lastName
firstName
ReadLine
WriteLine
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
UnverifiableCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetValue
add_AssemblyResolve
CurrentDomain_AssemblyResolve
S-2.exe
System.Runtime.Versioning
String
Smadkyphfozalh
get_Length
Ptpnjxsj
System.ComponentModel
Ztvvhmtm.ClassLibrary1.dll
Ztvvhmtm.Resources.Hqowpfskfwog.dll
GetManifestResourceStream
MemoryStream
Program
System
Random
Ztvvhmtm
resourceMan
AppDomain
get_CurrentDomain
System.Configuration
System.Globalization
SecurityAction
System.Reflection
DisplayAddition
CopyTo
CultureInfo
ShowNumber
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
Xhvhouvmr
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Ztvvhmtm.Properties.Resources.resources
DebuggingModes
Ztvvhmtm.Properties
GetManifestResourceNames
Settings
ResolveEventArgs
Contains
System.Security.Permissions
MethodCollections
PrintNumbers
Fptzvzfwiuigvs
Format
GetObject
target
get_Default
GetEmbeddedResourceContent
Xcqctt
Gwjcstt
PrintText
get_Pbugnw
Hwswarwtlbax
ToArray
get_Assembly
GetExecutingAssembly
ClassLibrary
Berysvmry
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
Credential Guard
Microsoft Corporation
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
$d756e255-ce74-4985-a757-3ff4c1b8f6fe
10.0.14393.3659
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
XW##Qk-
nlcc#C9!`
L;zBXh
XhWAiFAqk4
]R)M4tkE
.%WA{z
}=(M'@
-+;Ji4
F@9m*~>Lr
-jVPH5
kVCuw|
3 L%jXU
unj. ,
VR5$6\
:O]]'m
H.+GW
_t$j`8
SVYb}Lk
#mnf10
hCF@6.
/TP|26
"-~|7cB(
LhCa"|x'
k<"TjH(
n2/F$lcH
: 6E5~\tlJ
bnXuGy
AG4Ak:
B~+ u^]
eq^L^_k
)-MVxKB
[miY7zT
.d87Mq
.n;Y0`G[
?^_6r}
mwN}9
{l>Qz2
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
=*i!JZ
g~IdM;
k]G?dy
~%]+Qs|
u=rXr[
]wk,ugw
:?y.n>2
h7KUu,
GoyS4^
t.jjXz
}m3h_^
^rV`#<
}M=O,)m
U9[0s]
`!`gt^
vviTH;
GPe\STN]
Ne[C[k
dQx$?\
A@ 3+*(H
lW(+h7
%Xe)VY
1..#AK
$7Hc!M
'W5Mlc
)2bp`T0
&KP+q/)c
6ZU<>.,
[;Y8i?
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
buffer1
get_Bytes1
set_Bytes1
get_Text1
set_Text1
ClassLibrary1
GetValue2
buffer2
get_Bytes2
set_Bytes2
<Module>
System.IO
mscorlib
Thread
<Bytes1>k__BackingField
<Text1>k__BackingField
<Bytes2>k__BackingField
GetMethod
CreateInstance
CompressionMode
Invoke
IDisposable
get_FullName
GetType
MethodBase
Dispose
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetValue
System.Threading
System.Runtime.Versioning
ToString
get_Length
ClassLibrary1.dll
GZipStream
MemoryStream
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
MethodInfo
InvokeMember
Binder
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetExportedTypes
BindingFlags
Concat
Object
Environment
ToArray
Assembly
ClassLibrary
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
|7B}XM
O3'tfQ
\\H2ORZ
yULfjq
Kl~r(O B
T1$Yd*CI
]Krlhv
1]hiOX
}@aP2=
NBSh$'`
O^Kk{C
-N1*][
j8:?6g
6;&o}J
rIw{!r
Tl3r=l.'F
<^W[(Mw
\jNuz9PKw
I}:{~O
+gMo/!
08ZFB
Ed/!#y
]"+bJ
bIRmCu
-qAEE5
J_-T^L%
[5E3pF2U
lAzec;n
*B:y%-
C](j5#
N6) a@
:Hm*0cM
2|cL<~
XL;`R<
*=E:C%f
d8PHrf
| aj;C
gPnrZm
C*<&3'e
x")<^pw
~n%|5=
XoAkbb
+G\"0N
)x(8E:,[
v_Db Z%*
Pv)(p#
Iiw\b
(Ju$pB!0
54A;E*
`kI=kpJ_
h5WuXVk
rhhn++
]u}eCw"
SUm}IRsx
XZp*ai
e~kek-
YA#_n.d
Ks~!2c
FvB:m\
@{%;)o
o[O3%-k$
}d\wG!
U150]&f
ce*A>$(
7VwY;Q
/U_!#B
S,aMZr*
~f?]GOm
0r:%oD
p4{<}Ll
n8{Vq'
+kLJ}m7
%sv|9C7<,
WD@A'D
bX_v:<
:>PRZp
@*kWap<
Xt&??F^
}/^^{
"kgTd!
$6u;lvp
6*8_9F
aU:Nx6
?)kG@7
8e(u5h
hUvX9!)
7L7p]XX
oPZm' V
(ei/+$?*`
,b&VHO@
t}!;ta
:&4& T
CDTQ`i
hZYg-,
.Q2ajE
o2{RKPKl-G
h,W5m,m
0WLn!v
wJ[/^s
wyB=k#
L1^9Q~
`OBQ/e?8
3vyo#Z
^<myP/
^Tz`&P*
yo axc
/8b#9}
$ vo$2
j\DL>`h&
Bd'sx
.~}X+8
E7+)04
<0ksk7
ngsy4T
t4?t24g0F
O=lh^cO
KoCogq[
O;DO;ALI
qsDvrg)
}'{~o8|
XaH4_<
IR$p8a
(0,Pcj
_(+Hsg
hk^>8Nf
g|WR}J
}xDGOX
7:xDon
Z{&)hF
!ubGIFA7
G3Y`*&+
uQf>0\
;`Lc5A
>mCRPy\2
RkDawv
)tw&FA
uJzgvQV
X,vT =R
(3$XYQY
-8"qJ3q#w
AUOZR{,"
4! actX
_CorExeMain
mscoree.dll
)7clhj
oF/'fI
y{Ouuu(
,wT&%
6zhhjF
4fSIL\
L?3;/q
y(ru}+
KV;~^B
3rH(bz1
00999\__
'''4'''d'''
'''|'''T'''
'''d'''
'''|'''
''' '''
B`u MZf MZf8MZf@MZf@MZf@MZf@MZf@MZf4MZf MZf
B`u$B`uLB`upB`u
MZfPMZf
'''`'''
B`u0B`udB`u
MZfDMZf
'''`'''
B`u4B`uxB`u
'''p'''
B`uPB`u
B`uPB`u
B`u,B`u
B`uXB`u
B`utB`u
'''d'''
'''d'''
B`utB`u
B`u\B`u
B`u,B`u
I]m8F^q
MZf|MZf
MZf@MZf
MZfhMZf
MZfPMZf
MZf$MZf
'''T'''
'''p'''
'''8'''
'''|'''
'''t'''
''','''
'''`'''
'''@'''
'''T'''
'''\'''
MZfpMZf`MZf`MZf`MZf`MZfhMZf
''' ''' '''
MZfXMZf
MZf,MZf\MZf
MZf$MZfpMZf
MZfLMZf
MZf4MZf
MZf$MZf
MZfHMZf
MZflMZf
MZf8MZf
MZfHMZf
MZf`MZf
MZf<MZf
MZf<MZf
MZfPMZf
MZfpMZf
MZf,MZf
MZfpMZf
MZf|MZf
MZf`MZf
MZf(MZf
MZf@MZf
MZf|MZf
MZfDMZf
MZf$MZf
MZf`MZf
MZf(MZf
MZfpMZf
MZfXMZf
MZf`MZf
'''n'''
MZf MZf MZf
B`u%B`uXB`u
MZf|MZf6MZf
B`ubB`u
B`ubB`u
B`u!B`u
B`uB`u
'''X'''@'''
F^pFD_s
MZf,MZf
MZf5MZf
MZf)MZf
'''Q'''
'''-'''
'''^'''
'''p'''
'''\'''
'''('''
'''H'''
'''w'''
'''%'''
MZf<MZf
MZf=MZf
MZfBMZf
MZf7MZf
MZfMMZf
MZfuMZf
MZf+MZf
MZfeMZf
MZf MZf
MZfpMZf
MZf|MZf
MZf=MZf
MZf[MZf
MZfWMZf
'''"'''''''
B`uFB`u{B`u
'''~'''
B`uoB`u
B`uBB`u
B`uAB`u
'''<'''&
MZfUL[h
036W.13
'''S'''
MZfyMZf
'''f'''
'''%'''
MZfGMZf
MZf6MZf|MZf
MZfzMZf
MZfZMZf
MZfgMZf
MZf.MZf
MZftMZf
MZfcMZf
MZf5MZf
MZfCMZf
MZf.MZfA
'''E'''i'''l'''L'''
''','''
B`ueB`u
'''j'''
B`ucB`u
B`ugB`u
+-. '''
MZf&J\k
MZfJMZf
MZfRMZf
DNW3=EL
'''%''(
'''#'''
'''3'''
'''s'''
'''e'''
MZfWMZf
MZf/MZf
MZf`MZf
MZffMZf
MZfSMZf
MZf6MZf
MZf+MZf
'''F'''
B`uyB`u
'''W'''
'''{'''
MZf,MZf
MZf2MZf
MZf MZf
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
***************** Action<> Delegate Methods ***************
Abhishek
**************** Func<> Delegate Methods *****************
Addition: {0}
Random Number is: {0}
Ztvvhmtm.ClassLibrary1.dll
Text Printed with the help of Action
Hqowpfskfwog
DestroyTokenizer
Addition of {0} and {1} is {2}
Your Name is {0} {1}
Ztvvhmtm.Properties.Resources
Pbugnw
Pbugnw
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Credential Guard
CompanyName
Microsoft Corporation
FileDescription
Credential Guard
FileVersion
10.0.14393.3659
InternalName
S-2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
S-2.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.14393.3659
Assembly Version
10.0.14393.3659
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.483155
FireEye Generic.mg.4270337062dd7bc8
CAT-QuickHeal TrojanDownloader.MSIL
McAfee PWS-FCZH!4270337062DD
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057cdeb1 )
BitDefender Gen:Variant.Bulz.483155
K7GW Trojan ( 0057cdeb1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/Trojan.TQMJ-6046
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABAS
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/AgentTesla.f1bae081
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.MSIL.Seraph.a!c
Rising Clean
Ad-Aware Gen:Variant.Bulz.483155
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Trojan.Kryptik.Win32.3224491
TrendMicro TROJ_GEN.R03BC0WEP21
McAfee-GW-Edition PWS-FCZH!4270337062DD
CMC Clean
Emsisoft Gen:Variant.Bulz.483155 (B)
Ikarus Trojan.MSIL.Inject
GData MSIL.Trojan.BSE.XNY6ZA
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.ubctm
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Bulz.D75F53
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/AgentTesla.BAS!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.AgentTesla.C4496328
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.pm0@aa73kXn
ALYac Gen:Variant.Bulz.483155
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Malware.AI.3663528369
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R03BC0WEP21
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.74570710.susgen
Fortinet W32/Seraph!tr.dldr
AVG Win32:CrypterX-gen [Trj]
Cybereason Clean
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.