Static | ZeroBOX

PE Compile Time

2045-11-18 00:41:43

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002bc84 0x0002be00 7.95954500758
.rsrc 0x0002e000 0x0001ca7c 0x0001cc00 5.79925954179
.reloc 0x0004c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0004a498 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004a4f4 0x0000039c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004a890 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
tFa -p
x<X aGS`a
~d4T
Y 'u"
#`e =."
~d4T
ef 5^J
cf RX`7a
x<X aGS`a
qOX T^
v4.0.30319
#Strings
IMG_52_67_21_33
IMG_52_67_21_33.exe
<Module>
IdentifierQueue
Fsjhubdxcoai.Queues
ValueType
System
mscorlib
PageWorkerFactory
IMG_52_67_21_33.Factories
Object
RefTokenizerWorker
Fsjhubdxcoai.Workers
GetterTokenizerWorker
RulesCustomerDef
IMG_52_67_21_33.Definitions
Tokenizer
IMG_52_67_21_33.Candidates
ObserverWrapperMessage
MulticastDelegate
Customer
MessageFactoryResolver
Fsjhubdxcoai.Resolver
<PrivateImplementationDetails>
<Module>{08ecab27-2c7a-4faf-8de3-9a0ec6ca63df}
_Wrapper
m_Factory
ChangeGlobal
ReadGlobal
CloneGlobal
endres
FlushGlobal
InitGlobal
ListGlobal
NewGlobal
Boolean
InstantiateGlobal
PopGlobal
CollectGlobal
RegisterGlobal
FillGlobal
StartGlobal
GetGlobal
parameter
CalcGlobal
ValidateGlobal
Delegate
Combine
Interlocked
System.Threading
CompareExchange
RestartGlobal
PublishGlobal
ForgotGlobal
CheckGlobal
UpdateGlobal
Remove
ResetGlobal
IntPtr
visitor
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
DestroyGlobal
SetGlobal
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
Thread
DefineGlobal
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
GetExecutingAssembly
GetManifestResourceStream
String
ToArray
IDisposable
Dispose
StopGlobal
ClassLibrary
Ddfqhjqensc
AwakeGlobal
MapGlobal
ExcludeGlobal
CopyTo
ConcatGlobal
PatchGlobal
second
RijndaelManaged
System.Security.Cryptography
Rfc2898DeriveBytes
CryptoStream
SymmetricAlgorithm
set_KeySize
set_BlockSize
set_Mode
CipherMode
CreateDecryptor
ICryptoTransform
CryptoStreamMode
get_BlockSize
set_IV
Encoding
System.Text
get_UTF8
GetBytes
get_KeySize
DeriveBytes
set_Key
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
CancelGlobal
ViewGlobal
FindGlobal
PushGlobal
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_9005287f7f0b49b38516bd00c03355b5
m_3b88fbb502cb4b8cb4043ea98534aaa0
m_bf7d81e46fac4b6aaebfa9d63b9d09a0
m_810dfaa033784a46aad9d04a0791ead8
m_ef7836f854ea4149b963aa6a01a96511
m_0f326a726bb64071bb986e05685b4978
m_a1566ad435ce415cae46b59029836269
m_f29ca8df90514227b0c0d2cf08a8a04a
m_b46552cf5f7b4630a17e2500191dc338
m_22086cb50f09402f815d00be570c4783
m_932437ca4b6f42e78118fb3f919e82f3
m_6dfbf59c37b940349ab5a27678a9abf3
m_f0c63f27cdbc4deb8e6bdb810e7a0ed8
m_0425674657154f7a8c4af786756791f8
m_30912858d4dd40beb4ede53d5f6dcb5d
m_ae96b801cbaf42f38b7c45240252ffdf
m_e78b933e2bd941ed9277d00cbb1df245
m_96b51d1400a94ab9bf6a2e43e6cf5f3c
m_92587047e6a942168c7eaeb1f420ff29
m_e174ce8499f84518ac1d878dba8e148a
m_9817adee7ae847fa9cf6ea10eb87dd9e
m_17b9bf77996347ed8c079423f7609119
m_fe9ab3349b8a4074a99c2942dd4e2b25
m_354eef45a92a4ee1abd8eada054985e2
m_73821a1c48354dcaa2e601dcd2ba9321
m_c66ec711bd02429c809e211406b5aa5d
m_393fa53f49b94416a12d4c84c724db5a
m_81cc4ecefe8d4fc3ada2735a2bd892e4
m_94193cb4db154a1eae776418ced0f016
m_f48fc09c94ec46ff89fdfc9eb85eebe4
m_2437e6adb0ef42d3953378df8da0800b
m_8edb7c907e0c43e3bac3fa703968d52d
m_dee8a67cdd1143189b3ef1a24c41d43c
m_42fbe876853a4dd1bbc158db721acdb2
m_5bcc5f519cfb48f4a2d71d951f408d0f
m_55fdcfd58aab43b6946a451c4be4328c
m_84fa3a9537094a4c969602ec8bcc8ae9
m_8decdf8bd94f4744b472e53412698849
m_eac798d890c44f0a9617d1ba1341aba0
m_3c941f1e7ea248339a2964610aba2f4c
m_8ed792bbf43a44c78e6ee1db86f91b28
m_e47d6ba89594408f8f470c8323c6627a
m_fb5d07e90b274ecf8a6650c7c2f24f7f
m_9e282b3f3ffd48eb8259d399ef53e526
m_af23affa15f14cd18cb286c58e4d2da9
m_b2d74b4428c64c09939fcbc5cf9d1597
m_3a097678535146ab8066e7b23b4ce9a3
m_db5cc26d66b14eeab088fb0769ae4a63
m_a6d5cc780c094bceb0795195df65b266
m_7623409a7e494447b2b3fcef69869832
m_c7f7bac1350247e5bdf65d0ef3f26644
m_2c6065a068184b4b821c9e93d28b72c9
m_354f152b95fb47c3a5917be79d480914
m_69e41b309ba14451b08669a959b6cb6b
m_d14a8e172797481aace27700d2188e5c
m_634b7a9b8bf9439e8399ff7559607aee
m_fa9eb368cef943168db235929d2c9627
m_8fe9149336944ac28ddf5ff2e8b83cc1
m_ca57c5224709411c98c1488de759a186
m_4f17123a499240a8843837d631b93460
m_1275ce7defba4b6ba02044266c688723
m_4e52ae11d85643e4981212b004527b1f
m_2bd83abc3df347aca337227a8e8f89da
m_d348c108c0a9490d82c6a1f1ed18f0e7
m_681123b2915942668fa84c0882604d52
m_4417dddaae0f482085c5dfa2d5950f43
m_a25a3a5a0dfe436a95d332e7643e1def
m_966d2e3984b2442b9b37b1559beed180
m_e3b223d0362a4a039b320f09b9d900b8
m_2212ec5f62264a70a050eef92be13222
m_06010264c2974f83b61ffd0ae0586979
m_92000e23fc354c3bbc8fee4b8af85bb1
m_c22e3caa416d49579ccc2603a5b90019
m_3fa8beceb29748589039d0c158081583
m_eda287dca819470cac43717b32d8f8b1
m_7bb84abc5f3640c593ed65f15a37eb75
m_743394e84edc454f93cfe6f52b49f299
m_9e58e973da584243bf71f17201d8d2a2
m_a2ba4481a393424b8edd2a75f87e94bb
m_4db002d3afaf47a18ad99162d9d1c5c2
m_11ff18b60544447681602a986924ecc9
m_8bfc0eccc40148a99875b26c081f3a34
m_291416d358fe45979ed804a28da66994
m_039cf46e4222474a8566b2a4244b57d9
m_463193a5314d44f89a64eee1f30384b3
m_0330d6dd1cc2420bbce971e83c0477d3
m_c049ac257ca84642851818454edbb336
m_46a22b6e6cf04274910940af61bdd038
m_375d3437978645678401eb527c1962fa
m_accfcf32856e4d5599acef1d683003e2
m_3552e636c31a4ce29a0cdddae793e74f
m_543b5103faac4ea089147a4bcc547eae
m_2c16dcdee5bb4030a43a57091fd1f6b1
m_f715a6782adf4eb49d22cf7139395a78
m_8e89f9a22c1a433f854e5504d8390cfc
m_47049881c0de4d7dbadab60eefd317cc
m_48f4113d61e74819b6516cb1688ed4b6
m_580cc69758b74e9badc7f2230e9d6477
m_784b798368fc485e890f8f94cfbab237
m_2ac153c456384556a7a8a76f591fa599
m_c627d621e08f45998a80b0bb06c40d19
m_ea7b63da925446d486358f88e17e21c7
m_cac02dcf8e56404c807830eb219f72fb
m_d7b64fcb50a34e169214a313be0a07f0
m_88dc0adde5bd44a2887c42e88b1961e7
m_37ba3ce2c1ff47f09972a345a926ef80
m_b803619222664461bcc0d5417a82fa04
m_dac21af3bce448358802cf1e09768c47
m_02f42b9f420d4898822ceaa04ea854ed
m_fe4dec9358eb48dbaf0f029b31d572a3
m_ab03ad0ebce9479d88b968557e3c3f59
m_c479081494074c69963141ba0e6002b0
m_dbc9daacf7a54cb3a8488505afba2c29
m_c6d503ab5f2d43e5b1475a524cfa4137
RunGlobal
.cctor
af5b53c29d6974bee827a1365028d4f5b
CountGlobal
CalculateGlobal
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
Fsjhubdxcoai.Ddfqhjqensc.dll
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$f2bce0de-10ac-4153-a458-bec986ccd64a
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
+V]3NJM
2Q$*y
hq9H/9
"_-l3^q
a5O/Qa
KS^:q\
9PIqcG
?u#os
)vqfI'1
+n> uL
&19<l"
|H@80d
KL~u!
%kFw}m
,`^N/L
F?'5h%
#Zk)9s!
^&Q3]b
qB;},r8A
:{_H/^Bu
&(*TiZ
m"WW~3
NEQU*&
y^8qv_%
~C)VQj
\RVs[W
o+![c%sI3
"x)wjym4
iQhP9d
S*|Bzh6
rvV17y4R
u~{ _vg
Cy9`7C
D?t7{FK}U
YBq3\C
g<!#R,
NXtUQH
K"AECT(
Q[RT|Y
G'@&'wA
7NE":5KP
D~`"M.`
navQP1[3
mb3&Tq
Qli|P\
)n2&&"
kuI%.F
P2&qe8
/jekt*
mW@.qH
J3-q{>
X@0}eO
yOXdOqy
w_7l1K
**@NGz
N.7)D4
4=FUrP;
B?^_6l
>:U'?z
4|nk]S
22H9d
KL_wD(
4emZn=[
L{Mk>z
"s9%"]
y` eB
EaVb5sSl0
]=Ur5<'m
D\FS$$A
GjqGrP
.[}Xlp
97fS#Ljj
O`qvPE
wBVacdn
oZ"\Ty:.
&9mfK]
z9:n_0
B~Ht0?_
1*g2!F
l}m?\^A
7#=\99
qF.aD}y
~G,EH'p
j]&R/E
j n742
;xf'p}L
Lk:P@(
t/&qKSO
B^Gj~3
X~t^pcn
Bgb#f3p
r6n:M4>]q
l9Bm1f
uNk8%;
k3:pJ.o
9W{|[;_q
S7=kKsZ
['Cf1\
S|Am#
u-vj8C
+?,qb
Y{P|$so
qu6F^N~
Nue?#9
/TpK+d
N}du :2
<z8Ty
n1<n=cu
^fbMGI
FNk$Ul
V,V0BF
d$pj9a
x8t%`GX
>qG]8@
)1eO=V8_
Y`j$$LM
KW0N2,
}"X> WR
a=x3R\#
o>2R6C
n:D=|7Z
Y|Km'.
vCw?r|
R@%Z Oc
Af$rb?
7r>k=:K
1rqBg!
Ubj d;
BW8YK
SXa_D
6~~Qj/
+YCv10G
"EJKF%
}rz=`\
!Y4Q`4|
AP9<9^L
?:v4wrS
5V^n"a
6(3CLD
o$XJrNi
!Ni GA
qHV>9KsD
LW\`fabke,T"x#)7
" jb?O
,17G%5
bu*O}kYd
[a-nt7*
;.70YM
F-5~&g
a@tt3;
/vKO^G
'~I3?}:
Wv,WhDf
c0_dPo
CFhpsK
`kP|,,<
%#E$Mi
rh#CC8
TOfE3T
wCU=70
@wzOes
Y;/^_(G
rJ6#j-p:Lv#
Q%aqdl-N
mcV3t=
>H_1J
LBcG`I
Ta"P&=
#[ce&a3
pW5B|e
]{kZE
\bx-^
+lopTd'
_'KW1G
*@0[Xs
dG.q_
`u}#@&
/O,]zW
?lfxk'
M8c("-
QmF iV
dMlkXt
jw,T~G
h+XOyM
I)kVJV
PQa1zsH
kF6cu,
/Bo)a..
R1(]?zWZq
RbfPXWD5
y"p,;tw
{dJ?2%
1y6!1?X
_\>#Q0
x?/Xuy;.
J}pen0
\MBB_mY
P9y3/S
7(b[]*W
$0EvCo
/16znd
4{?!IW
v@-q[j
]ESi~v
A+q/zyg
:V+B!z
Tmd|4^
7B{Tgq
u9pNOR
Z[9R,h$
57kkE(P
m_NvC
zDvAMD
^M &HW
/WJ G{
Vg+Hu
<OO!S2|:
$[BU6&8k
>/7RGE$
&-frZ6
H^2[h_
Q}4BT-
mY/a]SX
e)_q#1z
,DVdZV
,Z=mrU
hJRH6=(
vgI,mf
CSF'*z=
1x;6We
=xnlePRp
BmULR<HY
D}d8^!Cs
,)&o:
/L`rP
d#tXot
)Oq!qv!
7X.S{(&E
a^<k\7
[I]dv$
[fn&o+
=QxQ_s
?Ns=>av
Zj|-i|)
Q<7zdiC
uW@Hst
7uC?(:
x+/MUZ
..X1*
B"doZ*
=LrWQO9D-
54|Z)S>
NfF%Ae
mU2c3/$
{;dZH
])si&h
XzF}r@
AbSl/{
a~Q\cO>
80q7h6
& !bvB].8
yHzD/{
@}YlF,
kRQye_|
jXM)`Z
W0Ya{f
_0Ro'%E
mB'ZDP
?s(+>e
_i9)iK?
0>r {\
_CorExeMain
mscoree.dll
=4IDATx
#G)E4A
8E\QAi
'$]9J)b*
MrBZBB
<G&dV8
)PQiUX:
msG&@i
&DpnXR^
|&j*B!
=k=L2&6
|<Y-Et
lJ-~xQ#
@}^+{*
ys?_?9
UJ]$l:
;t?M0;
H?)g-8R
=g*n=wZ
t$Bl{C
'O*\P~`
="vH)p&
fxh}'b&
=F?H$$
Ah+iG^9BW
x,ok`W
al(%@"
[LT22f
22GXUS
n|xVy8
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Fsjhubdxcoai.Ddfqhjqensc.dll
Ovpcioxfzq
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
IMG_52_67_21_33.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
IMG_52_67_21_33.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37056040
FireEye Generic.mg.becc9c4709bbee07
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.MSIL.Seraph.a!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00577e181 )
BitDefender Trojan.GenericKD.37056040
K7GW Trojan ( 00577e181 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
Baidu Clean
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABHY
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37056040
Emsisoft Trojan.GenericKD.37056040 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.821
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Crypt
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
GData Trojan.GenericKD.37056040
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CF721
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet MSIL/Kryptik.ABHY!tr
BitDefenderTheta Gen:NN.ZemsilF.34722.sm0@a46@R4o
AVG Win32:RATX-gen [Trj]
Cybereason malicious.4fa9fc
Paloalto generic.ml
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.