Static | ZeroBOX

PE Compile Time

2041-05-20 06:32:52

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00055e54 0x00056000 7.99302488543
.rsrc 0x00058000 0x00000bbc 0x00000c00 5.3413575496
.reloc 0x0005a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00058100 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00058578 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005859c 0x00000420 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000589cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
listView1
get_UTF8
<Module>
System.IO
WZDAN#@R
TripleDES
mscorlib
Bdqobclbvesvevjmiwlac
Ejbjczsagjnkblqpioxic
Form1_Load
add_Load
listView1_ColumnReordered
add_ColumnReordered
Synchronized
Android
GetMethod
defaultInstance
set_Mode
set_AutoScaleMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
DockStyle
set_Name
WaitOne
get_Culture
set_Culture
resourceCulture
MethodBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
WZDAN#@R.exe
set_Size
set_ClientSize
Cniqrpxdjufg
System.Threading
Encoding
System.Runtime.Versioning
disposing
System.Drawing
Samsung
Jedbgkhnkcleqlbh
ComputeHash
listView1_ItemCheck
add_ItemCheck
set_Dock
TransformFinalBlock
System.ComponentModel
Dhjiumqmcuxkxgvdkq.Ejbjczsagjnkblqpioxic.dll
ContainerControl
GetManifestResourceStream
MemoryStream
Program
ListViewItem
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
resourceMan
AppDomain
get_CurrentDomain
Application
set_Location
System.Configuration
System.Globalization
set_HideSelection
System.Reflection
ControlCollection
ListViewItemCollection
Exception
Nlwfkun
CopyTo
MethodInfo
CultureInfo
Emkqpbttgevbnuo
Dhjiumqmcuxkxgvdkq
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
sender
get_ResourceManager
ColumnReorderedEventHandler
ResolveEventHandler
ItemCheckEventHandler
System.CodeDom.Compiler
IContainer
set_UseCompatibleStateImageBehavior
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Dhjiumqmcuxkxgvdkq.Form1.resources
Dhjiumqmcuxkxgvdkq.Properties.Resources.resources
DebuggingModes
Dhjiumqmcuxkxgvdkq.Properties
EnableVisualStyles
GetBytes
Settings
ColumnReorderedEventArgs
ResolveEventArgs
ItemCheckEventArgs
get_Controls
get_Items
System.Windows.Forms
set_AutoScaleDimensions
components
Object
get_Default
SetCompatibleTextRenderingDefault
InitializeComponent
ManualResetEvent
SuspendLayout
ResumeLayout
System.Text
set_Text
Ihzqxzaccyv
set_View
ListView
Zxfgnsiqqngtw
set_TabIndex
Mgxzspdjyouxbycjlpeycmex
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
ClassLibrary
WrapNonExceptionThrows
Firefox
Mozilla Corporation
Firefox and Mozilla Developers; available under the MPL 2 license.
1Firefox is a Trademark of The Mozilla Foundation.
$f52baec0-3fc9-42bf-8d6c-121718e6c36c
92.0.0.7897
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
=vJf0T
:h.V}I
(t2!Ail
E:`Ne<H[)+FG
pK|0/VpD
kSR:jK
Vv853S
QCkmjw
nw`=Hy5*r[
S l+h*
sFQ0kb
oHyc++
lcQ59u
`unj<p
"ThVh?
~v\{p'`
zsJ:wx
ww,YeD
7>(>8vs
m#uhH6[
{6+`m
\>y7d|
Tq; 2K
4LMcke_b^3
jk_;Zg
z-V*{}5t '
1,HJ$z
~UaY%JoA
`pQiPt
3Wze$j
<4;pB]
^J6MLmEQ
JBzAQ|
Rz[>'8
a(tD8Q
lS*)q1
#W*0?hN
^\kk:[y
1 5\X7<
q+U>.W5.F
@.m3ai.
?/bu8wRY
XI4]XX
{//.hG
*WRn#6
W5yVEu
nh<[ y;f
\c2_\>t
vN@p{T
{~<QYT^H
iQ_Wn;
C$-:Vy
*U>W%]
_Hf4VV0
b}t 8!
sW\TpP
^?vIK(
A\c)>#
g"Azs9
h+0Jr
bY]$V+`R
";zZ^D
cGfuKQGD
RN9 ,d
D_jP9'
U<q6QGw
2$;x^u4DQ5TyG
{%)x$+
RcCG*98
vi:(ef
|l&Sg~
:IdC:~
O.m]:;
,>4lVAMb
gH>5"6uq
?^]_a6
Je^b6oC
Lj>\k@
Y`P/}<"
EFiY)+&
N()N.+
:WYA u_
|=C_5P
$\_'Wq
#+DgGuF
Wk$RwY
3zP^Y<i
V6aD`
XJ-m^&
|}~~1L
V4p7r
{\G]+n
OV"NNg}.d
7ow {)\o
2^)-D
Q6#]4|
U'.mq`?
_w%E9O
%!m)8f<
Mn*5U
MbVz%-g
\[2V#Ml
'e"(U>
vs79,\-
a"uH'C
CQ`Deq
DG#|}F
=!BCX^~X
W|\|T*
4 rUSn_
\zxE/d
7_}7 l
wW 0fzM
. aBW4
NZ*'ao
klWMGf
j`=rqL
p>LF]q
0dmw0P
;JuyKj
M3Yrt;
NQLTzVmQ
:Ar;o!Vk
a4mm:
F=(_^'
8Z?U;k
VoT&O0[
Lmld;e
XMu,j0
I9?KtV c
E't]Ii
vpRr>`
r\mtWZ
<b@[43
0w`G>I
ZGvx4$
wwR\vD
SX1Xc7[
#c:P;B[
p%ctM)
$nM@D
)gK%)n
=RA>uF[
eb#VAX
;dHoFD}
w=8ZM{v
VyU*Qj((H
lySLVR
u!lM@?
O8spl+f
s.Z&D$e!u
dfM'G/
&bS{=II
|@pT9JBv.
1#%4Ho0S
0x{ -/
bGQxY@m
9i'|Yr
_ea=Wg
AD?qT9
`2KA"n
o\n#W8
-z*;T1
Cj_ $u
uIm\8!
l$%1"2
fj0s,3
*^eajU
p9f(NR=
8t.G2]
#XvE$FO
5.3S#3
GfDU}|
o\rPR
82T<quI
*@LEj$
r*$;Ta
syig@Z5
W?N7{P
K!u3oN]B9
mW8Nq?&t
R"Va670i
aDX.Eg
$I`3`8
bitE\2
7h*aM>B
E?o*_%
pZQH:I
*`6e,7
-Cvy?q
&95"bG
G|xw1v
=u40}}
K*y`r]
XglX(d2 v
j7yr.CG
y{:4!CC
\ExLiP
QZ7Pds
gx(9K5
uioHs6
T'-&'EM
[>F<5yfqO$
9uXGN0-
g&aU c
vCy]Pf(?U'
\|'1O6%
;Z}C#L
C*HZN\Y
d^<|YziX
I3k&ot
@MV"H}
!y2Z<4
/JHe%c
}m4AmM
7]Vs%@
m5V/v}
v.>Q&>8_
ZYz'.9l
=n[Nd$;
,5kg01
1D:Ks"
"*L|\SFM
I1$P$*~
Ga'z$Uf
3Dq.FN
6d48wQ
twi}7X
S=9poA
HF[/|F
xtQXTh
.,b!<#d8
mq)>{
FBNo!
+2;ZV\
U8|\An'`
?)&4d'
B?4J`6
NNV:FGh%
T8E6c4
uK5v)w
"/f{aB[
Y#ys"ID
4|j?wd
&1#N"w
?{ogH|8B[
ULin!3
]H.H &
UWUHWQ
Sv!J*$
={?/}P
Ta=i1vGXG
]GaQ\.
&$Lkx%
w=g55S
v)}rmL
<cbN;,G
j:=)_"
^{0{,+r
sgMX.x
0;D"{5
*`55p
` nUzhS
Tewb_e
0S.eE,
m2EQg+D
yd:_.B4
hKz,)9
S3goE:"~f
&W(E^z
|^tvq|We
RzMhd"b/
wh~1=,]
Gr1Uw/
\Tunc<sA
N(qdFM8
sL5+oP
v{ov3T
vfZJg[1
>7QUpl-
b<Bsg5
EMO#;p
}t)6o8Ag
?nu>F]LL
4bgjB,K
JPB6N8}
^^-o[h1
ClS+>~
)B=DHB>]y;
$+NABE-
VdqE75Yy
:}6WWPLF4P
Yf^AAA
W}6$>!2y
+P/ODT&
tU#:t%V?
l0BHlL
^hV,7B
gON9I
xEO8*Q
G56g\uJ
92j^L2m
AT=c&eH
D-UdCbR*
6IBrpW
MtrD4
D>0:t#
?~ih-J
Z#iho!
"EQ+o
suc0./T4=
.QPJ7]
t/S$BG
Jj&ZWSC
FrF0"#@
-]V-q?
(L[f_
]xlBcE
6mR6]@
er=*vX
yh\^0F
ZwS5YF[n
o;'}_I
yx2Vi[
C,=jip
x2\R%d
lYsC]l
Z#u\Y;
CF`8 u
tb:nmQaE
At2HQB
.|?b1o
4/Kq6F
X&=b4
@Ymeh$w
R"3.21
:L%2y
Bs}!5s
{6'/~Wj:
l`16D^
b)GT0Z
$gpfL
&vG}9
q5UM(W
4}'*Xh
F/YTFZ
Ptmu/q/
S!oH;j-]6
@L,}04#
_k&=+"
m:RvAy
6|:|QFx
HI+!x%
T|-?P,1
VU[.?`j[;qb
"|-v 8
mkVIz:>;
,@O6`]
lib0R5
``^?%o
AAw,b0
h@vZyQc
*ymiIe
=9I1x
h{58y2
1z3Wa
zlSUhM&
*JI{H\
n.9cv;}
X8S^"~
"dT_f:
,?mUnT+
x"K9->\\
g{oHWS
:wG"U\
U^L8vfH
)#p5D!v
!_X"EP1F
nu-NS*
qn*Po6
X#N/%j
Mg&9Uc@,
s{JdT
Ka)RHfrDl
\v-"Ly
zD42ry
Z{#0Y')2
E>wOF5
x2s1lq(
*V9c4r
iC]+C)
Z'4uE,
F3|eBn
"!D9#I
r6I~G5
Pt9"r{
%eVAu:
$"z7{Px
sS7#~,x
yK'UlM(
iLSy+YcH'
f"d}oK
Y"dwJU
IoCQML
\JV9.L
E0UM2b
%?q5eP
"J;zeGQ
\:(^oh+
Vqg{t]jK
*C@k.K
:HyZcA6A$
TA-2,rO
Ayt)B_
-b>wF]fg
SevBZ:Q
&l594c
Soez<'
se=xaz
$%yp,k
W-(Mm2
7f1<|%
SB/>7G
G%zhro
O'kw|i
YZ/rMG
NY4Qv!
ztj2qv
&$;#s:f
7}0="BQ\g
B\V!v_q
&ZBzR
<D`FVE
|J\gjB%
J.-zJ!
FG7=:Z!q
3`H*k0
9kt^Cmi
!Xl,m?
hNr2P/1
zq0=tX
{fQ0r?
Fw)O=!wJ
T5FP2%]
i^DCHS
W=o_*bQf
_c4=EX
:TAaN%
%">QNo
')>wr
~Y@,FKd,
m-}Do,;`
?8lLfG-m
kqYs!F
}`E[)A
AplpY2bx
\z?#TKg
s|Q-:mE
2cWM[~
5!=yr,
4DbXp"
Kz2|3o
i=6*Nb
4*d1;t
U~XT`iy
lOV(N]
ajLif{
u>8[mq
c=>Rzt
joNWiR"N
\7wrq
_n4gwUC
vnw<PuKB
z2wHpH
48H v$
PQnTa,1
'$+{^C
SVq=aS
83."$/
cfV#}"
$=ZO4^e
HiJ2{|
\Tm's"
q\|9K_,
ZqTmJz]
Y_6A}-(
R)b*~J_
J&{"z<
Pid_67
cj`m5|
>I+t}>|*]c
s^!"x!
J{JH+
WDFd\toO
@|e?f{
7fwd}9
UQw_b&<
8E.)St
WETgGK
^oSt'g
:BGdR&TV
~G|=Va
M_"a](m
J~%|JSM
e*"'vdDd8
` t$==?
Y+?u7
Ov6>&zbm
Kb;=DT|
x'>>2pp!
a\13oz
: fXN]
L:l4T
GOdAYh
@aV:6U~
-OODO%
+FXZn`
U<"ygs
i!SCq%d
"Y92R}_\X
G:0=r<
glv$oN
4=IR_1Y
f 5E2sZ?
;^x*%jp
7)KA8/F8
Oq5dgt
Qk3o6E
c(gT=kG
T@ sM]+
%amqhK
me2w3^d
D*ni,B
E{x[,N
u$P|3-6{E
'7n|ic
vD?f<*
9yF|@}Y(
Dpv2[c
1S]fxe
"##@tQ
?`j2WLz
{m'bXN
bW0z+N
.(]l,^u
0i}*h_
H-%'@wh
jEyqX/S|
.aO8mk[
hRYpRo
ir8g)i
x5dNfK
FaCTKx<
MvEP.8
*<Pdj|
4GqY<^$
:Or9@)
a`Uix0
FbXN>
v)MyX3
H^F+AZ
uNCi#r
uz>[|(D
JYc9}yp
A[:rNZ]
S*.'&~%
9XL`<!
_1I,5u
#C6ehH
#2&Y-J
u;|g2$
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
listView1
Dhjiumqmcuxkxgvdkq.Ejbjczsagjnkblqpioxic.dll
Pwumdgcxwlzqejsmydie
Dhjiumqmcuxkxgvdkq.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Firefox
CompanyName
Mozilla Corporation
FileDescription
Firefox
FileVersion
92.0.0.7897
InternalName
WZDAN#@R.exe
LegalCopyright
Firefox and Mozilla Developers; available under the MPL 2 license.
LegalTrademarks
Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename
WZDAN#@R.exe
ProductName
Firefox
ProductVersion
92.0.0.7897
Assembly Version
92.0.0.7897
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Seraph.a!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.3c06ef80548abdb4
CAT-QuickHeal Clean
McAfee AgentTesla-FDAW!3C06EF80548A
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.063a00
Baidu Clean
Cyren W32/Jigsaw.A1.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACMN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Dnoper.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition AgentTesla-FDAW!3C06EF80548A
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Malware.Injector.Z2D1D9
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34088.vm0@aytg7lb
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CHI21
Rising Clean
Yandex Clean
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ABUB!tr
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Win32/Trojan.Generic.HgIASakA
No IRMA results available.