Static | ZeroBOX

PE Compile Time

2021-07-07 08:50:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005a768 0x0005a800 7.98910726757
.rsrc 0x0005e000 0x000046ac 0x00004800 2.29406882758
.reloc 0x00064000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005e130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00062158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006216c 0x0000038c LANG_NEUTRAL SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x000624f8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
rIDAT8O
x<8"gY
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
(P4Lh|H
>tw7Bee
}}quvB
!l%RXh
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
LQQKQ*
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
VIDAT8Om
7}nYRR
khT"N1
4OuZGu
$`-7xaE\
~tK;R#
C"F75=L0
Vrkm5VQc
x%Fhv?
GW d.
iQcpm
DbvX7-
R8Z|]#>z^,I
yyL%8~
%p<i|
ng7<0j
-SP+i!
;JHYU|
8D(f)ZQ
&NEG5B
| N.WL
~`O3\l
%DTvB|;wH
mk(uF\AIq
l.f q"
1<91ksA'
gReIao
e)sE8[X
yx+SidkBJ%S
9C/*_n
M4KyG6M1
%_<p3n+
n^.K)
A?)&Ropr}
q)4RJQb
X_<]xiU`7
vVsC&t
AA:yD'
qc7<@G
ASD`uL
s{N\:)
UW>l6a
SYj&df
'?Ge,#
?"9E%H
sg^$9-
F%eT~{
.qEZIl
qNL@l>H
TXbtCL)%O~
cJgBfN
pxepcj
rkE7)Y
RO@/t{
sh*|Ne
t2m_*bU
z3xV[]
V1k'5}
ltQ Uh7
dF1 aXp`
(:AU4Wsr
Y);LZw90
x;rOe?1
6swa;b=
43EL}V"VRa
zaKOi
Q<=rwo
Oz%Y;g
JZF$-S
C$#.Ey
I+-ysW
yq'zxlL
WIXu;_
w6:^d$6
4jp/$'
jWh>K!A
#dvYv&r
2iracYk
W%3I2v
pVPHv4H
f]fts
X=k3-`
DH-kD
aQOe]/
|S"P_Et
iZI9Gi
uh)Ha
iPkhH^
xP72^@
d5-ew!/
prQjIM
!M[;|@
% 7XP*Z
g4V]U:
(c|wC9
&KMkY9
@w)S'bX
:ViFv/
U!Yueat4
Q# z#`
-O^=H7d
PZnO?8d
ZcN;=Hp=Rr~
kGE_*?a
Ze)Uw'GF
_G5`!
h5|4SjS
laU|>0uG
t]cr\7
K!cLsh"J
zhb|kkU
qI.+N!
O-r$;4
^O/R=v.*
3dhf<a
US7~oU
#M(26%
g!g.BB
r4{s*%
N )W4/
[3Fvu7U
%!O|%*
3;XCvU
\HV"t
$2f@0[
sy]<}C
RgMYwKq
Micf@<
_2Qs'V
G;P:cu$
UN;+]$
Zjqci%
E>U.o;<
K(9k$:
WCVI_6le
b&/Oo>
A3.T?(0#
T(pEik_f
CC(X!"m
EU7R$~
5&F$Nz
KQ_0|_2
ZO61_q
F[uPz
4?\w`r
;+]~.H
|9>PD*
=cgKe~
QC<`Xc
hRP1fS
D`6T_m
)>@m-|+
S?}ZI,~D
_C/\So%
,6FJj/\X$
q3l3wm
]Am}cNulZ
$.CcU:K
%2?cQ'
L{asgL|
YIN4?}t
$|]TD-
*|}R8#
ZEyn.#
4`\>%LsZQ
?Qm|T\
:nqgZ;
c]Kzh=
!w,QUw
! 7$P(
Q0 r%?
o]=<}
=ljaui
X|:B"v
/xD%cG
*wivots
9|DIht
;#]~Ofk{o
]spAewK
DsD*D!/-@[s
m0:'/d
a#KQ&:$#
nR"<jv
6?@JLe
UNGrN^3;
[$G&'89
M6?1`cn
u/]]Eq
q218Z~_
EB)}46~
`P<ne^
*6hb%g
*|*~48
OhDn!u\
m#TeiU
:04}4
u=Ct=GuP
X?n],w
Te-N=bG
#hg&:4-
bF2%#>8
y]Rx,4
~|vnmM
cLlCP;
JHm<[a
1<|9r$
&<7VcV'
MN"YZ!~%,
L?F=S*:
~WW%v/
M<lrmdU
la0X@QL
2:}VHi
a@l{&E
KCTp#C
cnlOH@}
l\eD,G
13Xiqf
v$z<
p&a\]mT(XH
x]>Q;%
,B1Cu\
{2"o/)f
`n:qu%
F3i<Sj
f:FO,%
6MN/,>,L
RmN"r8
5->YTO
OHs`(1
X#.W/I
KRRU2{m
:u5js(
T'W$;gP
^gs\eL
j?00xz
*}4ncgh
|nB>&}{
,.s6N}
T>tymQ
(}B*%'
nk'3',
h`t%xQ}
Iq*TDP
kYmU?m
lL60pqm
v&*z$R
i7h3$$
Y*PVf
RNcsk=
v%od~/(
Z+#cY@
F:^:4d
g\sZ7p
&rPhiw
IBuj/]
lP6`KG
7[BR=i
HAoPDi
xAVp^@
I)h|Zn
9QE:-<o
=.9f00
CT_s=[
1v&s}E;
'[n=[j
*?ZN;$
SK?{ao
J|J+?'
gs-/b+
2!5[;7
s\*NW|
MGX'e@
pT:D/F
,4C|L%
%?}UNi
;,s+XAt
1lEd;y
%vtk&z
qMH0()
yUH_>`
qdwygR1GMb
4mJP}=
`?-_=gn1
CwSGf4
$grg8Mj
% 1NL
jpB)NU>
[x `D
X("cc_
Ou;B<
sAh'~2
8NA;NO
w%4))|
T!AU]3d
cEz$/^v
-j8}()
-ZvlLh
N/FEjL
C!{d96
_B:>!R
6}jUGi
p|.a-v
+;+piwk7@O
HB7DfT5
\5#eNGE
:Ii>X%
ax+I6;YJy
\S&o!:BC"
%tL5AI
e,#n$=b
4 . Kpt!
m M:wed
,4T{nm%P
}6+>~w2
d*1EF'
mzwklu
_$!QH6
@n~|!X
j5bwh6
Sy9rv1N
i~\!\3
?ybsX{%
x>0ZOT
<z+LRO
\m[Zga_f
yI&gff
l,sA(bOmG
pxJHVV
(d=C6u
fPO-X,
NKBnXW>Vi
I[pR>"
YsFJz,
;(&\b$
d78@J`
Qj:!,J1+
<'MezJ
l@5`at
`CzRd%
}(MAP
?>=X#z
daWgh1
(/$Voq
iYT`,A
W}ZO=0$q
D7/bg9
jkr~)J
R(|nQO
~InIC`
LA1&*D
.(WRu1
Ua7Y?q
LDwruP6
,9}kU>
O~uY8m
;N^w.zr
gm_8B-
T 'Vrm
h'P?5g
].BE/F
otU# V}
Qd{q>C
Ei<=br
@1a)}X=
YJ^TQ{
}1\?&p+kn_
#o0iUd2R
lg8^Zs
b(=h51
2Wslo5
wn) l
qxBy@`
~zM[n
3t$5sh
.bQo<Dq
L%Koqe
0G/X=dC
w`RI|m
?aVZg }
8tvZi
sBH@ 9
g;yqji
;)YaRK
yY>4R",
]!3yK&6
={m"=m<
V&<Zl_
S54wcu{tk
5 1!;y;v
U*-vG,
v1:c`M
07:,`p
e'mJZ&
j2ZZWB2
]b;c`yD8A1`
}Q;aE/@
dKx;*"
!C>9%u
ZExP#O
SSt59}g
#&V?qO
8s<zj?)
+pzd_a
wOfb[}
!k}L&F
FS$2=
CD2M_fx
P=:7SIrX
c!':Q`
xv*sI&Z
L:w22L
.xqV76$
~U|()N+
@F@'j1
7 Wo;-_
6>@EPNqP
e)g)ck3
S~YQR-}
4EWTvy
SV>/v~
BX(a!c]I
%;-D^Q
iBD=W7
?{9*%~
q*nQB&
a PALq
Acb{vs
.K )b00
3\mOh&-f
^WBnuw
~;mm^,66
-%xmf+
*q4({h
y@:3W3
"[]qHai
82$HZ?
J>(sT!/
<~p(*Y
PCY&8|
&iOT_r
O9x``t3
@{0J/i
ORSllG$lUm
GxyJL4q
^a!asO
5s=`hU#
\4=b%
u)vq{!
NQ0N>|
!QLPO4
M'g*hr
i6 -3S
Hs8w\o;p
1J=EH
>u4{nP
R#@f#Y
XaVv(h
l:VlJc
yTSJj=
'*CgI1-
Bz%&$f
?&hO=E
2O"H0
1OO,T
U+.sE]
(`:hOe
s+at2P
=<\7Xp
`T|`eK
Lm;2j
4Z<{2$
Jh1.|*
X*AUM2
qrH(1;
aen0)F
]\/v"x
6|M+lmU<
ynoINv
W.BvxP
?6%+?3
KBtrXG
u<A%U12N
mxUk+$
-PWCP.
9L4c:j
g7\Q#
z _$+V
1`h0yR
Z1W73u
{~#EMW
-vD%:9S
%(0*`p
g-XfHq
LW30P5
5moE(2I
4_du,}
%&rlrY
/bCvDG
iUi1&];
rYZlur
L0u<t>
~Yw'-] b
T9Bz/o
6zfWY3
Q%9V!2Y
5b/!Q@w
C}8Ix],|
\hmyP[
/J`|5CA
J|32=.
|l@]4U
YcqSi+
\4*:rk+
#( |!0t=b
0+=iO5
W838`w
nbInew
9?UzYc
4RXC\{
ANvU#=
N9qTs>
O.|To"o
]K&}/<
sQ*f0Yj
~)d&.*
bJm Ev
lLyAw(
cKX;.*
xrtJQ5Z@
aUG*}d
^9eR8a
1 %mhP?
[Z'r*D
QHLAs`n
QkUV(`
E&1UZr
"#\?f<
9#zjX
GTWGqDz|
A`~lql.
^L)sy]
6=t`48
cHitX1N
,yq[]n
+CG0G3>
N>kuK+g
AHhwuF
)A~[*o
?ghY!~n
NEOQX?p
rU%ZpE
H^z]W_
7h=Ya/_
3XB]$}_
)dIOV?=4
pD4_:8[
DUg*e/
4h('B$&OX
>8KNO2o
H]wedy
}$>D{
U;axhl
$b$ba@
4Kj0,Wc
^X:Oy}'19G
3 OM:.
GG`+|J
E&G`Yqc\
o iL:v
h?XI5?
QNt`a"
P}=85'
v?Z^Rh
LQ/!Z,
=cT"=wj
zOc908i
3)B\&'
J#>f8=
t|2&4`y
pgp*4MF;
kmxc0z
'-5u;S
UB'Wg3
}Zg.L/4
8:3:~%
sR{vaj
kE]>bz
_?M"O_Gh
D+ eE\r
~;D9K`
_7"|isb
Rtb]pT&
z'D-WM
L*nz!>h
{AKgJ x
" hlK9
IrYwUl
vqT8)JK
i9S>9~
UXd0@3
^pMiaG
Qt4$%6
mjLD6&B
Y4pRPQI3
)mCCu
~.wQ8vr2T
>+(.og
^WyA]$m
gD7`/#
9I2=$2
?5yx.
^"xLA%
3G<f'xr
yB@V=s
'*7(+(.
;0\i+w3UM{
;<*LeD
v4.0.30319
#Strings
ConsoleApp8
ConsoleApp8.exe
mscorlib
System.Windows.Forms
System
System.Core
System.Drawing
Ivrekdywvd
Microsoft.CSharp
Uzkacndhaisbzdtglfsivlbl.c.resources
Uzkacndhaisbzdtglfsivlbl.Properties.Resources.resources
Uzkacndhaisbzdtglfsivlbl.Ivrekdywvd.dll
ClassLibrary
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action`3
Activator
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
IContainer
System.ComponentModel
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DebuggerNonUserCodeAttribute
System.Diagnostics
Bitmap
SystemColors
Environment
EventArgs
EventHandler
Func`3
CultureInfo
System.Globalization
IDisposable
IEquatable`1
Stream
System.IO
IntPtr
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
BindingFlags
ResolveEventArgs
ResolveEventHandler
ResourceManager
System.Resources
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
Single
String
Encoding
System.Text
Thread
System.Threading
ThreadStart
ValueType
Application
AutoScaleMode
ContainerControl
Control
ControlCollection
DockStyle
ListBox
ObjectCollection
ListControl
<Module>
Settings
Uzkacndhaisbzdtglfsivlbl.Properties
Uzkacndhaisbzdtglfsivlbl
.cctor
Dispose
Equals
GetHashCode
Synchronized
get_CurrentDomain
add_AssemblyResolve
ToString
Concat
get_UTF8
GetBytes
GetExecutingAssembly
GetManifestResourceStream
get_Length
GetTypeFromHandle
InvokeMember
CreateInstance
Create
Target
get_Items
Invoke
SuspendLayout
get_WindowFrame
set_BackColor
set_Dock
set_FormattingEnabled
set_Location
set_Name
set_Size
set_TabIndex
set_AutoScaleDimensions
set_AutoScaleMode
set_ClientSize
get_Controls
set_Text
add_Load
ResumeLayout
WriteLine
GetType
op_Equality
EnableVisualStyles
SetCompatibleTextRenderingDefault
get_Assembly
GetObject
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
$3fd983ad-1cb4-471e-9dff-bef2c2968709
Copyright (C) 2014-2021
Telegram Desktop
Telegram FZ-LLC
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
2.7.4.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
PhotoCamera
Private_1
Private_2
rfghijk
Yzaktqczo
Uzkacndhaisbzdtglfsivlbl.Ivrekdywvd.dll
listBox1
listBox2
listBox3
listBox4
listBox5
listBox6
listBox7
listBox8
listBox9
listBox10
Uzkacndhaisbzdtglfsivlbl.Properties.Resources
PhotoCamera
Private_1
Private_2
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
ConsoleApp8.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
ConsoleApp8.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.485635
FireEye Generic.mg.c2a9f9afa108921e
CAT-QuickHeal Clean
ALYac Gen:Variant.Bulz.485635
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.485635
K7GW Clean
CrowdStrike win/malicious_confidence_80% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34790.xm0@aS89Ygl
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABVE
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Ransom.MSIL.Blocker.gen
Alibaba Trojan:MSIL/Kryptik.15f0e9e0
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.485635
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
CMC Clean
Emsisoft Gen:Variant.Bulz.485635 (B)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/Seraph.F!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Bulz.485635
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!C2A9F9AFA108
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ABUB!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
Qihoo-360 Win32/Ransom.Blocker.HwMAbocA
No IRMA results available.