Static | ZeroBOX

PE Compile Time

2096-03-01 07:59:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004f360 0x0004f400 7.99261399924
.rsrc 0x00052000 0x000112cc 0x00011400 7.48640523051
.reloc 0x00064000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00056808 0x0000c42a LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00056808 0x0000c42a LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00056808 0x0000c42a LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00056808 0x0000c42a LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00062c44 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00062c94 0x00000438 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000630dc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
s"s#
v4.0.30319
#Strings
button1
get_UTF8
<Module>
System.IO
TripleDES
mscorlib
Farntmysydoclptbglb
Form1_Load
add_Load
Synchronized
Ajbziekqdlnjmvgfeoauaamd
GetMethod
Hbzsgfyqpmlce
defaultInstance
set_Mode
set_AutoScaleMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
set_Name
WaitOne
get_Culture
set_Culture
resourceCulture
MethodBase
ButtonBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
ConsoleApp12kk.exe
set_Size
set_ClientSize
System.Threading
Loading
Encoding
System.Runtime.Versioning
disposing
System.Drawing
Wgzrsoqqh
ComputeHash
button1_Click
add_Click
PerformClick
TransformFinalBlock
ConsoleApp12kk
System.ComponentModel
Farntmysydoclptbglb.Nvnnun.dll
ContainerControl
GetManifestResourceStream
MemoryStream
Program
System
SymmetricAlgorithm
HashAlgorithm
Bpjmrufrpisjmlgxevmsvpm
ICryptoTransform
resourceMan
AppDomain
get_CurrentDomain
Application
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
Exception
Button
Nvnnun
CopyTo
MethodInfo
CultureInfo
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
IContainer
Helper
set_UseVisualStyleBackColor
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Farntmysydoclptbglb.Form1.resources
Farntmysydoclptbglb.Properties.Resources.resources
DebuggingModes
Farntmysydoclptbglb.Properties
EnableVisualStyles
GetBytes
Settings
ResolveEventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
components
Object
get_Default
SetCompatibleTextRenderingDefault
InitializeComponent
ManualResetEvent
SuspendLayout
ResumeLayout
System.Text
set_Text
Dhztloknkqwkqiuwfwvbv
Niismzilrxmtqorgawdaiv
Cwhrlbsvhtv
Bkrczmrsdw
set_TabIndex
Helperx
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
ClassLibrary
WrapNonExceptionThrows
Firefox
Mozilla Corporation
Firefox and Mozilla Developers; available under the MPL 2 license.
1Firefox is a Trademark of The Mozilla Foundation.
$309ebb5e-02a8-4ea4-9fea-8de381ab29fb
92.0.0.7897
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
`9Ok\TI
Cy3-juyED
`f#y}@
NuZ8oR
6V4gn>bw3RJ4
3d2aEa
bb:)je
H*phb%W;
$TdrAhE
ad=EOb
wad=EOb
d=dh!J.?
xjyr>Y
63{D3z
csSWxa
csSWxa
csSWxa
U0!DC$
fBo8]5)
<P.vdA{
[(5|3=
OxB>:yx
Fn%zU7
&9avEL?
$UJZ}JJ7
$UJZ}JJ7
$UJZ}JJ7
3e"t^8
,-WwW#VUV
pBk\M|Y
+EWh1F
b(gx%<
#Y7yVF4
Ni{rA8
8hw4>,
qVpr()
t\+]V.t
dg;`jU]@
Bm#522+
rk)Hav
hB{I2@[
/'+Jot
FD'81N
}[>@}:n
O|zPVZ
.!zsyfGOd?
2IagK-PN
ZcVX9J0
c^ldRU
pl[&G2
S>['X4
GVBdgF
/De7V@
f2o32xC{
zn2aky
<]i(_Z
F#B-{1?
+RU)\<
5!_jWY
>w/Pp@
}4HUe.
-3G1ob"
U>OcUX4
owZmc
YzG1E^(
R)0"b
**gpY/
P'rRjr
!??d\3
4^;8k\G
r/L7Ht[ v-2
]^u~rO1
?Y{vV
Wui](0
lHYIQ(
i>uDCn
-#{\ #8
emnXdA
!db6@
>)9Z"y,|O*
qz?Au_
[@`te)"
Cb5svR`{
QG$z}
&]#.=v
G!h-]jS/
(Qj)adA
-5uw[C
*r]`Mw103
sHJnzn
bYJ4RfE$
LUXB)u
(7yTNP
>1:3"nP
,6JoEd
}[cY"2D+
IPV,~XM
8d,]W2
?{k63B
3S2fo,
vo- @M'
PKS&~`X}
|sA-zp3
8?0.7?
hZn82:
O]]4Z?/x
O1S!vY-
&-)a~3a
+_S6$;%e'C
f9"=y'
,uxn3@
G6U'6C
8(z'&~jYT
:Dj3|9
5>`m<_5
h-!Ktjs
+wtt$M
8>x<"Z{"
-<Ezyn
s/dBXX
Ia']]:
)ypOya
,7nvr:
MyGVl
B^Yt~
y+s#B{
B?[':=y
y7wbm&5
n"t7.H@
A$jxr7
w?a3/G
%)2LMW
f8d\OA?
Vo2E2nI
V4hG/l
Du5tb3
eYZ%AB
TXpo~A
e3c>v
':CuZ;s
8m'k'"
pm0Xljy
B5nUJ.T2
%2@bFy
pU`A4$
^&khKd
H:]iMug'
`9u.Jo
$ (77%
0&LRS'
?O6%[$
~L5<<mz
q9-H*"
E69Ef2
1%E%6gek
;`@+ty
o(%L{_`
~jc_y,
9\|}(%]
J%okiG
xosD)1
Q>ax&;Z
D30>WN7
1_uK]q
_IFm@+L
QhJlvM
sxX=pb
0|o`\%b|
U!ldf*\
?>{5/v
NnnyW]
^2wop{K
s^W%9i%
GAPQ0=
t: R
=b>/!C
Am{]ZD"\
lb.l?|
b`s,e}
`4O^b&Z^
$ ~k+R
y"//DI
yxa2f1
cAC&2a
8i0i#>
Lt4~z#
SH*d,W
-D+ae1
l1C^=&
.qk!^%
V7aIz,`I6
c9pcM-
6{7zq
ek`(lNv
"/^8x=a{
iZSc-Dy4
n:<W,]
36H^;v
hxh{cU
;n!A#Y5
rFDllO
I:dI"z
Vm;Al/@9Z
9P~b,<
VE1e#2
(26PfW
C*&;Fs
#sdGsm
(bj n$
V}a 4f
\23cCe~
[=!)?.'
HByVa9Y
@9_q!Zq
DW%SG?
t~s4jt
/S`-E#
["q`[I
?'n$
_#-$@F
*g, ^Z
Odn*SZ
>ew8s@
Wlv* f
;RB&<+|
4-?:,L
%Np*im&&
ZuicW:
;wD2g~
kt&mSG
EH?9L)
M!e1$t
>M%+Zd
lD}`y)
c;fldMzSo
AI2SMs,
[3|F&pq
xx8;DY
lb`EzX
kp6@06
8}nb&)
ht1Ct|
`c)'/A
e_P~-N
XY9@ep
@"Y^]
{8_*m%
Ns>"Rl<
Sk6G}[
A H[/5`
Vr9O&V
`=TJ.-
K)>du[
0`aE3${/
ukF]'~
byG\+R`
N&@Mzb?
iVD(}Vx
][{a<&
8_~.hS
@m,6T*m
"Hx{V1
$fNx5q
~raC+~T
0,D$7?
*8+K?
XqhDYzJ_
a=n$;p=
[s%<7=
|w7\,Fw
wii^zv
FT\Ztn
3G:DOV)
n_L:r_
h(Ptq8
Gvbc*OJ
L5Dx16
fJ5rlC
kFxHv 6
D#*Pj+
G_QG3%
SC9@;
[XwDiHV
$"6FWA
d)d=`2
{V?@_
qMk@Dl
[hHQ.P
=x^46d
#ps5@w
Bw\NI6[3
&\GK76
|8L''1
Ye)p5x
+G=`PS
XD3O+3
'>z<&y
lr'o}H
EMpx[p>
u7J<!Y
c&A<'bc
[L_8})
.@(G!<
"LZ1~v^|
|U^.=a
aC70fE
4*Pzgc
z}z;I-
&Xd;(g
}nW#Oz
nBf\DN
qEqAo?
ekHE~]A
"9MpR#
Suvf;s
x38vO}
zOu|l8/
U(&PILc@
_uS+*x
):4%cG
iYa#C"5
rjj{@MTHs
JA}ziK,\H
?qCr#G
]b}2A/
GmC(6(
._2_z^
WMU'z
kGt"bF
cpBw!O
Wa5yo.
^u;0}]A
@H6oHyMB
hy5L)9
X)HK?A
]k.q~Q
'`#c>M
FxBR^M@
zW]7Bbq<
g@qo+)b
A}R@dH2R&#
p?{egz
QZWIhp
k,"^`
P)z%(Oc
U`pL%CW
8$I~+B@\
`~O/i5
IHvq)C6
40ImCH
F?@5\
WdrqdC
Wo@]TsO
cz_[>1^
u2#:}
9#G]|,{[
}sBv2L
\Ch{V.
)r%Ya2
.dH@S`
^<T&w)
SrXsxi
Ol.&tb
@QYcOF
.r\I~8e
#"g/:ve
y !U/<
Kq16"H
$te*M*]
SD}m@t
EKNEJ2
*ao//e
:GoO{u
;zB]I`k/i
%7B"UP
Vlvu[Z
\g&*0uF"
<G8a(Jt
eiTil;;':
]#`Go>7E
h^L7,)r
QoT9i$
"6fx_K
i-Wij$
ZSR! |
Tjmvi*
+}_&Js
]z{zoJsk
.sHuK?
!ZV4Dw
YCO)I#
n!tHM4y
DqWsK&
9CKKU3
aZ|pkJ?|O
gX<J)D
zeyKYDD
Dq"\L,
Vfm~/JT
YyD9gX
8Q><8eFV
zB<~qb
RI)4x-
{B=p(~
MYX0 C
QiXvvijE
+"Jf@
>dN2i:
20BC^a\
(0m6{5`
pC42*dU
tp{gQ'
W)Yq+j
E.U~%wX
!r32#=w
:4?<9ah
Sjr`I-0X
p0MF/u
,nF]<A.?
Y7R[&C
o#m::R
|QyH{G?
O&+2_w
Tw.%89Wq
mxwUA%
-xM/^{
^r[U$N
s>kUl.C
`@DU#x
`lvlfO
2T!IsW
bXjg"9
|>K6ht
9s0~R<
7Q>5hJxA
v'=Y3y
:jdf8$b
i]?/Aj
03FP{F
TJ(_[
s|Bnu?>3
R1\:ws
.<qNer
`Uq]bM
P$j5n.u
ak @~A7Y
#w*F~y
*><|JA
xFJ.r^
$)-K]
b~z7eS
XS$-:-
R (V.R
"%2k^#
q_mZxXi
^y0JI
i|k>#
qC[y-
BNfU:N
8%iy"8
kbJqBa
RRdRZ*l
!v4F9'
/{6:;2qn
wImHgXK
<~XK:y
YzBmBc
CJfX`[
|n[&sRI
$[CFE~
aFJr6<|
0h*x=r
Q*JHIbtP
qD.yry
^j'9R'*
8{S><#S
R06 kOd2
-{S9&?l00
v.xmUS<
wP[/p
^K/,+)
_0jL;R?
\=iiU6
h^K12
3.J~uI
~^6bA|
}$Vhv:
I:g2ES
m;eg1,B
M@0t(
{~t|m
0LUSGz
G??N*Z5
xc=cIg
3.+J]u
Z~p&aL6
wE$Ddy
o"i|~
NJ41|72
t!d|Vwj
*f2}KA[
sO~/`
9k{meY
,-zH.;
ZSQm!G
8HRe=lL
X>OTqH
ayZpmM
_&As7c
]"$N&R
Egwei^
$}g&%o
h:5l&+
N\&}Ce
AXlD5A
QE;Zd{c
siLY^'jo
Vsg!2z
EcLr:t2
?]*IZh
xu3ejN'
+}e6*a
obHLgo
v<=VgyqE
QIc~~v
B3'?#g.#
5|:qp:
o{p.z?
&#-7$#
kRU1mF
j1sZ{1
q(\Y{:6
7=[qr3
L3e"V]
12$@I2
Fj9\='8
_CorExeMain
mscoree.dll
Z!g'M
W,n%W,n
w3;gxy
rZ18R4G
G+}tq@
1YR*9
#)sb.%
?iNt~(
n5dWW!-N
UlRM:
239^t~o
2yF&@/
O:A2S<8x
~vd8<GH
DiuKL^
3?x<n0]
i%EGa`+uL
^l9d@W
.%gvW
"@{|8(I
& mY(sZ
lS8l8@
O~WRmbS
~vn?*\w
}<9'2.
KC4I)
R+`C0^
q6)utg
U\^&pQ`
dc>I+A
(O*5};.
X|!`_|
Mnc$ T
w;o3ak:
u<{G,K
WJ&{\k
%FA_^J:
hg~Rm2.
H=)RUP
Xeg8i2
-X:Njx3
#CaGF2;
,`v8]Wb`
>s&6jf+
bq`0P>S4P
Y-I@r9<
ftvf&eAg>
7?Qtgq
`)QF)r
<L?x!>
lKX(_Y
*Kb^V]
N%G#u;
R}2z]6
X5~./;
T>BN6r
^=9],`
Opnn}x|
P^fn$?
hBj4r=
d+xA[O?
#erCUxeq
S ;((
@.wLZ-
jF[G.lG
0D+)aA
y]09()a2S
)a;$N?
R-p%!Z^
Wldx&u
oq#gH-71
N[R[-pA
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
button1
Farntmysydoclptbglb.Nvnnun.dll
Bbrfwp
Farntmysydoclptbglb.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Firefox
CompanyName
Mozilla Corporation
FileDescription
Firefox
FileVersion
92.0.0.7897
InternalName
ConsoleApp12kk.exe
LegalCopyright
Firefox and Mozilla Developers; available under the MPL 2 license.
LegalTrademarks
Firefox is a Trademark of The Mozilla Foundation.
OriginalFilename
ConsoleApp12kk.exe
ProductName
Firefox
ProductVersion
92.0.0.7897
Assembly Version
92.0.0.7897
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37428923
FireEye Generic.mg.56be1905fba872d1
CAT-QuickHeal Clean
McAfee Artemis!56BE1905FBA8
Malwarebytes MachineLearning/Anomalous.100%
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005811d01 )
BitDefender Trojan.GenericKD.37428923
K7GW Clean
Cybereason malicious.b36232
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34088.ym0@a4jb6Vl
Cyren W32/Jigsaw.A1.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACMN
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Seraph.2eb0d8cf
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-downloader.Seraph.Sxfa
Ad-Aware Trojan.GenericKD.37428923
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.fc
CMC Clean
Emsisoft Trojan.GenericKD.37428923 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData MSIL.Trojan-Stealer.AgentTesla.UNASA4
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.37429572
TACHYON Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CHI21
Rising Clean
Yandex Clean
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ACMF!tr
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Win32/TrojanDownloader.Generic.HgIASakA
No IRMA results available.