Static | ZeroBOX

PE Compile Time

2101-07-26 02:33:14

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000036e4 0x00003800 6.03844810126
.rsrc 0x00006000 0x000036f8 0x00003800 4.96675764027
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00006130 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x000086d8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000086ec 0x000003b2 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00008aa0 0x00000c55 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
NVe j;
~BP
_b_Ye @S
4Y X,D,a
=ni\
<Rf +Js
~BP
|Ua tC)
v4.0.30319
#Strings
msiexec
msiexec.exe
<Module>
StructPrototypeReader
msiexec.Readers
ValueType
System
mscorlib
MappingRepositoryConnector
Wlgotpmxccaitgtpvntp.Connections
Descriptor
Wlgotpmxccaitgtpvntp.Candidates
ParamsRepositoryConnector
msiexec.Mappers
Object
ConsumerMethodProperty
msiexec.Properties
WrapperPrototypeStub
msiexec.Stubs
msiexec.Adapter
ModelItemPage
msiexec.Pages
Getter
WebClient
System.Net
Settings
Wlgotpmxccaitgtpvntp.Properties
ApplicationSettingsBase
System.Configuration
<Module>{af3a4d92-f611-4d37-9ccb-55efaf9feea6}
context
Double
m_Queue
DisablePrototype
NewContext
SetContext
ToString
String
Format
CollectPrototype
Boolean
SetupPrototype
_Repository
m_Customer
DeletePrototype
connection
CollectContext
ChangeContext
ClonePrototype
PrintPrototype
_Method
_Parser
ValidatePrototype
caller
SelectContext
InsertContext
ResolvePrototype
PostPrototype
AwakeContext
ExcludeContext
InvokeContext
PublishContext
UpdateContext
GetContext
MapContext
ReadContext
FillContext
ManageContext
CloneContext
CountContext
PrintContext
VisitContext
CompareContext
PostContext
m_Publisher
RunPrototype
ConcatContext
Application
System.Windows.Forms
DownloadDataCompletedEventHandler
IntPtr
add_DownloadDataCompleted
DownloadDataAsync
Thread
System.Threading
RegisterContext
DownloadDataCompletedEventArgs
get_Result
InvokePrototype
SearchPrototype
DestroyPrototype
CancelContext
System.IO
WriteAllBytes
ProcessStartInfo
System.Diagnostics
set_FileName
set_UseShellExecute
Process
InstantiateContext
GetTempFileName
Replace
Concat
ComputePrototype
VerifyPrototype
defaultInstance
InitPrototype
get_Default
.cctor
SettingsBase
Synchronized
EnablePrototype
LoginPrototype
Default
m_1865da7d2a2f4a03bf6c58d599ad104e
m_7a409df634504f79b93232dcec5dd63d
m_86e13d56136b428997fa3a8124fa690f
m_a18fa1ea2025470a83910443b4094c35
m_df2791304b2640238d47ec814765a18d
m_84c3151f66af4c3095e5e4e9d18e58d8
m_ce5df37a6c004c4b80788669af85388f
m_c457394c08cb486ca416a268d55ead92
m_ce8777be6e0242f6ba5bfe18597d0094
m_19e2e9ae816044f0a0d07b065f1739f4
m_f0178e96f11d4d8793e1ceb003c6948a
m_58cae4d4bcfe49a8a4295a82de328e09
m_338e0f1bfcfd44dd85daecbcbf248b28
m_c6e5ec690f754009a7659d71cc8bcbc2
m_7600908ae5b2497782ab5bddd8a1dfbc
m_92ffc339d0b042af8043bfc6c4e429f4
m_9f1c58fd32b140c8be521841b55e5854
m_e0ab2a4ae4e6481e96d8f340a7bed76a
m_26f61a0784004c7d825867151b42bccb
m_dff4903cc3fd44b8a2ae9b0227cf842c
m_5079a4e07ce044f98bdc904209121480
m_34d79ac25b7345a5b976eb31d6b9a07d
m_b6b5aa071e0e4a1fb92cfbdc6ce76073
m_a750feb189f444718362150d4ed8f752
m_cdbbeec837904f45aa81ed3d20d4c697
m_bb60b648abb64bda9ce385b16cebc866
m_3f621ab01b9e4033b26efbc8f411ea2a
m_ee27c5a5e0344547abc242ec4922310d
m_02e255af2c9c40808ed34d9d43cef357
m_a018d96d5e3c42f9ba5e90aac76e229b
m_29c5a49ca4d240d5984677aaaa946231
m_7607121938ea4b2d98f9b3f8f6d88ce6
m_033304effbe14ff0859beb2d31f85c8b
m_898723e622b649ad832ee851fe9039b8
m_1cc18c0a0c4e45d491c9cf64608ada7a
m_6b228872a458491fb8bff5fdfdf06317
m_600eeda8c8f9494fb08770519dcb09d5
m_108a61c32eb44780a69dd27c649f4055
m_4fcb70e6737e4eb4badb4d7ef36a80d1
m_2890f7064cb446c7bd301e188064b389
m_a8c6d42cdbb94af6bf625e82daab1ad2
m_61dfff70d7d74c4a82a66a11943b2606
m_2ea8ad57712e44ff8b1b5eeec879d625
m_31b454c03c3947c79d2782ae49f88505
m_aad4889c137a4f849cbba25773868e8a
m_f06818d255c94698a6b5a22bfaa2c349
m_da549d6ca0d441bfbdec6465dd8dadc3
m_00d5eba0815d4f96b755985a2700e555
m_b26cf7d9a92d4963af7ff684cc37d173
m_cc8143e8c85e4459a04dc2966e1fed20
m_eb9c321f522c4c59a363d9442a06c9f9
m_d09e34b838154c0f9518e889f5883aa8
m_3be956010880453d95a48f1faf29b83e
m_2f54ebdb64d64122ac1703609a5b4291
m_4f861e5b8bcd4407a8eb9a149acf658a
m_6b87e9754e144440a35c5af81744fe4d
m_6d781dac8c504942963146db1151ed7a
m_3c8e568a7f9447a1b2f02845fb7d8f6c
m_db49355835544108ba79e105db581184
m_25b98747a98a45babd3fad01ddee1b90
m_f7d0654ce0604932bbed6cbd781c3124
m_9b58494c663748bb8aa547b81be62d60
m_f24479dcb29446719f7c1d6c0d3b0ba4
m_edfef2916a544675ad4b2f1bf56b240c
m_6f82a4f7c6514b6aa99af082ee0a52f8
m_7f64cafd61544f6da8dfdeb1b588fd81
m_93c554ffc3a44fb6973dd17e868eefdc
m_20100d4a3fe141489713d806604389bb
m_d65cb8ddf49e4014a3279a37ae8b1ea1
m_cf7aa68e341a46fe8bbe0a9c794a662d
m_dc74826b620e400cb6e3ad6da58c2eb2
m_3c4c3ee11ea94699a91cfb30a8c82128
m_a7e5491d0f274d05ad23bc684babab26
m_426f21dc10fe4821b071cb25e305a013
m_c3812636e3044fadba98d381520c52d4
m_d8760b75304f4279a5d9d46b0bf46948
m_58baea6fba504a7f8a98b626b2d9cd37
m_5df6ba7a8c4340b2bbc9643e57ecc063
m_3e8991c65c304dd39cd270ba906cb84a
m_eeeac57a241a4eada0b751af89b8e541
m_c0363af7b18547a1acd6e371c14da1ce
m_89e904fd178c470ebe8afd21df1af8cf
m_cba060de5d0944a996ded1063625e9d8
m_7018a5223d7343d388f5f91022f4d3d8
m_1381c7bf67b44310a52fb5552620b524
m_db3829f8ac4e43cfab39a25261ec1e18
m_80d71832800b472bb72545b4d612c550
m_ce5cc11c5d344ee39bcd5ff181411df7
m_03c7b84d7b9e4c4592b55f078ba1f548
m_9c95419a5f9444cd8bcb231550ca138f
m_a4839b3dd34441368284174348e8a2db
m_53fb7722df544c09b2444597a36fdf47
m_93a5711aa9e041ba80029bc9553fcd29
m_0138d058bd2a44218fefd0060097058a
m_0b8706ba5aab4a4b93b32a930644af19
m_a7da45a53dcf4e39a2cd5ea4106632c7
m_a4f46555a97e418fac75d6140297fbd9
m_4197c6c24eff4a2b99081b022d4ff142
m_30c1e976f8e149ed85537732f2d44701
m_fb97f62e742a4f1b965df4c38a7fd3de
m_7dbf501f7f024112b6f430ba5e86dafa
m_3724e95b6ae14efbaf1fc45b610d2ce4
m_ad4bbc4376b74c64825f2f9d6a0cb720
m_c14ff50111e14c90b530f22314f7cfc1
m_45b95b59fa824eb4ad8cb78739f054b4
m_f2d0771cd00e4b6791fabc3212a7ee92
ForgotPrototype
m91e7deeb1fa04f638ef7de92cbec045a
CheckPrototype
AwakePrototype
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
CompilerGeneratedAttribute
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
mIRC Co. Ltd.
$Copyright
1995-2020 mIRC Co. Ltd.
is a Registered Trademark of mIRC Co. Ltd.
$6cae8c78-0be3-4929-b9f1-6d8b49ae6fdf
7.61.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
_CorExeMain
mscoree.dll
o^DhdQ4/y.
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
({0}, {1})
http://45.144.225.135/csrss.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
mIRC Co. Ltd.
FileDescription
FileVersion
7.61.0.0
InternalName
msiexec.exe
LegalCopyright
Copyright
1995-2020 mIRC Co. Ltd.
LegalTrademarks
is a Registered Trademark of mIRC Co. Ltd.
OriginalFilename
msiexec.exe
ProductName
ProductVersion
7.61.0.0
Assembly Version
7.61.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Autoruns.GenericKDS.46569954
FireEye Trojan.Autoruns.GenericKDS.46569954
CAT-QuickHeal Clean
McAfee RDN/Generic Downloader.x
Cylance Unsafe
VIPRE Clean
Sangfor Riskware.Win32.Agent.ky
K7AntiVirus Clean
BitDefender Trojan.Autoruns.GenericKDS.46569954
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34790.bm0@aiEmJbg
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.IEV
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.BitCoinMiner.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Msil.Trojan-downloader.Agent.Syhv
Ad-Aware Trojan.Autoruns.GenericKDS.46569954
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.Autoruns.GenericKDS.46569954 (B)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira SPR/mIRC.Gen
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.Autoruns.GenericKDS.46569954
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX malware (ai score=83)
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
MaxSecure Clean
Paloalto Clean
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.