Static | ZeroBOX

PE Compile Time

2065-02-17 09:26:29

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006107c 0x00061200 7.99496002988
.rsrc 0x00064000 0x00000bb4 0x00000c00 5.32657620677
.reloc 0x00066000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00064100 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00064578 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006459c 0x00000418 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000649c4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
listView1
get_UTF8
<Module>
System.IO
TripleDES
mscorlib
Form1_Load
add_Load
listView1_ColumnReordered
add_ColumnReordered
Synchronized
Android
GetMethod
defaultInstance
set_Mode
set_AutoScaleMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
DockStyle
set_Name
WEZEne
WaitOne
get_Culture
set_Culture
resourceCulture
MethodBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
WEZEne.exe
set_Size
set_ClientSize
System.Threading
Encoding
System.Runtime.Versioning
disposing
System.Drawing
Samsung
ComputeHash
Dqdscqvxpqbbbxarkqj
listView1_ItemCheck
add_ItemCheck
set_Dock
TransformFinalBlock
System.ComponentModel
Dqdscqvxpqbbbxarkqj.Xicxicqdthy.dll
ContainerControl
GetManifestResourceStream
MemoryStream
Program
ListViewItem
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
resourceMan
AppDomain
get_CurrentDomain
Application
set_Location
System.Configuration
System.Globalization
set_HideSelection
System.Reflection
ControlCollection
ListViewItemCollection
Exception
CopyTo
MethodInfo
CultureInfo
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
sender
get_ResourceManager
ColumnReorderedEventHandler
ResolveEventHandler
ItemCheckEventHandler
System.CodeDom.Compiler
IContainer
set_UseCompatibleStateImageBehavior
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Dqdscqvxpqbbbxarkqj.Form1.resources
Dqdscqvxpqbbbxarkqj.Properties.Resources.resources
DebuggingModes
Dqdscqvxpqbbbxarkqj.Properties
EnableVisualStyles
GetBytes
Settings
ColumnReorderedEventArgs
ResolveEventArgs
ItemCheckEventArgs
get_Controls
get_Items
System.Windows.Forms
set_AutoScaleDimensions
components
Object
get_Default
SetCompatibleTextRenderingDefault
InitializeComponent
ManualResetEvent
SuspendLayout
ResumeLayout
System.Text
set_Text
set_View
ListView
set_TabIndex
ToArray
set_Key
System.Security.Cryptography
Xicxicqdthy
get_Assembly
GetExecutingAssembly
ClassLibrary
WrapNonExceptionThrows
Firefox
Mozilla Corporation
Firefox and Mozilla Developers; available under the MPL 2 license.
1Firefox is a Trademark of The Mozilla Foundation.
$99a06e49-deab-4b88-81e1-9c6d65ed84b8
92.0.0.7897
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
]I- h-
fF@EeA
7\)M1i
5]z?sU
r<x~k1tL.
'4:cWLd
)P}!KH
=;E9MG
uRd:@6
7\)OnQ'
_/'9ogz
h-p{/m
QWuYnt
JEy-Uc
zCw3mx
%%2,`
cnQ2bs
0r+[.`#
NT(Txz
o*_^ky
o*_^ky
U1mO`5!
@CXzi)g=K
o*_^ky
7\)7W!#$
'wbyi9
96uY{w
L ![,p*
=WVpMxs
DY#-cyK
K:g2df~
l?sgF#
o*_^ky
$@.U/2
{R"dK"
@b,tL7
";dI}'
hziwbu
@p~1ZP
!woDMu
8o/Yn9
tL&^d9
wy4LY<g
]]tLL"
6fvw}pL
)KX{VBF
mvyg&e,
OfR:}
ZQ0(,c
L&)PIE
/tXQsv
3_)$S5
5zw`j9
$swQ4t
YYcZf8
2MRlG$
r]]dLtP
BZ7cam
X=+:h)R
r0=qt~B
rJQq:I
1W+*e75M
Mnwq$4
TYcy?!
42fzi
bK\_\@
yo=Z\e
gkG3fv6
h_^C'c
JA2,U`
>&Wd;z
NMB{pWv
XfsGGwb
Xu&Mms
d"wn&m
cL.dkG>
rpjEPrw
U8|w{E
[<CpG~I
;@l4AQT'
|^M~ZPx
A2$|6%
(9T$"(,T
Z<+R.B
%/9I/5
ND#}d_
xrc,n|
K#|URT
w#vrMi\
4wVz[:kab5
wW<dA~
gl.E^i7
DX`r:0
lH8SPFuS
_xKukYP
,uRoq3xRp
)/[h?0
zfZq\~U
te<l-hY
*?S"?%
@@So7tY
"2e+^Hx
J*M_E"w"9
v(dN%#e
9%m%0K0
.;IuW
WI\p"h
&&2sq<
!K#|5'
d6)!U@
W_6BBD{
-1,6cty
p\Yx^hp?
LU=*?8vm
]_*.eK
<S?zG
*5Lrt9u&35E
Rx^<\$
uAfs@d
e~oz08
+yFZ-q
,s1K*b
Sp@nVeL
4aW;er
:s#U(a"
#>.39.
)(.Rb/
XJ-;CC~>
Wm7>`E $U
;A??GJ
Y7_CL#&+
:*Hp=\65y
Y@'Iz$
A.TVs.
)cjZ>7
gmtI.I/
F='s/'
(DvzP!
cZF5W0K
+a$<#e?
fm*0G,T/
P;'W L
,$xk#
Svh%Ti
:[*wi_$#
@kssgz
||"o!M
FY$.fP
ok;0ot
Nt_:66&
;|)cs05
{>]?wR
-<WN=8
/ORw<u
yq^j:h
SCnWg&
GBLB>k
Z/!_K|
`-%.<)
<gBj>\
F]A&d_
sEbE8J
XodMPr
'Lxm\kNk/
/15"KH&
/dM+FP7=
k`QR0e3
@MAOX;U
TH}^&(
l=!ga(
2 # @(
TCgB&e
hWFwMGr
$Z*!&arh
'}Nr6'
k~gs*z
r?F&Tw
CMau2
:9%TBT.
+z}`#&
X-.3\b
xMPx:S
\g>d`%
DYNPR=
NykQz.:
M@dmI,8uY
R\heG/
9yJP^l-
,d6,6
%8e|<
7x!P*H
3~ZW5
YRejE7
CCsFI>
DvaB+}
i"$QNB
fV/oD@
i#=yLx
8$1bQ8
|c*TyS
;KAjk'+Y|&
}x]\D
oeFqSYu
:JGqJLO
;{]6fG
NBOM1Sl
|:sO:E
rL9wEQ
H~,jb.
t5J8='
$zhr*F
+Q5II6
sz|8W;
s5|E[;Z
kj1${r+)C@
v)hi./D
HO*0#u
}Ol$?9I
+DW4,K_
F87< yn
D%Q~oc9R
/6XO,R5(
MChL:oq
yFmg-Te;!^/
Um-%)3
:MKtSU+J
e::~r@
v``ZZt}
O!"v.t71
4YGH;%O
'ro2*|]
7yty?5
]=s:#)T+
G*xYN^
.u\\`F
dV$*5j
Me&Z|O1
"W"Y*#
'Kb!QWc
;klWf!!
u}<Qv\DI
23&n 5
!]d'?f
$|AFd;I
d!W`u6>G
I~#0Y)*
=m0\Z:
IyKn.sVRNY
<Y$zMz
m*R(v}
K+wKj3
4g3}Y
J*+z,KYao
.z5_~@
7!ijaA
B}svqp
@)Q.JX\{
#)>O)Kn
k"H~Tw
ZJq):u
vhTl8A
(Ns4x~
+k]:lP
q~eE`}
Z r0.v{;
n.x#oK
<5{P2^
>Qp[2T
#X`F)#
"f'3YqU1
>nBW,7
4sez`[
z+ybft
u,NN~V
|c2Y/
uR3~yv
t,^G|$
0~tlD.
x)ES/8.
kN.-^A
[AqQ'Ih
2dJfXP
"lb_G.
%*L9%I
+7EVq:!Z
*KNu%i
mV%v[X
mu edA
?y7+t'
gylL2:
_ RK"Q
e746Dpo
DFiHTMB]
6(2<}:
)}C.y=
l9*?`A
3`=wkLW.N
609bt'
;P)_.p
ESwYbl
0Xo:Fd
nF.S`O
GN_8f<=
'Cjhq42
n{qX`.
zcakj/
uBis8F,
WOIBzD'-
vu7r31
{PMAYB-}O3Q
~&iY)
{rV{e,2
e;T &p
uOJlK&
14xLI0
G,Nk9*
P:<HRP
7#CzHA
"=NbQ*
W"{i@A
*9|M:?/n
Bd:\\?
A1+{LA
q1mB>g
>?Tz0@Q
!:^(5Zmk
GryJ_K
_B!W`h8
>0S*`V%A
ZK4-
gYP>Mk3
'kHgkFl}
iL-C*\#r
(vZW|m
7&*QEM
LZmeJzA2
7CVvuV
>zm"YQ.C
Eu<D$-J
9$e@O<
M/K}W]7h
%;vGOT
6J3yBxbSlc
IaUka>
xDVp90
X.}@e{
?$UGl;A
2u:>}#>zr
=npU>J
$&KFkn
'HV#If
(hF@sQ
\t)|{|
xO0_*s
WJOb{"
0TVGH[
(%T@04
tB{?M\F{
_*wB |
"Yg^\|
?)trQL"Y7
QJ9$:'
GF\_yL
xsn8~f
XSVIi/v2
IdGU(
-rq14F
W`mCOG
N;XJx%
B16d`O
!PrLh5
>uQn}c<r
0-to:++
ccFk~b(
Ej\|X&g
1Ie7=5
=5Q+Uz
;5P\(7T9[
~nE:~r^
YCC#?d!
O!fsc;
cN:Y(b
$iq3y(
Fh=bQ2
F@hl\*
SxQ`!V~
lp-FH4
m!{>Z)
Ix;i}0
Y?"+5G
M7A5NTr6
IY+ed^F
JB/j]d
X(jeMH`
)|>N|G
J\>rx
A)R)c
)p{/?m
_P?oGU0J
5J>XEe]%h
1fv9 ld
X7vSSi=
?$oBXX
*zL9h%
XSs'V9
(?is,f
0.3eg`
]"3IWw
\LY]hO
5"]-}
D^er Qx
8-N3pM
.GwSRh
o6o`T3
TO<Y7n
&q9`$J
sTlcd>
V5 *(sTg
o<}gp;
ok*)mz
p~xTBR9
*/Sir.-
s`[]kH-(=W0@
M2|.y@
_x(c&N:
eZ}tf>
`$U}!,
G*0j[p
n!"ex
V|*x3u
W<s7dS>
2isYQa
='$^pO
U_zIR@
sARCNt
5N5@5
8'fj"S2
# /0/}
r0HUE'
"]C|Q6
P6o9qde
Y*lj[f
m. ;1Y
2MDahl
[}W>y1>
e`=nI >
}`U@p6mE
^E40Kf
Z$:9Bbu
5#}f"9Y
)`@#lf
$.Y#50
;o]]7Y
ZjVp5_
9wOvL&
)y{HqJ
{z*N[kc/
D+R6rBR
>P|g+b
i0v^v<=
gYA:vFgq
,8*Y]^
XUv`qd
i#e/L:m
Z'(UQl
oo1u#
nxi=%@
P4b-W!
WT)-b|
I&Ersu
yTQ_;.s
A;*Oo^
dG,fKn
F_cY_HtdV
5!kiT#'
z_Jj:;
cfU"i3
ttl.F3
OB2eC]A
8c~\]U
liJIy|
=H! iGc
"aSE>%M
-1+ n9p
oy0/|9V
(,S1'Z3
Kl<Y2m}
wUmKW6
PnXwg3
17/s)E
m{.LD(
{VlY{W
Iz|)%Y
)T)159
K61jO
W\Mm2c"
2LmN#8
Ih/D_sX
eK9_D^
p+M;oFy
FBbeGEd3
d8u&+!
UOYc6I{
H_>f4U
cL9/TC>
A>.|X%=
tEHsYu+
%I=f?{p
N?P/uA
lelAzC
J{9JQh
VUGwf7)#
WP[%!b
e%}R4$X
eCzr~%
mFdJo@5
V:|U;+sQ`
(Wu*1'Q
M8M).o,OW<h-
~2>JMS
!^e8 &
h.^$~e
Jb76dIDd7
)$]/9'
L>o }O
bvgMN
od<Oz|
O_eJ<
-}xG l+4
";egT^A
h|zeXK
t'=r)Z
nA>}B5
d#,^?B
G6efRz
f31{P$L
Y`aYH[P
\~k/6s
OVP0Y&
O`Lb0U
MRyAn
OLaF!z
NhA+#j
qar>hk
/1sOq03
6 u~u3
XWPUY'F7:
WbtUw7
WW]U1]Q
*U;p-M>
s0Xk x
+?L2z!
.Ua!6d
N=SO _
:Xy 5q
2U%A)wl
wzc74r
F6XWEml
,NIF)Hi
b9G.x$
YUL9}t
Ed)bj&
Hue{B^&r
O~Cz&r
(dk]Y<#
,QCgib
TIYQb{
ChGlL$
JN;i~jP
uP7{nJ
T[g{lo
v(i[M}
m]4xZ6
p&AvAf
,*Lw;Z
VV?{Fy
]1H%D+
y2A!O0
VpKC?5B
pj#(e
f Ltp0p
xB 41t3
1KPFo~
R+Mfd#B
C&(:nb
wbpYi]
Xks1MV
#l^>]i
={d`CI
h{Tg?.
tIwWkr
&4vmW;(
ipN'yQ
)&oKl)
Umi0F*
!F0vK#n
&&l`lN
aV#]JE.
#L4=b]
0^"lZJ
O&vgrRp
*xV'68
a9M,4#UX
l7NP51s
KD)y8.?
3-`zr`
&"RFa26
bbN`4J+
dO.b.f
"I{FkV
y/|-PC;
/wxBCC
7CSaje}
km7r%OzG]4
,AMw}oEI]
Wgx-+S
\iFFVi
^m|$X:
|Sf%O
Fh>u||
2ZVtZTp
glN8;:
]#h_]
M=KBz,*U
tR'|R^
"iD:O,
A7v@iUhz
2kkFwZT`
,Xq!-f
yvD1)"{@
%u3.&
LCP~*\
-;d8{/
:s.0XD
Ec#1[HJ
S]-_/.
E'6<oS
v1Uoq]
lv:<GN,
0fm?Mv/Uk~
V]=EhkK
jK`\V7M
I>lki9
/fpFP}+
[yO sI"
`4~]&<2
6.6MDU+
$,"L*b
zw1Y51
.gUw-@
b4j^%r
F0=D8~
y AS~6
M_WeRh
MJ{>I
90s=RB<~
[2f1Zn
acv^n;t'
7\)S8@]%
E3caJJ
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
listView1
Dqdscqvxpqbbbxarkqj.Xicxicqdthy.dll
Gsgwdcdpma
Dqdscqvxpqbbbxarkqj.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Firefox
CompanyName
Mozilla Corporation
FileDescription
Firefox
FileVersion
92.0.0.7897
InternalName
WEZEne.exe
LegalCopyright
Firefox and Mozilla Developers; available under the MPL 2 license.
LegalTrademarks
Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename
WEZEne.exe
ProductName
Firefox
ProductVersion
92.0.0.7897
Assembly Version
92.0.0.7897
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.1edf6239fdc16549
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee AgentTesla-FDAW!1EDF6239FDC1
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.f18c89
Baidu Clean
Cyren W32/Jigsaw.A1.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACMN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Dnoper.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Trojan.GenericKD.46820831 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro TrojanSpy.MSIL.AVEMARIA.WLDW
McAfee-GW-Edition BehavesLike.Win32.Trojan.fc
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Malware.Injector.IO2OKP
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34088.ym0@aOn8B7g
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH0CHI21
Rising Clean
Yandex Clean
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ABUB!tr
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.