Static | ZeroBOX

PE Compile Time

2060-10-12 11:37:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00018f64 0x00019000 7.9657206856
.rsrc 0x0001c000 0x00008200 0x00008200 4.31085691799
.reloc 0x00026000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000236d0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00023b48 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00023bec 0x00000412 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00024010 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
~b)d?
Bx'yCgG
g$%|$@8l
$jLAv3H
j8x6u0mE
(bB@%l-e#
b>R#HP
@#4t"6
"dRBP3
p>M$ ht
<$]pq6
Fp_>pN
S9$(1
@f# 1!
,21Q2
LTVqq&df
y5TR|P4
IFF,e*5
F4}zY;
4j-fN94
l-J2fU
URQQQ7
F[[[w/
i:p1SY
Ya:<_g
5PW967v
nYz>l%5?I
?.I:%p
vOeaN}
YWugg%
0Jasbu
Z,>|Ib
=7v^0h
[}Ej"7
i7nhYn
vN?rMy
.<o~gC
Y7o&wvv
k#w-v5
(i0,0PD
|d#-=GbH@
5yw(yz
EmzR~d
?zBLbH`~h
*'PwCo
3l^K+Y9
YT^yJ'W
KpAy!ko
=Yz#>4
vvvfvvvo
"1vDEQ
zmwvvvfvvvw6]
QIY{}&6
|{dkT(
fj]O(n
^j]@n
{mq]6d
L?08 $
K<}%b#
"hZJ*=
qopES\
cF-? )
.@h!rE1
6g!vKD
jJmm)hT
bfEbc:
!,`n5.3
F5Gld'
OZOwf-
me8\^1
W6:95!)
6:Ni4S7
>X*tY-
jrF\n-m:!!
67~8\;?>
;v<6q
a'_-;s
H6e>S>
n~))X5
oUjQh_f
l?qmQU
._27d_|
?!}bJc
Eh&oGn6g
cj?Nd&
xRmPt+
ro7MZ_
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
b:2[Z[
fuv+W2
tO}:nY
x"m +&}
NGawQz
s|eeXz
^Y|u/#l
0b]imxa
#d1'7_
E#ip-_a
/;QyEt|
+`NX2K#
_@Xr{I
P4EQ5o
CfzBnK
'~GOa9
$lMSym
Z?]73G
^g3[u/
6"1^wp>
So$ ?3
tnAlv
^GmFQ*w
\1V[cv
zh@Bwg
'6]F_Y
Y{Fi,S
qJ0aZz
vRbze,
:3U43!J
dDkIn*
UBg},M-
R(:+mc.
tFxAO?
Q'6<QB
yNzMD8}
Z7+|K9
U JtW*E
6Q%'[I
F14Z5Z
I\&>%N
_8[%Oe77
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
Dictionary`2
program2
cmdcrypt2
Lsggmqimbbu.Lsggmqimbbu2
<Module>
MethodA
MethodB
System.IO
Costura
mscorlib
System.Collections.Generic
Thread
isAttached
Interlocked
costura.costura.dll.compressed
costura.bxlrwauorp.dll.compressed
LongRunningMethod
method
source
CompressionMode
Exchange
nullCache
EndInvoke
BeginInvoke
IDisposable
Console
get_Name
fullName
GetName
requestedAssemblyName
WriteLine
Combine
culture
Dispose
MulticastDelegate
MyDelegate
myDelegate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
add_AssemblyResolve
cmdcrypt2.exe
System.Threading
System.Runtime.Versioning
CultureToString
Attach
get_Length
EndsWith
DelegateCallBack
AsyncCallback
callback
nullCacheLock
ReadStream
LoadStream
GetManifestResourceStream
DeflateStream
MemoryStream
stream
Program
set_Item
System
TimeSpan
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
destination
System.Globalization
System.Reflection
set_Position
StringComparison
CopyTo
get_CultureInfo
Bxlrwauorp
number
AssemblyLoader
sender
ResolveEventHandler
.cctor
Monitor
System.Diagnostics
FromSeconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
ReadFromEmbeddedResources
DebuggingModes
GetAssemblies
resourceNames
symbolNames
assemblyNames
get_Flags
AssemblyNameFlags
ResolveEventArgs
Equals
Concat
Format
Object
object
IAsyncResult
result
ToLowerInvariant
Lsggmqimbbu
ProcessedByFody
ContainsKey
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
ClassLibrary
op_Equality
op_Inequality
IsNullOrEmpty
WrapNonExceptionThrows
Microsoft Corporation
#10.0.21376.1 (WinBuild.160101.0800)
Microsoft Corporation. All rights reserved.
&Microsoft
Windows
Operating System
$e7b5f3b6-8746-4a5b-9ada-26965f6eba3d
10.0.21376.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwwwwwwww
Se%ae`
cCBR_p
RRRRP%
CCCC@40`P@
cG?CCRRRRP`R
4qaCCRCCCB
pqacG%%apppppppaB
prRRRPa
wwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwww
se%%%%% R
u%6RRRRRPp
wwwwwwwwwwwwwww
wwwwwwwwp
wwwwwwww
!

((((&&(&&&(&(&&&&&&(((#&&###
*)))))))))))))))))))))
eIDATx
""""""""""""""""""""""""""""""""""""""""
'Px0&D
XXX8Pvh8v
],//cuu
n<DSbb
!KD4)#
NDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Executing method A.
Executing method B.
num : {0}
.compressed
bxlrwauorp
costura.bxlrwauorp.dll.compressed
costura
costura.costura.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Microsoft Corporation
FileDescription
FileVersion
10.0.21376.1
InternalName
cmdcrypt2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
Microsoft
Windows
Operating System
OriginalFilename
cmdcrypt2.exe
ProductName
10.0.21376.1 (WinBuild.160101.0800)
ProductVersion
10.0.21376.1
Assembly Version
10.0.21376.1
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Bulz.501896
FireEye Generic.mg.94d266e338b8c8b9
CAT-QuickHeal TrojanDownloader.MSIL
ALYac Gen:Variant.Bulz.501896
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.MSIL.Seraph.gen
K7AntiVirus Trojan ( 0057d9dc1 )
BitDefender Gen:Variant.Bulz.501896
K7GW Trojan ( 0057d9dc1 )
Cybereason malicious.94fad5
BitDefenderTheta Gen:NN.ZemsilF.34738.im0@aCzDHRm
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABJC
TrendMicro-HouseCall TROJ_GEN.R002C0WF521
Avast Win32:KeyloggerX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Kryptik.b45208af
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.MSIL.Seraph.a!c
Rising Clean
Ad-Aware Gen:Variant.Bulz.501896
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0WF521
McAfee-GW-Edition GenericRXOT-PX!94D266E338B8
CMC Clean
Emsisoft Gen:Variant.Bulz.501896 (B)
SentinelOne Clean
GData MSIL.Trojan.BSE.XNY6ZA
Jiangmin Clean
eGambit Clean
Avira TR/Kryptik.xemiq
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Tiggre!rfn
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Redcap.C4514266
Acronis Clean
McAfee GenericRXOT-PX!94D266E338B8
MAX malware (ai score=100)
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Downloader
Panda Trj/GdSda.A
APEX Malicious
Tencent Msil.Trojan-downloader.Seraph.Huza
Yandex Clean
Ikarus Trojan.MSIL.Inject
MaxSecure Trojan.Malware.74570710.susgen
Fortinet MSIL/Kryptik.ABGK!tr
Webroot Clean
AVG Win32:KeyloggerX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_80% (W)
Qihoo-360 Clean
No IRMA results available.