Static | ZeroBOX

PE Compile Time

2021-07-07 08:51:14

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00068658 0x00068800 7.99013122644
.rsrc 0x0006c000 0x000046ac 0x00004800 2.2928256847
.reloc 0x00072000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006c130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00070158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0007016c 0x0000038c LANG_NEUTRAL SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x000704f8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
rIDAT8O
x<8"gY
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
(P4Lh|H
>tw7Bee
}}quvB
!l%RXh
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAT8O
LQQKQ*
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
VIDAT8Om
F|B$p#-=
$$p-VdbGN
3cHR,Ja.
|0mxm<
3\C]p^
X,nxD^
UM;586
a8NY\6
3EloFp.
Dz?v:Z0
(p*_:~6u]P
T[p_o*
k"Awx]
:H<:il
5xllx
_-6UVG!
Ikz#+
{}?dc^
Xj~es75
>O}WpBBX
"OMK:p1
sR"Vi;~
SMgs\V
m\[c&f~xAH
[42d[8
4goMa3R
'd;JIfO5
BlG#WM
1acoj%
9.<sx^
cR_=^)
BRb7}
]'X ;d
d{@TAA
<8ffLJP
4r\.'N
9*da^^
$69h3j
:"[s`OI)~
T3-CrT
/#w2W?
9h#@O[#
f{xn&x
.)IAFl
m_^s*!N
J'i>!(J
ED7C)&
<41[74
#(V1%D
I.X3QD
<vB{Fk
+3Hdt7
t?0b}m
+}UK&
(nbuBy
<q/9m0
9sM'DF1rN
(t8EJ\
9_C2Y:
KLHHA.e
nb3wU+
UMZyD
u?7ppsY
UaR;2w
8]h"Me
w5~wSjE
A+>Pk+8F
TsY51MM
p9ubA4z
5V4T=j&S
%bPJ^%
b/.~IKW
=yI(}TS
:,::[e
"{Oa6+A
Jt^4}'
F9r8a'9
Pb^jbi
|K'9,k
H`CD.q<j
=C7CK-
9m5wi(i
)vJ|M
E Q2g~
W.r8.J
3v}hvE
Bvhtn-
?|.:cH
l=$S7@
XC'5]9y
Y<|-LA
Yu'B](_
#@16B=
R,)W}at
n(%T#F
I9wg|RJ
4&0:q.
U1&3ZOM
p>=wPK
{Pr"u[gNF
Nk&/]T}
bo|[eMtiG@
$j&MEB
aLITnjb
=&Dv!~4)
Y,:mRM
x$Y/Qf
,,C!JT
]eAEC9
lpj85a
5_;Kz.^
Ud-D_Mz
o0L(jh
96^8IE
q;Dehl
Rel]"
=7s.H
,HW#&q
+*x{mw
)l!$WP7$i
_pFls1
`\]|~O
(h#%_q<
qj*Q9!
q?CWXyan
.K/U]e
<bk/<J
66YI3'hs!
aVbs(eR
8}e9e17
.dSx;-
v^-Dq
qCq2|u
#[H47#
FFS+%j
d,4XxL
ScYW}0E
1lBQ'&^
'bdp4:
&aw~wh
oo*,F5
T:}sA6
3$/s\"
;MUt-F
_/$Z:y
<5hJ.qQe
;evRuc
]R`i`Q
uQ|'j
~O;lIq
E<R$5h
_E_! Y
IL2vIT
nNWw!
AU|NP_C
q7cX<]
so2E{$
g~Cl=C
3~M[zz
Oh5(#_
sOaIp{J
`ireDw
<Y1N+
: NH/N
vx7g\[,
))e.;TD&
#]^yM5
72;AVr'
tg~V,$=j
Xr+?Jj
YY;6JxdK
Zj.+5ST
5R8!=PV
vD%]~qe
vaWL`]
uH)5Pi
}SHP<G
]PirI3bF
>NAPt1q
mO> yh
ou0CFvv
! H<*=
3Ie[{:
fi4J\o
sN+9,0
wqxJcpgA1N
pNP{KMN
b}7J$,
QsO1d<
;Zo_jA(o
t_sQ=$
K%Il?z
7[wH!J
S5Q((y%
MI;>|'
4?J:,b
S)J:tH0
!qX18gMg
$6wA-zX
T& !p+
gt+6|'
5K9N9
EocX((
Bj<_w;
GH|UFV
~j`>SWZ
c'.D~{ K
j\7O{
Vao;&+J
<h;k4O(
+F<MQ;
E(m0h9G!4-f
i%x2#X
a/R_"]
N[+4Go
Q'dNaJ
_*$}`
Pu<kp=-
M>.-z~G3
-&+[(L
g^wpHqo
qlADc"
g~_/'"
T=l4FJOd
yi+Rs]
)gSHmN
$j#A"+/m
Cha12D4
-XDZq
~Gt.MfP
.vxGed<
1&iXh*
)#,|R\
RR$kU^
M&cG+qz
[1sT^7u
Mk6AT-2
cJr:wV
Z]4(M>F
pu*&-.
UJKI:a1
q:4*pL
e}'r+5
Ro/ =YA
v@.xnh
}:ChOy0
95?5x8o
FXUw_` ^
XY/e2Z
Hz1/dhB
%5sb{
o~Q-s;2
7L/>]W
Jd$SzQ
=o{Vk2
;g=|rG5I't
+#Y|iCkG
ZedHv9'6<{
oHhKn0F
e)oC+6@
|kzG(1p
HzLHB){~a
J/qpJ3~v
<E'X\{
JX_ZgVc[
zxX6g)?`l
%CEOt\
@/xia-
pCQi)Pl&
LqaQo]
Ai63v0
k9B7kgk:
LF2#KY
lJ,7Jf
-!n<yt
D.y\3o
3S!`N1
T/}hc.
=fQZ?5hG
$}u4Fz
/zI?IY
uR;]M
E_p(f_
_qf~|Q
i\hYuXs
H.Rx3/
C4q,Us
*ZH=r[
m?"=q1B
id|Yx2tSG
vD\gm1
%>T0YT
]^PDR^
=}\BDA
xVpSBE
7p;%!|
u&ClH
YW"^7F
/[t2ro|
Wu(sf#j
WylAdS:Q
%DO[U2
.xlNQq
(d!I
c3,<=`w
^&isBc*
M#z9'lt]UJ
NP$hhi"
Nd3`^B
w,aIJ=
F;[BK8
fRi9O~
vnfD8_
YnFoGP
=Z@3h}q.q
}=7$qr
?@n j.mh
dUH7^7
2!>8&Em|
#"qb[f
_UTluC
"TnS4}
zB*)uj
,pgU=[;8
)HV"B#
4P2:UPr
p2~0AD`?
r(DHYJ\
cD1;*2
bl6<[y
^TMGh
+-gp-L
_9_z3b
A0?*U1
y<!gw9
+)?:n {
3M*|{z
YL@)K&
3xkSVB
Su\mnE
>UM=+*
k3&p `
ShDtrF
~w[BV83r
wM![pS
)$^dw"
zMa[@M/i
H$XNmU
BlMiT|
qQNw/{3
s/XB/.M
G2Y.a>
e.^cs&
yx,lFZ
lOX[PU
q56=;X
v6%\@}
[b^gPU
qZ!Z[$o9T2
F$!gpN
<;?as
E-;]u7
`0`VLt
v~/b/[,x
Mh/^0Z
[^uPZKl5
LeM?,;E
%jlX31CBResO
`[>[O)D/
><6E?|.
R!yr#"~
g9>b(m
[._N7Imt
F>)$vlXMtI
^v0HLq
P?~#.`
(=]^%+N
8X;+)$
k2VXyr
Qw&hi*
pK5@Fv)8
~$az)Njg
Ztm4z*3)
p \52)>
u".Hvo
7z}l`uq
G?="r6
9z@cvf
k?tWiy
Sv]uDOo:
-dq8)j
-B&J s
S<11jn
+\.}>R
!m+\3n
;aMuRp/
U}82;]=
X^IfAl%
Ea7q/MTi
I );fk
eBi^~!
'Q!5|D:
lrR#(@
j=x=48g^c
mb>eY>\Rh&
t_ODGz
-?shji
xW0WIi
.sSiaV
0O09vn
O:!&BgUOm/
x6EMX/
Sa9+y0}
gK{)i]c
z\\)u^Qj
;W$jCn=
HaN$+y
>tnvdw
"[m- B
\8\Fq.
z}zMp(
ckpK]8
L['.Pt
lkpb;4XM;
.[H.K'
m-9vVvI/
nrw\ (WDYj
>mH.vZq[
p 4v\%
glf:P,
x'R%O-
FS%U>B
^5EmN3
v4~y,0[@
&=-?GKkdFLa4
Y[+bZ=
zB^+m2
s?D|ai
n3l|:
)G&Z[
:}Ms*h
; yh]g
M1?}CC*
j'z:ue5,
m)IU9^
oo j{ES
H2`u6`<
\(1m8C
y93$wG
yPA`hD
X7}<Ml
zP@>:/F
`dv3GU
3to@G_
/D(i.K
]Fn\{B8
T2LL|k
?T~%65u!
fs-_7 !
UV<]-J|
d\qFPt
F9=:':
<m2'#=
ZS-HTU
Q/5z(Wt
JO$0b\^
i_Wq!
f^Zg 4)
(`KH*K
yfwzasN
O$QC)'
EX^|uO
0N8=JFL
('\@SH
3^pz[q
_WOcZaA
yd kg7qL4
=p.<{
=|}DuO
dX)zJ#vT
$qG'=x
!Vsa6=q
S-,3)
omj:\Z9
61<f*r
F-_DfU
6)~H)}
l29&djz
)R1wKy"~Y
D+o:q,
Ul_9-\
CDINT=[
ms[BOe
UQ_<~/
' ~`f?VRP
Y`tYU~,
dKq-\h5\
$t}Ge$
ak?!}
gV>xrt
dI.`ur
"-+=S@
:7Z9\]
muBve2oX
Yc-5iG
o_).!iM
j(hHsz
51^CTl
HxzBw(
MgPFAb
Oj"({%8
PM[L',
E50t<_[
Gs8zjC
3/F_#vW
XE,LCI
-lYC`*I
[RsQOJ
OpT89>
/3q@[5
%C?zR'
4w\ICq)
sGNGZ6AKm
<PECZg6
xT%~D0
^<bzjG
POwL2XCu
u^.?8CKUM
1]7;;6Y
L]b<-`
0CZ/y<z
$X4 ^g
y-%oXw_4
ACe'pU
o37s!*H
mZtv\%
^5uW0C
WWV^34
O&<>vS
Zh{?P,
AqR0=c
ZD;"5{
t@5Q:@h(
|?YEHWIYw~pz
7EAbMI
vPfiG
foXC%Y
sWb_$2
ci;D:M
'NUjd?
",E/6KP
Y02T.pv5
c:Q52*
jK9{x+
%l\ g29
BWQ8Ch
m@~7-f7
.) YqH
Pya&!y
}&cnP8
&j,EZA8f
Q(9UV/?
:^T*8;I
!QPD0c
jC_g]a
A1-/^V
knnYuft
1U.sL/
dp(c/7ZA
*x7GY+
DMnxu59j
T,srnWb
CmCi,*
&*! |c
,8X%n*
,Ageya
j_H;5
oN>]fn
@vpM%}
IT%f/Ga
IPthk
*nlq"CF
+Fh:j\
_bq#Ej
;bc%GnV9m
@PZIO.5M
v8J`-^(?;?
9/kD9i
6v-rbx
22flUO
D'.^vq
xo/T-[
{+`&>Jp
zq2X&?i
ELnc5S8
Z5)ox8T
<*h"Xz
}sCu1
zlx&H"
kiKvYp
E=f<Va
5U32S@
M(`y,`
)p1s}^
k.zR.P
AvJ,/EF_""D
H\|Me6E
vg6%zL
T/>%.lJ
'G>jw1[
\$U^cO]/
e0QQCu
8)Py#8gu
FuucgP
l +"FG
D5d(C6
Oa?3Y-
o5fV[`
?7kr[6
,p!}=\]
mDrql|
D*d5)Ah
\Y#{27
ps|pY.
vnMxzXo
w0/C@>
<-I7[>_~s
6$*8@|
]8mu6D
.piZC'
\yoM20
b$l})L
[fPD$ib)
\EX:-!
?wkdZP
SqW{ws
SA|L)D
^yeV{|
DX1#|j
o%?#(C
3P5$Ku
5-]t5j,
D2H(U'
NlS?Jp
5)+p ?
'Wxwb6
NTJz@I
SOs&Q+
`k$-G5
K8/&\I
{~[%P
S24ij-$'{
#<M%|'
NmhzW_
x:@mLA
*0Debs0v
&<dkuWW
VVraNh#
_w;K*T
T0KmNg,
6SV9#u
7F{%_A$B
|l?im
+v"ZR.
!~U91~
$|;hnz
rS5;z=
+-[7T?2=
b"K&`{M
*H 1*^Q
8t\dS_]
#Z5RvQ
qv)XwL
IPSGjE
uXcfIX
,[YT}KG
RAYfcJ
vFu ('DJ
!94{n{
iSP_O!
!o8BDK
'=^j;q;|:
j=Q}Jg
JsJY^>1$Q
5Ta+}L
]=DOkF~#b
A&m S
!$[lZ"
-';$9z"J
Te$yZ~
<)i+cM[
st_IX,;
k_A_v|
m5F>y`
tCOlrZ
$/fCZZ
`!c2@.
$\WLa"W
,crNB8o"
Hen9EA
?,ci_-J
ig3uQ{
d$ za5
:C(.}p=
^Xw3_"
L1 }</,Z
M-KU-Kh!is
!v?~!CGb
}cJpNt
'659K:
fvL"ZoI
v4.0.30319
#Strings
ConsoleApp2
ConsoleApp2.exe
mscorlib
System.Windows.Forms
System
System.Core
System.Drawing
Rgytkqfgabrxxojhbhediaq
Microsoft.CSharp
Jrmrlioxoizmlwpl.a.resources
Jrmrlioxoizmlwpl.Properties.Resources.resources
Jrmrlioxoizmlwpl.Rgytkqfgabrxxojhbhediaq.dll
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
ClassLibrary
Action`3
Activator
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
IContainer
System.ComponentModel
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DebuggerNonUserCodeAttribute
System.Diagnostics
Bitmap
SystemColors
Environment
EventArgs
EventHandler
Func`3
CultureInfo
System.Globalization
IDisposable
IEquatable`1
Stream
System.IO
IntPtr
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
BindingFlags
ResolveEventArgs
ResolveEventHandler
ResourceManager
System.Resources
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
Single
String
Encoding
System.Text
Thread
System.Threading
ThreadStart
ValueType
Application
AutoScaleMode
ContainerControl
Control
ControlCollection
DockStyle
ListBox
ObjectCollection
ListControl
<Module>
Settings
Jrmrlioxoizmlwpl.Properties
Jrmrlioxoizmlwpl
.cctor
Dispose
Equals
GetHashCode
Synchronized
get_CurrentDomain
add_AssemblyResolve
ToString
Concat
get_UTF8
GetBytes
GetExecutingAssembly
GetManifestResourceStream
get_Length
GetTypeFromHandle
InvokeMember
CreateInstance
Create
Target
get_Items
Invoke
SuspendLayout
get_WindowFrame
set_BackColor
set_Dock
set_FormattingEnabled
set_Location
set_Name
set_Size
set_TabIndex
set_AutoScaleDimensions
set_AutoScaleMode
set_ClientSize
get_Controls
set_Text
add_Load
ResumeLayout
WriteLine
GetType
op_Equality
EnableVisualStyles
SetCompatibleTextRenderingDefault
get_Assembly
GetObject
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
$d0f34573-9569-4de6-a350-dd5a833fbf5a
Copyright (C) 2014-2021
Telegram Desktop
Telegram FZ-LLC
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
2.7.4.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
PhotoCamera
Private_1
Private_2
lbcdefg
Rlpwowfd
Jrmrlioxoizmlwpl.Rgytkqfgabrxxojhbhediaq.dll
listBox1
listBox2
listBox3
listBox4
listBox5
listBox6
listBox7
listBox8
listBox9
listBox10
Jrmrlioxoizmlwpl.Properties.Resources
PhotoCamera
Private_1
Private_2
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
ConsoleApp2.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
ConsoleApp2.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.550630
FireEye Generic.mg.0a696696f5ba6bc4
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.550630
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34790.Bm0@auQYFse
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABVE
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Ransom.MSIL.Blocker.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.550630
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/Seraph.F!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Bulz.550630
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.AgentTesla
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ABUB!tr
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.459e60
Avast Win32:MalwareX-gen [Trj]
Qihoo-360 HEUR/QVM03.0.6C6A.Malware.Gen
No IRMA results available.