Static | ZeroBOX

PE Compile Time

2045-03-16 07:45:29

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000233a4 0x00023400 7.95913498221
.rsrc 0x00026000 0x0001ca6c 0x0001cc00 5.79874611913
.reloc 0x00044000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003e270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00042498 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000424f4 0x0000038c LANG_NEUTRAL SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x00042880 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
xaef O
:@Jf
4f .<2
:@Jf
Q0a Jy
:@Jf
&[*Ef
xaef z
]c>y
H82Xf
"GM#Y
&[*Ef
xaef F
&[*Ef
NuEQX
v4.0.30319
#Strings
ConsoleApp5
ConsoleApp5.exe
<Module>
Configuration
ConsoleApp5.Producers
Object
System
mscorlib
Expression
ConsoleApp5.Dictionaries
InitializerOrderVisitor
ConsoleApp5.Visitors
Etxxxtobdfmggn.Common
StructResolverMessage
ConsoleApp5.Messages
MulticastDelegate
WrapperAdapterState
ConsoleApp5.States
IdentifierExpressionStruct
Etxxxtobdfmggn.Structs
<PrivateImplementationDetails>
<Module>{7bf4c5d0-e7ac-4c2a-8e85-02f86196ca83}
PrepareConfiguration
ReflectConfiguration
CheckConfiguration
NewConfiguration
CollectConfiguration
SelectConfiguration
parser
LoginProducer
PopConfiguration
Interlocked
System.Threading
CompareExchange
Delegate
Combine
SortConfiguration
Remove
RegisterConfiguration
CompareProducer
Boolean
WriteProducer
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
ReflectProducer
ResolveConfiguration
Thread
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
CreateConfiguration
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
GetExecutingAssembly
GetManifestResourceStream
String
CopyTo
IDisposable
Dispose
StartConfiguration
ClassLibrary
Paxqxcv
ConcatProducer
AssetProducer
ValidateProducer
ToArray
PushProducer
IncludeConfiguration
RijndaelManaged
System.Security.Cryptography
Rfc2898DeriveBytes
CryptoStream
SymmetricAlgorithm
set_KeySize
Encoding
System.Text
get_UTF8
GetBytes
get_KeySize
DeriveBytes
set_Key
set_BlockSize
CreateDecryptor
ICryptoTransform
CryptoStreamMode
get_BlockSize
set_IV
set_Mode
CipherMode
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
ManageProducer
MoveProducer
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_8ae12c8a40c34913a027713839e7cde4
m_67fb8bbf9b994e6abb40b01af26d3fcd
m_de5c73cc24164218a5de9d27231da838
m_8c8b2d7e8469422893196664c3626a18
m_64afe07f0bc34c7180b100c1cc85215c
m_e43702339a7348bdb785e51d849312c7
m_4a61c31e766c40da9f0341e8c392aea7
m_db96d41a765640a09d4f13880ff40cd7
m_e7ed9921bdaf45c7b5e496e998244d28
m_4f93167ed49a4e27be3579a8f96e386e
m_b11cbae57a0f41db87e9cdd0edc9ccca
m_e1017323225f432f895f5eb109a4150f
m_34fd28c63fe042efa8faaffd2a4167a5
m_7b188fbcc8474512a2b37a39d747882d
m_d6afa1b8536845fbad834c2c73842e23
m_b5057763f48d46118621fe7312db115f
m_347d34f9773944bcb43875a969d377b7
m_af82d35b2e0443f083dd6577be38c658
m_782af9adcb634782ab10d993b3af4c71
m_3ae5b0c8b248423b9d6569bba07b0f13
m_26d71add017c45d2ac284a9b462125f4
m_8a06253106734427a0faad9123055007
m_fc230dc5c8f1451a88b31cf4bd7915e9
m_2e389cef18ef4dcdb643f78384273343
m_20906adb9da84426a8bde330906e7693
m_1f06f3d3a7d24f458c8b53cc43ef1ac6
m_94172c0ad1bf4a9eab699f7da426e61c
m_be40a01e912b488abd6386699d1771da
m_08e09ef57b69441aaf75fddf2904451f
m_15eef7f91bda4aee96380e81b6c4581d
m_e626159cd7b84502a84e3a3bbe41d5db
m_74bcf9b620f943fca50642dd217469b9
m_9f57a78ad2244679a739b8e2bc4966e1
m_5b10021e8f3c4ed9bcfd9fbbf01bb250
m_e2841332221040e58859eda5bdef98e8
m_1fef901dca354496b5b81dcf0ebc9e38
m_732b45f89a2847809f0711101f82010d
m_11e26dc3b3124cd3be845e0d9f7b54b3
m_6b077fd98f96452e85512c8e3fae9802
m_b7c44be326344029b2f4215d6deaecdc
m_d5de0262d1de48eba2e17aea45d55537
m_9e9e2d12d83e421d985803007b914403
m_997f1189670e4016bfe037736214a4bd
m_104dfd91ead94ec4a187c41056fc8b7f
m_1117df16832b49db9e4a4781fc3137d1
m_b3b0ff98bff54667a7cb65ca3dae7e74
m_5a4b53607abb472e8d59ec19b7bb36f8
m_df00576f325e4cd29536a3a1bc362a1f
m_a7fce40dca3b4a6ebf48b31c6fb40268
m_1d62ccedfd094f75a85bc1660c1401a8
m_c23e05ec0b2f48c192d3c73d9ddad585
m_cc9324be67934fb1b345be6804dee783
m_2f004cb1d39f4c23afd264b5375a967a
m_04daee829c4c47f1b9ae8d42e9cc275c
m_0b50128c8af042cab6bed2678d4df476
m_6c8d4e6a2c344beaa0f31b9c8de648fc
m_e75600cfe61740028dcd5a2ce6cd4f53
m_76405eec6a0e42f29e98d8ac9d663dbd
m_2167c15898e44f32ab40f0d31586c8c0
m_5d0986fb4d854afc8f56f2a6df87eac3
m_bf3862b1274046f2a040cdb297fd431b
m_f9e2a7a2682a47459b7f811854385fb0
m_b936e74754f54d529185fc4ad093f464
m_ddba3ce8942b425ea45e518b46c9a794
m_f097760698d04a29b8e1c6ce1e1a0036
m_b798ab0f309b453d8892e1842311e1f0
m_eb459f9d2ad7497c883f8552b6a6fc79
m_cecd1e8bb15344adbd37b8cd3ef376de
m_345e5268c5bd45afaa753562a8234e7e
m_98863ba8d8e246b281570c2f8541e1a5
m_6178416b8cfa46479d09636272bd0a10
m_e6773e3819e748efbac37979f70ea41b
m_3abd3ac7bfe748fea7f5915dfe48a5f0
m_22fd95d4b9ee437bb9a567b81491142b
m_e1c2a5f93c5f401096bb4ee75f64f4b4
m_eb53d1e8819a46a8970f901b132c86d1
m_e8afb74365534e9489e65a12263a8ae7
m_13184c388a98418e8b01dc31b272cfc4
m_2519837a16834502a1552698be3ffd4c
m_06a5921cf3d64b2eba4066e33f0e3ad9
m_8ee6a4a2590e4e2c8e8958b4762c2651
m_60effaaee31844d2b8715ae1ffccb44e
m_945439dc1a764d5582d1839f8aa1b742
m_dc84a649d7894a479e11fe1167aca385
m_b0a50e7b7b0e41d481d5151cb01a9aa6
m_3a1c0c3670094355a75b109a6d497d26
m_48892ea3d67b44d39e2c3e093b6308c4
m_523d040206554954903087520026205a
m_2799862be8524d79bc83f1ffe268b400
m_89226c50765148838200900407794c48
m_eedc8e0ce88d450fbda3f368f858b5c8
m_cbfdf546d176492ab06a99f3a97e04fd
m_1d81b6b0802e4c049d765ec6508b9788
m_1fee162e81b0445ca377adf04d936f4b
m_434ada6a32d84dd394d94a304ab69a5d
m_4f1ccca5bbe84bd697cf08dd716e9acc
m_86c77ff1681c4f4e90f31d857e47ceb5
m_7820b581ff344e69bdfe51536e7c9f3e
m_ed49ad16d5d94701ab03c44fc9a380b1
m_cc83f0cd082941b8834c58883be76f49
m_b28a710895734ef1bd9797afa8e5234e
m_62eb7e439aa6413e898266fff30534bd
m_7ff1a43280da4bfcb49f8269e6ad2f3b
m_d1b634f4235d40369236789d595c256a
m_0e78cdf28b8146a7946817c990e48b15
m_8f9276137c63417b9b76eff359f018d7
SetupProducer
.cctor
l06b0f564a5ea44c7970ec620428e2850
GetProducer
StartProducer
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
Etxxxtobdfmggn.Paxqxcv.dll
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$530590ba-1d12-4c16-9d38-357d3885e54a
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
AwrU|([
ZNYSs`EZ
r'Paw\@
V,G9(z3
603[*0
J %:,`
?WXfm|
vN| :+
>{dzA/
%a(!K4
)x)mq{N
NQ^9>{r
L%tmF8
J;d> t
I>v+b0
{5V~>l`l
%u}&W=
16Lq+i
;+ka2
mCt\JT
/]W98n:
6bsp\R
V37 vX
oJox,L
: xo0w
3A:#nr
o}~l9~
_-hf}4
+wWy2\
+W)Fs?-
6WW J=
R#bB9&
!d~*PlP
8~jq_B
?608q
8`j(?cD
2nQ;%4<j
|GN=G:J
*vuQQS
BxE>w-v
+`:G=6
Gj@!^O
S3~J0q
nTJ?}KC
vZYB0#%
?)IiKE
f8kl~f
b4e1Z4g
eXXQ 5
r@@g$s( S}l
<3bTo:
I3IxY#[
xP<3m.:
fRp=K\q
gO&_95(O`
";s&{H
20`6mc
!Je0,iD!
V<V=KQ
!>[otC
nQpI%uD
v^X#|+
f40o,\P>[m
U%Q}w_d}u
DBH3uw
11/C@B
U\F;6]
->zE|K$
<fN`4~o'M
Xc'bbgS
dvwRd8
Un:=>;
:/Aw66
|Lg\Sp\
<tj{Dx3K
m wl~9j
dQ\f-S
M5xpUB.>-
xDT0PH
H{P'TZ
liV#}J
2GbM72q
PN'm*k
kG^0>>
]72ro
$FVZ?YKe
8r80$
k|eRXA@
,=@/[$
-{i ws
f/N!_A
K9Otf"
F!t`vz
]>GWC
cpm[tB
9uCT0z
5&b<Ad
5 uj:t|
puho`>
Bx6mOx
$=K02W
#Y<0?9'm
R*Mh}
o5)H &
[DKa6^
b&w<&/Y
jk{j[V
GPC,pZ
E>YqHa:B
}9q3G}
##E8?65B
~s;s`E
N \@Kh
!3e(0d
@xu0I8a
MAxKIZX
?Y&shB$
pdpeYqQq
XW@Hf\t4V
AZ}B-e
=4(?c[
XpI$h#|
1;s\k,
)3<L>UI
fh!"r>Lh[
-{<q|I
Xb7#Xv
AQ<4O,
\JxrXN
H.?Bj+
Pes;zj
+kQwUb
0<`0rY
v'[E BGt
eAV\39;
3x0l28
r[%hi&
mr2J@ 7;
6(8Abm
dHZz.c
@\T,5G%
AR7dB
e+FBJ
Bdmorl
M)kB iW!w%
z1J9^HKQ;
VbZ+7q
R1NL!3V
}lhdQJr
;O;Ajy
9K{}s?!,
S@zia!
2R5M6c
qln:T*z
*{0{NS
<;@D)w
k)r3+<P
|^ylLygy*#i
Zxl4groa
rPm',+
UHnEk/
3u7s7(
UNr"&N
xRPcQ.@<u
vh%k/o
-+d[)&
EJn>e]
){+ERy`\
555)qJ'
hdU8|,G
Ae;<M01
q<O}w
m['QW
@ dWa@
U&$h9f
]Bk\d>
c(v)Dh
64qvP&
gpq[yc"
NRp1=7
p3_!Bj
fy}3Ui
("Z]NV;
>Y(_]}
7|=/UW
=w<Z0*
T*&W8O
)Xw[tB7B`
!OBr""sj
B5^cs^9
4f2X4"
S8F/Na
,FGD&.M
IJ}UeK
+d %"o
V&}>[&
<p?Xh`
a&biwdW
;cDl6zi5/
mq|-NS
5z3j%#
KaQ0%K
@p*3D~\Pk
QFRvV|
bk:FcjZ
yc `OHv
tnI9@*=
/Zrl<+
)2-\5P
s||KJN
T[-aq[
c3bps9
#S a)(
KveOJ#
Ak?l/n
-\Ja^yj
h!5}lN
RsS9?_
e#ift)
_QlZ>#
kQ8&$Ec
2Kqm-f
!w]tO)
_CorExeMain
mscoree.dll
=4IDATx
#G)E4A
8E\QAi
'$]9J)b*
MrBZBB
<G&dV8
)PQiUX:
msG&@i
&DpnXR^
|&j*B!
=k=L2&6
|<Y-Et
lJ-~xQ#
@}^+{*
ys?_?9
UJ]$l:
;t?M0;
H?)g-8R
=g*n=wZ
t$Bl{C
'O*\P~`
="vH)p&
fxh}'b&
=F?H$$
Ah+iG^9BW
x,ok`W
al(%@"
[LT22f
22GXUS
n|xVy8
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Etxxxtobdfmggn.Paxqxcv.dll
Aeyeywkbiixewr
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
ConsoleApp5.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
ConsoleApp5.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.a8ad861ef6877f24
CAT-QuickHeal Clean
McAfee RDN/Generic.dx
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.Win32.Malicious.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00577e181 )
BitDefender Trojan.GenericKD.37056036
K7GW Trojan ( 00577e181 )
Cybereason malicious.3ae888
Baidu Clean
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABHY
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37056036
Rising Clean
Ad-Aware Trojan.GenericKD.37056036
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.821
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Trojan.GenericKD.37056036 (B)
Ikarus Win32.SuspectCrc
GData Trojan.GenericKD.37056036
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1109337
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.qm0@aSKdhte
ALYac Clean
MAX malware (ai score=84)
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.F0D1C00F721
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ABHY!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.