Static | ZeroBOX

PE Compile Time

2021-06-22 06:15:34

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005e821 0x0005ea00 7.87123000034
.rsrc 0x00062000 0x00029f13 0x0002a000 4.26300418843
.reloc 0x0008c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0008b4bd 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0008b961 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0008ba21 0x000002cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0008bd29 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-2+;+<,
+0+5+6o*
+V+W+X
+&+++0+5+6
v4.0.30319
#Strings
nite.exe
<Module>
mscorlib
Object
System
MulticastDelegate
System.Windows.Forms
Settings
Cvuyvgtyfegdqht.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
IContainer
System.ComponentModel
Button
ResourceManager
System.Resources
CultureInfo
System.Globalization
MemoryStream
System.IO
EventArgs
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
Assembly
System.Reflection
ResolveEventArgs
System.Drawing
.cctor
Culture
Spotify
Default
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
EditorBrowsableState
.resources
.resources
.resources
Cvuyvgtyfegdqht.Ceqpzkurvoomnzldfpdijoq.dll
Control
set_Name
set_Size
set_TabIndex
set_Text
ButtonBase
set_UseVisualStyleBackColor
EventHandler
add_Click
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_ClientSize
get_Controls
ControlCollection
add_Load
ResumeLayout
SuspendLayout
set_Dock
DockStyle
set_Location
Ceqpzkurvoomnzldfpdijoq
ClassLibrary
String
get_Length
Thread
System.Threading
IDisposable
set_DialogResult
DialogResult
SymmetricAlgorithm
System.Security.Cryptography
get_KeySize
DeriveBytes
GetBytes
set_Key
get_BlockSize
set_IV
set_Mode
CipherMode
CreateDecryptor
ICryptoTransform
CryptoStream
Stream
CryptoStreamMode
ToArray
set_KeySize
set_BlockSize
Rfc2898DeriveBytes
RijndaelManaged
Container
Console
WriteLine
PerformClick
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetDomain
GetType
InvokeMember
BindingFlags
Binder
GetExecutingAssembly
GetManifestResourceStream
MessageBox
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Encoding
System.Text
get_UTF8
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
$1f7c1618-b5ae-4be5-b678-de720b523277
0.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
T"_u}\
I#EC^%
k0skaa
!Ek-fy=
hLbZj0K
#1Z0,0
<%oX2
xW--eip;0
4jORbMhG
|#ado}
$S0sjaa
K{%eha
gE|}??V
v[?vS/
An=#%=j
c36j7f
D$z3bi
7$;0kf
.7OPd!
!G9_\QJ&
r4r.6'
=?O {uf<
ua)nayo
tSR#`Zj`n
=%i{]B
$=Y%pe
((((((((((
((((((((((((((((
((((((((((((((((((((
((((((((((((((((((((((((
((((((((((((((((((((((((((
((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((%
(((((((((
(((((((((((((((((((((((('
%XO#((((((((
(((((((& #&((((((((((('
((((((((
((((((&%;0
((((((((
(((((((
tdWLHEGKUay
N ((((((((((
(((((((
(((((((((((
((((((( C~
)(((((((
(((((((()
*9J[fqxzysh\I7
!]vA ((((((((
(((((((((&&%
,%(((((((
((((((()
%&((&&&'#
.$(((((((
((((((( =
((((((((
(((((((
(((((((((
(((((((
((&(((((((
(((((((#/o
((((((
((((((((#
|bcL3"
(((((((("#%
.!((((
((((((&
!#%%%'%%#"
@((((
(((((k
gP@1+&" #)-2CUk
}#&(((
((((@
`%%((((
((((@
%(((((
((((j
#((((((
&((((((((
((((("
+4DMTZ]\YVJ@6*
&((((((((((
((((((((&%"
!%(((((((((((((((
((((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((((
((((((((((((((((((((((((((((((
((((((((((((((((((((((((((
((((((((((((((((((((((((
((((((((((((((((((((
((((((((((((((((
((((((((((
////////
//////////////
////////////////
////////////////////
//////////////////////
////////////////////////
/////////////////++/////
////////////////+5@,/////
////0&
"&),,,+&
5+/////
////(RdUK@412:HUj
t0,/////
//// u
xT$%,/////
/////+E^p
E3,/////
//////
(3<BA7+
s)-////
/////,NK/
+.////
////#S
rhbacir
f;+/////
////%P
/////(CYhv
KeO(///
////.
+131+
///.1clVI9-%"!*1@LXj
///(?\my
(/////
///(&1;=FDB8/#
&-//////
/////-,+*((*+,//////////
////////////////////////
//////////////////////
////////////////////
////////////////
//////////////
////////
2L@<?EN=!
73'#%*;RV+
4MQUSOG*
PICDKT
,:BJHA9)
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
"vSk!=q
@Dh,>=q
e&M<2B
z_~Tt3
>?W8u
qqqLxyy
qqqLvww
qqqLqqq
eee#stt
tuua_``
tuuaVWW
kll7xyy
vwwvlmm
eee#qqq
tuua_``
vwwvVWW
tuuaVWW
eee#_``
vwwvqqq
eee#lmm
eee#_``
vD;(F$t
MwwBc5
Tee1:g
iR\9X;
x<{_jmDc
p6_|r.
u^}xg}
Mpzs02
lpMB]8
lV|ir3IQ<
;sE<[u
O9)>JI
&&8T=7
AN2A1x
.HaU&#(
s]jear
qP%n/>
>4Wrkm)T[~
TldG>Vbu
c5tG<s
b^0q\h(/
a'!-ag-
v3tlGC
d[=L<~
#O94
DQC_`+(
0k Nbo@
MU-\xl
zMM_,l
1'J:<wH
VDg'<2
'ldsN w
A'lKL<v
Y-pl5
MQ{F~G2)Aey(|
C`pE3P4
vdw7U!
YS1S,s
m~srM5
zV{73)
/UjX)F
QxzNq!F^
~&Dc41
T9O^&
.K|U0z:)
R2)sd3
&;&p0G
=(/LgxS
y%Zw~(
/G!h7>
al}QaM
n~^y$
6s,-
Jj]QSD
B_1$^^u
ft+~n9X0
UC|<jks"
$pE\N.-i
MqTu$u2[1
z.x'L!|
rEec*9v1
w% >,Iz
v:kILL
~[7ZvWW
Tt.B6/
sroDli
`TY_F
`$a;|%.
#PIaUi5
8Ji+p]
mM5y1!rvu
zaK05\:.&aY?*$f
_UyVsZ
5v]_rF
@BB[%q
K|&|2m
}'aM^C
KeQ,2\ts
h(O(c;
%h??i$7
1jGp@#
>1Ri6{
H-ihU?
S2Ahf6 z
&DSce*
Z>Qdxl
i6U{u*
c">m;'E
Z!%QwkC
P7(W~TpO
yU`&A=
!ygU(-
bO+XkI
pz<@@*
`[o5vf
y!f&}f{w
[G_C;K
s.;qs(
)lyuB)
qv--Pw
O9}",@
!.{b:&
U2l3Ph
#4l33#
Zu~")!
ywYwW[
!FBjt\
uCbu(6po
?6b_m`
+*gv*9
]fWlH*
|54uzYc
/q*GH&
]:#rup
/S$u)o
tE:k:.`
]ObqNy
EX m_g
zg^J?2
f]PtnI-?r~
|"j@ts
_+nd&Uu
W@O";d
lhgl~w
P()%\+_=^D
mlB2j%A
uv}w7w:
0:MLMT3
Mf:Y/!gHBYq
?Aod9e
w17 CY`
zl:noW
KcPY8)h
y;X/uTi
VB;G~["
9FmPH61
ORO(UqZT
bpcb7z{q
LN,[`N
1!aTWx
U1WO#?'
]u#HG5
5W'&J8
k(Gmoer
)kI=4U
h`46h:z(
'A:HAR
]Z/)\A
VVS[90C:Z\
M.\%AsV(B
(r>V6k
fS8zEVAg
^nz"bO
-*7AQ*
8+GZh
,bRwr/,av
9(^'_=PgY
}cCnIydK
;uWR+w
s$c3ZK
Q7E@_}:
t$PY$J
P6XW*}6
OWh^U!
OTK^Uy
Oy)$`H
X@:j'5
1Y[N[;
_gV9c8
bJ!9tF/
tsJ9Q?
^$ y.V
5-Eo?gq",
Qb)M*DI
~WVTKt
]B{l~8
<twjo8
@mT:^d
_Sb%R
]\SjQM
;VY2L~
icPA$Q
q~.x-:v
q(C<cq
A4}M(~
<C[.}e<
_Uq~Bq
;/JeU-
51;{KJ
?~H>Qc@m
X(A.`7
`L6rft!^
`bKIShx=5
rX8%CdL
#ge+iz
8~P">a
bYK"7p_
Wq jzT5
@~V~*]
V>>C@M
,2YI#v
y[l_5wI0
j21:o\|%
}dRIKY
M#0rB{
uM`5rY
h:X5mb
aV #YTZF
2Ti`!~z1
kwm3GPL<
-G)Lcm
'!2Z=<
9DH;z
0n&p%6[u
!"do_f
7%8ZH09
X{;yc
^ib27Uf
}l[{;u
JJiAR
/9~E_g2e
N,!ddI
[d'Vb-
+mW7&
Nnv!+f{
VdF}fJg
K4q_Jv
>Kfx{p
M/)IDj
B!.Rz9W
Ig2tE&
+G;8~3
&5xO(F1
:S,8N$pV
V/nS[9
u w"e1
XA*pr
"Hta;~
Qh?u5s
%nD8wk
)tr[Jc
`M8HF
4fZGB!
PgLr+M/
x^F*[D
,m:]2^E
uO>EZ,
&R^:cU
!,,9vs
<RA?"/
@k;{=c
SFd5++
"xNQx]VM
'+WhsFp
<`5QJYG1L
]OFIN]
s0=r0qS
Vk*5;e
J}GxSX}
>\+eo\/
p&@@\Y
"fpTgS
'MZ"SOy
d|a]x&
.5nc<v
[l)ByX
SOFiao\(
<: rB3
TED|(6'
x_Tl}j|
P^r04jR
pi\`lG
CkEx.fP(=
PgC/|y
~QWu@8
}QE o@
$5Oa8WJP
izT+&\a
$}Ts?X
Vv1pagm"L
v>n"3t
He1U6t
9q&=L>
A]-zZ4
<1Hr~.
!<>LTS
H!P;%H
He^2ti4k
?/jwob
/o/-n5
lU@yWH
yqpT!V
]1L3>T
-L(!B
"~pNm=
\iCiY:go
ov,'0q
He\~6o
wF!&)%ks
3J'{y$
="yym2
|JNwgCe
r"*|Ws
_cr~Ir
eV7"x|
Ve1K|
B=k?YK
H;f7]V
#?"+i8
#^)=Tb
*^j$dW,
v]Olv_
)DjwE_
`~oJxW
AV/9f.a3
'pT6{B
9*j\ Nj
*Gj_u5
A$%~&tU+
}5_~WX
-YRzt
k95i)j
YmRI&@
}67OusD
TrFio;
ov$t'Z
[,Jsx&|
}].XGWMb
KQw58e
|6In~i
'"D-=X
&on;Fk
gSJ.9TW0^
r'v. Q@I
M_e|4X
{Lks0C
rh`l@4d{
^}HFAYdp)
BAKQl4~
Xi/KzR,J$
t4dO
.:=q10
b$#Xf*
5_C$@R
CZzl(E
I"jBhw
^A&F{,
?Ji4S~
9`:]es
>2Vl"2
@\cd8"
5q7eFuR
Z#m*[TdV
zP[qV*
vxj,Yw
GgCq$!
Y)on1EX
u"e>;N
kFi8d1
N^AEkc
V?2OF.5
#c#R/\=
bsRn\oj(
Az76}S
tt8)9C
\P?4 <^u7/
XBXS)\
g;~xF+J
ZOMv\?rH|#"
_^d"wu
$w*>|Q
MB[HI`G-29
y{M)J{
l01.#
RIW3>'
-,Es\
8->t#m2R
wNsdc_
rrb%mu
.6Q!gLU
t@`'jy
U|PD$s
q42FNz
%Na9.e
I^7M*t
pNf*K)
#wbZO`c
X$Y[Bv6
1nY3tT
tI02S@!J
Z4\#Pi
`f~qe1,
b:dfAIk
7J2dG&
?Acdf--
["VX+O
.r7Q5z
e[Vx8Gb
_2`Xiu
oFr;r4
?d;j=I#
#HxnRP
=ueQZOo
{yVVF
yPasV-
SeW1l
dL,e(1'
PdVCIkb
{qG7HB
e,*&y@ho3
v"*{rF
,I_&u]
i_)o:/gx
y |:nn
0+,//QZ1
k~'C8b9_%2l
_[9.*%
7<EN1?
vE@CCuY70p
Sb}&!8:=<r
]ae`1l
P^TDj_
TjkJ||
gX}~.qG
7fney]Jv}|
Xu@_>N2
FPE0~N
FdUa0f
4:0Q6A
q|;*Z$
!155/~`
sY'YpaS
j_%j|.P
8}gC0-0
"$AY0V
](]oR(
w*LA5#
I,S1..f
c@UKVi
9,{0;vid'
F<v5*
Coq:{%
r_$^B_
su5~m-/V
Drf<M|js
zX6<'
|r9"K
ZfouuW
0Q.i~z
O?k_]0
QYRl1WX?
6oK)vZ
#{UK`GQ
(7'MVt
:9~u~Ow
t/K5Uf
F5yxKH/4ET
1XI@' hm"<
u1`ge\^
2XR?Oi
RfEzO{~
%")C'k
j{s)-GK
-YDpi?U2.
P6(M}c%
^L6[S8
cZIXg(
WwdFT.
/9,A7im
ne56`:
I|X:-k
t- rgle
;Ijx9O)h
B;5,D`+D
6HC8z%
v@f.W'u
6;{s}Bk
pd]:E[V#
^GA53p
YsA:+#
x?Nz24
G]vT|q
2Z]I#a
ST"@#LS?w
v\$"e=
&:'v[n>
~WN.dd
7YtO)cG
o}FQF[
t7hFn*
2|td58bKx
A^sAj
v+1||,
HXpCa[d
=u*M^]
iJtl
=9a(7_
&dj%3]
{OEg.R
#0Tf_j
deQ{)x
6iX0kg)J
8T'{*B-
lfGH?s
WE$n,K<
]nb/CE
?5,)$
uT~bT
Z->ATU
k:3sX~6>
mT Kjq&<
si~^jWe@
5u^?Zf
UHW_(:
uch;.O(
B<hU_~
<tipf
0$Wktm
9WD{ZM
0cc4%'Z
W/='>f
F7@ky"
%klylP
>03AoG
"%>OL!
^F}X}q
>\m"w(
`lU(LV
H2ij>E
skYr&R
<T41Egy
b F}A
_8*8[C
qG-5=
$l !Nj
eel_iQ
_#x#6p@
T#D=:"
ZUj.oZ
~|83$3
]h%/#R
z0R@Tn
HsK=Wl
VSe.v7
@#olUkN
RztLD_jt8
$Z:3Tcv
~G/DSN
g01R?^
)$Pry,
xsTWPn
RJpP0(S
kFld{M
y.T-[/
B[;s3A
c?%*U/G
*k21~$
K}N6hb<F
:SLM"A:
W2zJm6
MI!sHNR
_CorExeMain
mscoree.dll
KIDATx
u{oj8g
r[p2zh
Pdk0>>
$D*D@a
kI0BH?
D ZN R
I:!+m6
BJ@xB>z
Ra(@H?
ytTQFP
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
button1
Cvuyvgtyfegdqht
Cvuyvgtyfegdqht2
Shobha
Cvuyvgtyfegdqht.Ceqpzkurvoomnzldfpdijoq.dll
Hello World
Tsarhqndubloderekapoyntj
Spotify
Spotify
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
0.0.0.0
InternalName
nite.exe
LegalCopyright
LegalTrademarks
OriginalFilename
nite.exe
ProductName
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.b13e549416031e23
CAT-QuickHeal Clean
McAfee RDN/Generic Downloader.x
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.530121
K7GW Clean
Cybereason malicious.82fd78
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Kryptik.ABPO
APEX Malicious
Avast Win32:RATX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
MicroWorld-eScan Gen:Variant.Bulz.530121
Rising Clean
Ad-Aware Gen:Variant.Bulz.530121
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
CMC Clean
Emsisoft Gen:Variant.Bulz.530121 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Bulz.530121
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Spyware/Win.PWS.C4531984
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34758.Im0@aOwETRg
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.4096735641
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Seraph.FGTO!tr.dldr
AVG Win32:RATX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.