Static | ZeroBOX

PE Compile Time

2073-09-09 19:05:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002a744 0x0002a800 7.96671266199
.rsrc 0x0002e000 0x0001ca54 0x0001cc00 5.79782514922
.reloc 0x0004c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x00046270 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0004a498 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004a4f4 0x00000374 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004a868 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
AX z~spX
b @\6~a
f c/:
AX z~spX
b @\6~a
v4.0.30319
#Strings
9011.exe
<Module>
Wrapper
Object
System
mscorlib
MapMerchantMap
ValueType
FactoryTemplateFilter
.Filters
StubSingletonResolver
Ertspezogztk.Resolver
Singleton
Ertspezogztk.Wrappers
RefSingletonResolver
Ertspezogztk.Common
ContextListener
MulticastDelegate
WrapperSingletonAuth
Ertspezogztk.Authentication
ValueOrderService
.Services
<PrivateImplementationDetails>
<Module>{821a06f1-0578-43e1-a974-33193c02cffd}
FlushStrategy
ReflectStrategy
ComputeStrategy
InitStrategy
MapStrategy
m_Object
policy
SearchRequest
RemoveStrategy
InsertStrategy
i_counter
CalcStrategy
ConnectStrategy
no__init
PublishStrategy
CalculateRequest
Boolean
ComputeRequest
InvokeStrategy
ListStrategy
RestartStrategy
SearchStrategy
CreateStrategy
PrepareStrategy
listener
NewRequest
IncludeStrategy
Interlocked
System.Threading
CompareExchange
Delegate
Combine
DeleteStrategy
Remove
DefineStrategy
CustomizeRequest
CompareRequest
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
ViewRequest
OrderStrategy
Thread
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
LoginStrategy
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
GetExecutingAssembly
GetManifestResourceStream
String
ToArray
CopyTo
IDisposable
Dispose
InstantiateStrategy
ClassLibrary
Ntmbgyvx
CalcRequest
ReflectRequest
IncludeRequest
ResetStrategy
config
RijndaelManaged
System.Security.Cryptography
Rfc2898DeriveBytes
CryptoStream
SymmetricAlgorithm
set_KeySize
set_Mode
CipherMode
get_BlockSize
DeriveBytes
GetBytes
set_IV
CreateDecryptor
ICryptoTransform
CryptoStreamMode
get_KeySize
set_Key
set_BlockSize
Encoding
System.Text
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
SelectRequest
get_UTF8
FindRequest
CountRequest
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_c728747278e0473089aa5d986217582b
m_4f8674959c4b47e0a8a166e9846370b0
m_a141023bf99e4c3cb5a11c11138e9d4a
m_9efb43da050144e5af78ea17e616f536
m_f9a67be00f844cdba41730f37d8c37b5
m_c532f7975013484db4f22e2e48ac7d2f
m_931e6d1a6eb54d9e808f375b2eb95794
m_20f4b5b1241047ecb0a34efe7c192094
m_7c6636c7dd61484d9342a5d47320e6ba
m_41cad00c3d294910aa21437b99829e4c
m_1920f0a2869c460caaa15e5c8435532d
m_be47fce87a7f46c78478852bbab7aed8
m_7a8c5234d2f04d2a822ad1196be8fb4b
m_92aaa445a7744f769a95274698cbfa74
m_58cf61fa2e0f46f09fa88afbd7a63059
m_cc8689372ff646bba5447b40575a7df3
m_33b67d724c8d4790884654d6e4c98f99
m_60458c80c6e74939b1d2f558754f09d5
m_aa7214f609524a44ae83d14c90477b12
m_871a12ecbc994b51ad3bd96d3801c5ef
m_b81b9ee60c4c44e89d3dbf1c9686cb59
m_3ae81971f44f49ef95dd771e6fcbfc4f
m_44c5ffae1f924795a064a8e85b71ed9b
m_5c2a5947d0e74feca5a5d459511bf69a
m_f2473ef40f874f168f400e3aee74c1b9
m_1277aa19736642febb0a8e92ac85c19b
m_dbd04e94b6a44b50a1726645a75c991e
m_96cdf9992d924f5797bed145dd4c1572
m_3a500fb911a348218be09daf703c0fb2
m_c05eed5db2b64f58a016b2bb52254fab
m_aa6b60b98cd543fabdd87d6c2d2efd20
m_8db6b8fd8d764dce8dacee3e0db5811d
m_2aa29c14e42242e3abe8587432bb90b4
m_c2d472b80c76404f83ac88f47a2b065e
m_6dbe4001fb0a4319a3fe4f346d897918
m_992adac9112548d5aadf7f8622c515b6
m_56fa0663277b4224b3dd294663102b72
m_cb1b6cac9c674ff08bda0cbca4f03122
m_07aafddd9b55425992bebf69dce3f66b
m_ac331ac525214ff9aa61ae62bcb5eba0
m_707401cc4233494f849ff10917643418
m_09fdd63ca8ed469eb2a1d1b4c3c7fe6c
m_8222d6a205a84cb7906ee0ce767f6231
m_e2d22706694a47b7ad04dde4ae04e2bd
m_e5ecdd0d81bb42029dd70873136f61c8
m_90db090d58d949b798a1a30838e68443
m_b95e510bdbd943bdb7341c64cfc2ff99
m_c661fc3f52b7412dae9be4a1ea55bc12
m_4df39fa0c79b4d8a9d839916c6c25b5d
m_03dca9e7e71044d5af8627070ee599f9
m_646a1cbed0b94fd88d9aa7e476a4e293
m_90d6a63433e240dcb74c9b1f19fd0cc0
m_1e09a78b9f954d18a62d630b35a80599
m_3d6b68d2859e49109c893e38b17af71e
m_0bf45536fa3a403292c44dc23f6ce945
m_1ddc3e857afc42138d7c693d5d3f20db
m_c440f48a1ab5455bbf5242786fb70b9c
m_c87d668874354a35986bacc5e8079d30
m_4b684aa1a5974095a566380890f4ede5
m_84dae471a2544a7b947a52a40eaa8424
m_998053665cd04886be5da4e233c1cc26
m_db01ad10f8804c81bd78778c1873887e
m_d743e75d515b4070afbdf14bbc5106f7
m_8b632ed0688b43eb8f42ed6c21ba3552
m_00a3e13353ec426aaec13334732692d7
m_70234067c6db42b593da076bc8ae36f8
m_aea84e63f62740f486ac5632627b9043
m_f1806a74d4a24396b7141864f75b9633
m_5b9cf7072db34794997250cbf4bbca74
m_3c8577789d8f4422ba78545f6ef00e7c
m_62d5c87b8181474696334a1da2392f36
m_03bee815ec9446118f010d07e4bb3ee1
m_b34f3b0e400646d1ade9f9ef11fa29ca
m_dc5287c5b64348f582f378c32e164933
m_30745d19548e450887a1b1abb0f8bdb7
m_2b88c4d710f1466aaf1e9829eb049e78
m_a8a8cc51e8154df897d58976ec55258c
m_dff01c9566ed48af90aa43c86f1b25bd
m_3f307b0aba194c40a06d9c43ad5360d2
m_da80d26dc04b48caac3684a419af4bd5
m_df7fff69c24343a48a09c0c8fce74f72
m_41e737a8725a42caa97330297e453480
m_6a58e9ee589e42b2ace905148a4b080f
m_31132523bdb341978b28e228bc915d98
m_1f1b3117b8ad45e98e351380e0c4522f
m_81cccff61d3e43ae9cb54e1222e7e28a
m_4751b2b9aac34188859860d1dbb02397
m_f825d117be2144dca9ed1b45988a34d9
m_817aca1b8f7e48aca609c4c44d3bd0e0
m_86026a074c3c452186b5f7b6ee93b55f
m_9a4a55e4499c4b80a09fbc5659076050
m_c39cb164f96a4bc3a079e1285940ad14
m_1beca60ec5d04cfbbfdc0d97db012f03
m_3e9a347588c54d37aca1a1391c703098
m_32bdb284540b47a89046a67626679fb3
m_a4e64b3d7fe64e0fa3467cf266cd0392
m_2d868e8fd772482f9db47dff3054d504
m_35aeacd5af964199bfcb4858fa864f85
m_80d22385821a4c659b204c6fe1f79afa
m_b48891a3f5be4ceaaca5dc6a0e35e3f1
m_95dc0fc4b7e945b3a134ac6ba90d61fd
m_286e3d3932674e39a8d7063fc2ac174e
m_b12542cccf7640f4ae7ce3698b711461
m_4bd40d7769734f988164e29b1cbacb5d
StopRequest
.cctor
tb6d8fab3117d48b59bc9ec84fbdc8797
SortRequest
CloneRequest
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
Ertspezogztk.Ntmbgyvx.dll
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$fef6e1cc-66bc-4328-a1f7-ce80373cce9c
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
y4cR7'})
F8&lkz
ia+!1$
]NxS<Xp
1B"}=+'
+D&^ruA
BpjYFI
CU%:_z{
35k S,(
Ku<U64
;iafQp3#XY
,F0>R;pE
v=.@6;
?A fYB
L;]!'>
A|wR60
[an7GX
h*PDED
U:Dn0,9
GNDSt3
&G70-!
w!CXga>
Y9%!qQ
19._^C
n5u($8d
q<#>=zF
PbN[!F
i:T(baC
uI-\ r<
@VX,J-
Bm9<!L
59S]|K
drbAd)=
G8y}Z{K
(y^WKm
-gcc>W
J&8'}g
Sk#oMo
;|gD5~G
Rm$^K!
>+}7Ga
_1:S:8
)+qHb,
xP(mVrj
looN=pH
u)Le@Ne
a0PI(y13)
&[(,(y
17@ydK
zOcL;jL
:z><3
AqaVcl
7-E6D[
Qi=^RD+
w6HzB-;
*Sm* ,<~Y
"9 z;;c
DQ" E:
#VoNI]p
<sS^m?@vK
{ZEr9f_
rOHNiM
H#:j[y
R)RLBST2
]j|l&&
FR_WQ"
gLn2(I>
F9_t^]
T}7X}!d
|Qu3&r
^lgo+w
->80FZ
z~rK|t
<%31E~UM
#C3Yrud
j~SJ//i
<e;"5bYM
EG<BF`
ZX2"FHFs
@'& hDK0m
(!FXdV
Dt5sCz1D
C9/RoY
<4U4r-n
)vlEIxP
%'fy|2
biITDg
*@O_et
`s_(\+9(
t.5Bm/
"U>GsL
>Mw P3
PtUKPH
.,Kl#&
PO41LcE
}+[D+z
n_$jmH
21tw;A
KH v,"
ifD7*-
ia1ed(
i;2gPz
Yvx*d'
=~*S9~
lAhP0h
?o3@Wct
CA(2o4
3v^1nA)
?s5N& ?
0=^V}8
;t_5X%RG
+(fJj,
mJ/JaZ
.U}j:!7
N{6ws7<
QjCHgUK
70JAhy
1Ne@sD
A60*\Wi
p0#-C'=$
qgyUCy-
J`a{FX
I^as"
+Rq+K0
!3FEx >
8ydDR3L
tSY?~(G
Xlq=5j2
>y@9H2
\5:AnvD
i/{ctW
$=Ih?Z
^&b]i|
167A=!
-bA^/2
NlRXD6
L(_:&
b)Lu4,
c,#Kpa2)!
>JV(#<O.
Rs!wQ@$
!ONsIs
{uj:J3
iGJr&H
PD96V(
wnsI;B
>9{^*Kg>o
l0]cOd
r[X'9&
l)E+:W
atm}+L
nQn>"dhF@
grMCDE
t[|~Mt
5+%B4A
j,2BE[
^KYO\m
'5U7{
m?4warUs
Ux;SG)
TAoO`8
!F/ ,l
\%rq=t
q<@|l1
[B<O~"
kX?m@u
_.8;3i
W*G-*s
ah|f`,
7,wn@+X
:.ht=[
~i'V*"
d(S?z(
d1w/Q,X8&
=xfo;[
=V'1mV
3<Mq(T
$OlA^>
A@ Xn(K
X6z%3V
4}9P?[?I{
OA|b=K
Sj>cX(
#<{sV,
UcoiXtE
'eNU8F
M<[fij3
2)Eu;c
[J+,md
><%y`xyT7
v\vrW
Wx3xc#
5KJh0L
]k50\$
KC7Ph(8G
E]}JW3
YuHh(u,
?5LAa^%
+z~PO4
8@{Iepx
*cr(yA
b!*57<
s`J\Q.dN
U-PD)'
Kzq:ng
#&KO7A
'eDYuhQ
%qTt;D
(WU[Z)gfC
&C8"==
/2?ppo
g-k)J
saGuG+
{bDX6U
8Z?Gk5]o9
uzNP7y
nmNSK5
:+Cj~L
j+ +3<w
rwHYEmb
8H^uQe
4(JjA|
u|=Y`h
KIE}f,V
?]!(p4M-E
nWW07K
EY9P1s
k~'4CA
j #b48
W~MA{D
FF;pY[
=L_H3"N;Q
n9le;X
#(>^f
4\.@2b
4+;1QH
n,v?G^
W-N.t|h
Y,arwt)
v u}D_
90p,:+
@Pn3 \
q(InFm
tcMMz,!N
58+g:4M
*Xw+[<>
6+Dr-{
>y)c@ie
Ts'a`*rczP
s"(r{V
m;>>,\
]{]| 3
Jmv-M&
9+UH}}
ZIF(+Q
.T8KzSU
,~E6FHG
ZZ|)J9~rP
069OP\
bXM*+[
"AG!#h`
aXh<cB
>.ohGE
@)%||8^
D&^db7
l9U'5{WI,%YH2
UUy58*
g*fmyx
B^kf3p'kn#
^RAAyR
4IG=`m
c.5m.&
C)9giE
So* |M^
l$ gfFu
C)#b,n
dE/<^lC
@7'Z`A
Dg5ZA
[1ztrfg
UcC6<Y
1R![0?
Q[piq|
cTcrP5
<>'eAa>
vtY[:)
_CorExeMain
mscoree.dll
=4IDATx
#G)E4A
8E\QAi
'$]9J)b*
MrBZBB
<G&dV8
)PQiUX:
msG&@i
&DpnXR^
|&j*B!
=k=L2&6
|<Y-Et
lJ-~xQ#
@}^+{*
ys?_?9
UJ]$l:
;t?M0;
H?)g-8R
=g*n=wZ
t$Bl{C
'O*\P~`
="vH)p&
fxh}'b&
=F?H$$
Ah+iG^9BW
x,ok`W
al(%@"
[LT22f
22GXUS
n|xVy8
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Ertspezogztk.Ntmbgyvx.dll
Catbdgnq
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
9011.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
9011.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37056046
FireEye Generic.mg.ed4a90d8b23e1ca8
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.Multi.Generic.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 00577e181 )
BitDefender Trojan.GenericKD.37056046
K7GW Trojan ( 00577e181 )
Cybereason malicious.c3388e
BitDefenderTheta Gen:NN.ZemsilF.34722.rm0@aKl9!dm
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABHY
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.37056046
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.821
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Trojan.GenericKD.37056046 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37056046
Jiangmin Clean
Webroot Clean
Avira TR/AD.XetimaLogger.nvufl
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Agent.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DF721
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
MaxSecure Clean
Fortinet MSIL/Kryptik.ABHY!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.