Static | ZeroBOX

PE Compile Time

2040-04-13 19:46:24

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00023704 0x00023800 7.94831898007
.rsrc 0x00026000 0x0001ca74 0x0001cc00 5.79891097704
.reloc 0x00044000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00042498 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000424f4 0x00000394 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00042888 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
3af vK'
,!a i8
D[ /?AUa
Y bGOKa
08g+X
D[ /?AUa
Yef 'B
Ye ]>u
D[ /?AUa
Y bGOKa
b 0hUva
:Je ea
v4.0.30319
#Strings
BLI_057702308
BLI_057702308.exe
<Module>
Advisor
BLI_057702308.Roles
ValueType
System
mscorlib
Iterator
BLI_057702308.Schemes
BridgeComparatorConfig
BLI_057702308.Configurations
RegistryProccesorMessage
BLI_057702308.Messages
Object
MethodCustomerBridge
BLI_057702308.Bridges
PageMapperMapper
BLI_057702308.Mappers
Comparator
Prsotwk.Common
InterceptorMapperMapper
EventWrapperException
MulticastDelegate
DicTaskPage
BLI_057702308.Pages
DecoratorTaskPage
<PrivateImplementationDetails>
<Module>{97bc8af1-3748-431a-b890-dc2b554db564}
OrderStruct
PushAdvisor
ComputeAdvisor
def_length
DisableAdvisor
StopAdvisor
lengthvalue
DestroyAdvisor
CompareStruct
Boolean
PushStruct
m_Token
_Indexer
VerifyStruct
InstantiateAdvisor
ResolveAdvisor
res_length
InvokeAdvisor
PublishAdvisor
param_max
GetAdvisor
ReflectStruct
ExcludeStruct
m_Customer
getter
CollectStruct
ResetAdvisor
CloneAdvisor
offset_res
CheckAdvisor
InsertAdvisor
min_item
SearchAdvisor
CalcStruct
SortStruct
CustomizeAdvisor
RateAdvisor
ViewAdvisor
QueryAdvisor
VerifyAdvisor
PatchAdvisor
_Proccesor
MoveStruct
VisitAdvisor
Delegate
Combine
Interlocked
System.Threading
CompareExchange
CreateAdvisor
Remove
ExcludeAdvisor
RemoveStruct
DisableStruct
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
AwakeStruct
AwakeAdvisor
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
Thread
CountAdvisor
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
CopyTo
ToArray
IDisposable
Dispose
GetExecutingAssembly
GetManifestResourceStream
String
AddAdvisor
ClassLibrary
Ujkiwe
PostStruct
IncludeStruct
DestroyStruct
WriteStruct
UpdateAdvisor
RijndaelManaged
System.Security.Cryptography
Rfc2898DeriveBytes
CryptoStream
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
SymmetricAlgorithm
set_KeySize
DeriveBytes
GetBytes
set_IV
set_BlockSize
get_KeySize
set_Key
set_Mode
CipherMode
ICryptoTransform
CryptoStreamMode
Encoding
System.Text
get_UTF8
InstantiateStruct
get_BlockSize
SetStruct
CreateDecryptor
InterruptStruct
PopStruct
ResetStruct
CloneStruct
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_8e66e79d51ec43b49118396cf373ecc1
m_97836319dc2a423e9958779a0a3b1cc7
m_59d4a59930ba42b78f04aeb378c5cf45
m_b5a635bd96c8404abecf7a224d754610
m_699da6998c4846389e0e7db72aa56a4d
m_80b0ebc9ce114e0ebd2561f567d1dd3a
m_d65286287e484fd5b7e8acd5eabf8779
m_386bc9c57217467bb65044c481f1f8db
m_32a8e42120494af1829dca2e72598e5d
m_b2dbb16e2d2648169e943866b6a2d74b
m_b539339b73f647eca80c85a485831f14
m_3da7bd52f99d4cd78c5c4bffdf35f8b3
m_a471b344ba58473ca7c7ace4f30241e4
m_f0f31ef885184e6aa91e4932d118e972
m_55cb33ef447e4e2f9cfa91102843402d
m_ebd07223de514ff89681adfa26a253d9
m_130985cc9a704489b2ca1e1fe142613d
m_33da865287bc426b8e4c0a59322302e0
m_79be162be2b74a96a8bc10e14fb69cb0
m_e5c78f66b37448a8be5f0ed69fb63d1c
m_9338f697fd4142afb38dc71d3840ed59
m_4500f9ef4c01404b9f70314901ba4ab9
m_6b4c90eb10ae4a2886183fc2bd4b1106
m_cc0ab3968e274c4ba39abc2b128bd5ea
m_1a70ac26dfa046989a6ad38112fe8e41
m_fc88c96d69154190a618db73291370d1
m_ccd7939b9e1744b0b21965db822d1a13
m_42157cc82e604b0193feeb20ec7f6907
m_d95d91c32b3a4d239b3a2544cd6e6a75
m_b51b66960dac40fd8f439400ef7547df
m_c4816a524f1c4c5898ff9a68da68ddb8
m_6974f4f596744abf80b55638f7c7bf75
m_15330e3efa84432786f984938b19d294
m_6675ad92ecab4ab18cc6adf626d64334
m_84b2e2ea84fb4284b207dc752755119c
m_e2b4e56932254a458d2fcd3af6cda3f4
m_8c077c30a4604352bf3a3da9aa5937f7
m_70af733a5fe34a548b6d800f532d360c
m_6a5e3b5214904c2e822f5a21d6e45793
m_8800f1fce6b74563a3319f5b5420e75a
m_d0ba38a0cb6246bc9cbe8d740233a881
m_8846c8f4b95b4be7a56eedd7db6cb770
m_f9a54119c3014bcebe5c6eb5d2a3025a
m_26aed7ddff4a4a4dafbbcf7bcf76bc7c
m_efba24611f8b47909d1e99e6642f429f
m_efcf57cabee84b1b8ffd38967fc119d8
m_41300ab51f2649aeb4e306efc15fc8bb
m_abd738c80bbc48d0b94dc2b1e3cc7c34
m_61b814b4fec34ad4b95f9d8327c57a05
m_f55e5482d0354dc98553516728c196a9
m_89c28f01dca848239c5a1524f6897c3e
m_516305b75b524adb805c84e9ba08ba4d
m_57c866bfeb034dee917829c5a202136f
m_e768e5e64b7b4f95903265e7ce8ec4fd
m_8707c90787dd437f890495c4f558b71a
m_b2f98c4d51c146c4a5a2dea764072454
m_e9b7092719aa4ae3b81f97c9315ec668
m_134ae0a38d5e4206a6427fae5d5742c4
m_6e2dc80eabe44847847ccdd09068307f
m_2c9c0c3ac21a4fb8bff7213c7bfa6804
m_d61e903c21444e1ba79e8bd03fe2a13c
m_eaff0a10df43445eaaf1ec5f3ea7e4c6
m_b2212c52bd854cc79b132af2cc91c0b7
m_3c2da75abb154be6862507c3bbc0f352
m_a334fb6982464178991ab0b483aadeed
m_1c88ad05edfa40d5a11f0998e794b476
m_0cce11a684724d0fa466db0a70d2c9ed
m_3be035bb78804664bc9632780bfb3b2a
m_46dbe21646be43b1a2fd7736f969ebd9
m_80372308291c48a08914bd33118927a7
m_1052c7f528da40d7a0e4eb480a8f0152
m_f9c5d93b77be45078627fe825fa1ce5e
m_4d2aa0e08a6e4b378014ac86a982da32
m_bd4e45ec70d343f2b14bf2be9abf8106
m_1fc06ab252df4ebebda0a18fa3c8480e
m_24286a59f62c40858b8f5a09cd7e949d
m_b70b824dacac4b1691635240c5964c0b
m_e144b6f02d3e4673bd4146a2fceb9488
m_7eb5538cb6234e4ab0997b1c6323ac89
m_de6a920f82584647b827e4cbfd3a5b98
m_b25d2425d97f4d61ad6ef2835b9448c7
m_3eb619f05b214e1e8103b0dbac6eb74c
m_b782a8d521ba418690eace12d4df64fa
m_be938eb3da1740ff9c1351846483bd9a
m_9ed86341542840b794218f87ab415e97
m_37204367d99e4488b131c9569bcb62af
m_0663c054686742fca33c28e3eb03e675
m_8d23109ef89e46a5a557e2d65133d008
m_30e9c99cb21f4388ad98e1955ab85ac7
m_36b86de179f0401696247467dff7b716
m_9df23eb6c5e54805a5cc4522980b2cf8
m_efe28e2f9d2545c4a3457d80d3739b35
m_7965b026deae44138089fdb6e0d168ea
m_023af2637f844129b0912ee585eb1e28
m_0d186c8876c741c2ac7f1105062723b9
m_fcddeec219644a5b85af3cc1e635c855
m_32cb398caf5b47f19630c5741aed0aa4
m_afd62dc8fde244e4879fe14465e8fddf
m_f4ebc9804a7f4e15b59d2102c82a5cee
m_257068c64ab84bc7bf60322e9456dd7a
m_5ebdae9d79c34dada87473d0db36ef44
m_731e2bb8d9034d9099ec7333e44ef6e1
m_b985e58a5bb243ccb0d8bed37fed547a
m_bb09658040fa45d2be62e6289da95a42
m_3a6d938582ac414fa862c44e305303f9
m_0b675203804a46a5952d8ea2284683ae
EnableStruct
.cctor
w90c162495a9c4733902093942a5e4e92
FlushStruct
SearchStruct
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
Prsotwk.Ujkiwe.dll
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$fa36536b-9441-4fc9-9cb7-e6dc1e833d3b
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
qgk6vw
IR}\r)
ZwMd3a{
Fr)99
,3g%:=
Lu{G-H
aoI<jpZ
ttd>-*
p0fA?3
-AkE_s
eO?k*Hu
HCg=q4
#FFTc
asp>`4#
{:bvr})
W(Nn9
DsXp=o4$
5JDVn~
1,@-Eg
Aq.I.Pq
G4b`5+
cKqlV'
kUC'oW'q
\vK YX
s.s3 4z
bq5gQ1
lEAj`p
(*+_Y\
,9zN9_
<'Vmtu5&
niRw!|
tAvsw
,;b&-w
a!c7T.
2BF<gbY~I
k,i-'GE
j><E;_t
#vEg(0yO}:3
EgJCz|/b
5C5I&a
REX+q3
}3u~nd:
u*vA80
6gx1,%
Dpy%:
Z/D&kz
r\W^A
T$-''X
QAHG8"
W}by{P
y\ 4+L
l=b,oD
#Cjlc,h
% RBkM
GB0:qDo-'
f]=OVn
Ut_Jz]
)uxQQIb
f$AUP^}
,1+{5F
,%Ec}C+
AKlyS:
AB+<bC@
xZzH*)
+mbUl95TW
t#VvuG
t5:p*7u
FNnzk^
-XF`(J
BBdA\h
#*IEdLt
j 4`=#
zaD6h~
KR7!_I8
sF*n/
a?_GHYv
QdTPB|
mlZm+08
2nb10]
Vsvq9
k\$w+;
L+}^*\s
`pnSj%
3j)!2LEW
w":I`2Z
DP:l*\N
n?o^X2
0z77wuv
|uw0,&
r}H%Ic
Afs}\R
B1^*G[
?G*gpR!
l7]W\A
T|=b+iuD
9cKG5[
{p#rxn
m%g72L
|Ks&~P
z{1MbL
oNW 7s
(DcMJX
bk_h2!
2\V-Th
yMH5JPc
mcwh )
#xDa~\
:$WWYh
QDC,.g
I7%e
b%f)p'r
"V; Ja
IYdT;z<
hV|B;N
d~j`fd
?@3H4%
;[?Ftj
VEV!JTB
>s`Xkf#
{Ogp_.
u@7<re
d!`(<avv
C&#ro}
M{{R&Q
Ke>NPM%
#GM(y9C
rV"9)o
U<s=r]q
q$DMK3
E8@?az
fNuF"vP
GWvr{1\3/
Tw9e,b
)6(3 (
a`>V4isT(
_\*Iy]
H!(/<2P=w
3~4l>ol
rd @.w
7|7<?r&
/Pm=_F[E$
]2D>o6
!p.V2g
$H{hTe
jBK_\\Vd&p
=JDUyQ
=~DB7.-'
("[X8[
@&kbV|
WNH*lY+Z
U?"<8V
SAu&z:
t#&dp_
,4ndA~?
ulXx]k
`[TSMa
YM03R
t:&|qGCu
g2rz`o
&QAEWk
lc&eFC
ub}qZht
@A9Lkr
u@}rk%tkc
yYHJZ)a
|3a~sJ
;wUGQFc
5cXiDC
nym"J/
EmYMz-ng
<pPE0*
}gCGV0
SoGYr8a
hx sWZ#
eBvF=^
/X[rtM
W2_%}jCI
FK?4c
ra)}X=nwk`
/6Mlm0
dU"T's
l!GwTn I
*AJi$c< s
7aa3^99
/?-<dK
]2Dz
Mpe;Z5
dd2x*^
O'X@h-x
,5KQ18
*~J58z
4j,b_N2
td?_a}
'=,+Q;
UYcjr~
T~YaX8
KuIVLA
5;~p{o
5GL@'^
^~4arupTS
e2kp[c
6`m+4db
nF!5ly?
h9Jx` *I
v9;^J3$
Mj}WAB
J$[W6c
!xaqnJ
_CorExeMain
mscoree.dll
=4IDATx
#G)E4A
8E\QAi
'$]9J)b*
MrBZBB
<G&dV8
)PQiUX:
msG&@i
&DpnXR^
|&j*B!
=k=L2&6
|<Y-Et
lJ-~xQ#
@}^+{*
ys?_?9
UJ]$l:
;t?M0;
H?)g-8R
=g*n=wZ
t$Bl{C
'O*\P~`
="vH)p&
fxh}'b&
=F?H$$
Ah+iG^9BW
x,ok`W
al(%@"
[LT22f
22GXUS
n|xVy8
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Jomhzjoxcwe
Prsotwk.Ujkiwe.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
BLI_057702308.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
BLI_057702308.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.37056027
FireEye Generic.mg.6f86775cd014c339
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.Win32.Malicious.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00577e181 )
BitDefender Trojan.GenericKD.37056027
K7GW Trojan ( 00577e181 )
Cybereason Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.qm0@aqRBSj
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABHY
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DF721
Avast Win32:Trojan-gen
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37056027
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Trojan.GenericKD.37056027 (B)
Ikarus Trojan.MSIL.Crypt
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Microsoft Trojan:Script/Phonzy.B!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
GData Trojan.GenericKD.37056027
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.grp
MAX malware (ai score=99)
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.ABHY!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.