Static | ZeroBOX

PE Compile Time

2021-08-08 22:24:55

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00006210 0x00006400 7.80615234698
.rsrc 0x0000a000 0x000004d8 0x00000600 3.69607345702

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000a0a0 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a2e8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPo
jT!}>~
?AGIL)x
0#n6.to
V5$,&S
\SrBL<
<GP<My#
ryT#h8
x6D&7i
)Y~X)H
y^~L 7
oIi:u1
Ui"N<i
Yy^:Ab
iqr;][
;BQC4*
Q`E"EV
/*R_E-
yq*%O4
n0rLQ"
~S@vD^
*2Tz.XY
RzIT~j=K
MF`d;Z
e^/tbck
:HAfCC
BL$ryd
8OKuy9
wo)oi6
0gKI}7Q
uuJ>\w-o
e?]fzp
9lEWFsW
NM]K@w
hc&\Z+
&fi%*@RP#z"
&\9cm)
VQu`3_
\!mq%r}
v4.0.30319
#Strings
<Module>
svhost.exe
rqumvafbeaeo
mscorlib
System
Object
nvmzcbgigiqhioddfl
usnswfu
System.Runtime.InteropServices
GuidAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
svhost
System.Threading
Thread
System.Reflection
Assembly
GetExecutingAssembly
System.Resources
ResourceManager
GetObject
MethodInfo
get_EntryPoint
MethodBase
Invoke
Exception
System.IO
MemoryStream
System.Security.Cryptography
RijndaelManaged
SymmetricAlgorithm
set_KeySize
CipherMode
set_Mode
System.Text
Encoding
get_ASCII
GetBytes
Rfc2898DeriveBytes
DeriveBytes
ICryptoTransform
CreateDecryptor
CryptoStream
Stream
CryptoStreamMode
IDisposable
Dispose
ToArray
gegxbbboaswrrpydqubopektiednjugxhdyvw.Resources
$8baea9c0-1b0a-43d0-8217-290fbaf32239
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
wxeqkmdgtbzpkyobwnteqckakttrauic
gegxbbboaswrrpydqubopektiednjugxhdyvw
wxeqkmdgtbzpkyobwnteqckakttrauic
ltzeoyqkgyofukggjwliivowfkpgdzosgvxmxkjzrpmpfkmmtyrpxzxrvukqbgggvizmqwhxflfxdxjvtzottxdgcecqzcfltyvrlzwfltuubawclebvtooxtbvctbxjgbetdmttuthzqtlcszsyskbvcxzrfrirylwauvbyckkzepyarxvtnwgcayignawdcpeafllggromzbwhqzzhudpgfrzajomvcgdmjtvgiolkmexhgenbagtnakvilkxt
mnbnmixbdbycnwwpynvbvcbmokmzohvq
mbyxifettzmhiuau
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
svhost.exe
LegalCopyright
OriginalFilename
svhost.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Cryptos.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.48fe2a425a5c393e
CAT-QuickHeal Clean
Qihoo-360 Win64/Miner.Coinminer.HgEASZ8A
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of MSIL/Kryptik.ACHI
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Cryptos.gen
Alibaba Trojan:MSIL/Kryptik.0360d88a
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.943
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.VirRansom.mc
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1143066
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4556632
Acronis Clean
McAfee Artemis!48FE2A425A5C
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CH821
Tencent Msil.Trojan.Cryptos.Pgnm
Yandex Clean
Ikarus Trojan.MSIL.Krypt
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/GenKryptik.FHLO!tr
BitDefenderTheta Clean
AVG Win64:CoinminerX-gen [Trj]
Cybereason malicious.7948f8
Avast Win64:CoinminerX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.