Static | ZeroBOX

PE Compile Time

2021-08-24 15:56:41

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00007028 0x00007200 7.74083668102
.rsrc 0x0000a000 0x00000690 0x00000800 3.61301900095

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000a0a0 0x00000418 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a4b8 0x000001d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
I!Q8Hc@A
&dQp{h
S8BNVU
C6ANs
R=>[b9
vHA;G/
{*/Zf1
M'B00lk
JdL h:
#PNn,lH
D>_'Tf1
; T@.Y_s^
22qSE>
Uv@L(ZBC}<s
}t-4t8u
3P"3:2X
Z5_'4`
>3Dt1@
?7B#F2[tM#
Is8#'.
%OcC}[/W
VA'7'a0u
v88KG+z
4{M._b
at.k"L(iPJ
3Ab4S"
K?('\<
a!yHJ:
5 )?#@!
}8dR~{
r-{t*g
u|n.`)
++~%0?
$7Av*6
"|4GzQ
=?_hH
3OVe33h
<'(JPf
#ctOkL8
W+?`U}
hgBSJB
v4.0.30319
#Strings
<Module>
ETC.exe
dqbjbowvqnoz
mscorlib
System
Object
gqylhfccc
gwajswtivgojukq
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
System.Runtime.InteropServices
GuidAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
System.Diagnostics
ProcessStartInfo
set_FileName
System.Text
Encoding
get_ASCII
Convert
FromBase64String
GetString
set_Arguments
ProcessWindowStyle
set_WindowStyle
set_CreateNoWindow
set_UseShellExecute
set_RedirectStandardOutput
Process
System.Threading
Thread
System.IO
GetTempPath
Combine
Assembly
GetExecutingAssembly
System.Resources
ResourceManager
GetObject
WriteAllBytes
String
GetEntryAssembly
get_Location
Concat
Environment
SpecialFolder
GetFolderPath
set_WorkingDirectory
Exception
MemoryStream
System.Security.Cryptography
RijndaelManaged
SymmetricAlgorithm
set_KeySize
CipherMode
set_Mode
GetBytes
Rfc2898DeriveBytes
DeriveBytes
ICryptoTransform
CreateDecryptor
CryptoStream
Stream
CryptoStreamMode
IDisposable
Dispose
ToArray
sjlqzwhdcmaghptxwtbufc.Resources
mwpaxrsxojqtynxn vfiyiewijx
djimsfptnuidiouxm glfkqyljdfxl
#dwbsyyrgxtkbglfbmh kclkjgdeosuzmzyt
oylbeiieedezrj zcatiqduub
iqyvtkktosvh ylqxtxnfyvrfbfq
ybunchqobniamuf jftjibeimdst
0.7.6.1
$f0eca544-efc6-485c-9aa4-f1891f7b2974
WrapNonExceptionThrows
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="Program.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
wavrmfdpxyzmnomimwllvvihrjhoy
Pv4t9WuECP/KoWYV+oiTOGSIpPFOpWhBCC3ZZc0dJv0yh7HmuVb+onmKSmguj3T4PQMoIh3naT/LF4MpH+kHAlKgK07YNdC9KTgVZlusYd9Notfqxi4jpxXm6vPVKO0mz4WTDMLY5OyYdnq8twgwkJfeh4p7ESceohk11j0gCC6tozfDumG/Y161f7h0sUV5QAsE9AiSd1W2BcdUIsQNCxE69MX4lTGgKm9I3OdGsyTZ+wXFTxPx6xGNIXlvuGFgtMdSQLP+OEOZJu7lBoIwLQtOapo02HtP8ljM3su0z3XCs/DVh9RizasvWc5HgbkBQFL1J2TgXOWn5HWlLjyqPGg4Z9mtfudChFY8xw6iQv/SimBSjKeckDz/hSAO0ikw
hdpsfV3IyhgtzB+qwckokw==
sjlqzwhdcmaghptxwtbufc
wavrmfdpxyzmnomimwllvvihrjhoy
jbnkpvfyzmneltwpbobwlpslwuusakipbcjewgwkralfrpgitpktwlzymrvdjdtpddiwjzlokyxkqxbpeztkzdlrxpockkaqriawsmqyqujbwohbifojyjpamgrykewayybmcwioizcwvrskrvkfinbjcaicjnkxhhkvbecjrziullgkdhswfjqmpubcmmwbpxgiggesxaiofhcubqnspvbxvtfhiarmyncqftdxmaefupitohswxqfbfhnoajwc
ycfqlyeljvkowoqfcitwzsbgoshxmect
iyypukgfnmfdsewe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
djimsfptnuidiouxm glfkqyljdfxl
CompanyName
dwbsyyrgxtkbglfbmh kclkjgdeosuzmzyt
FileDescription
mwpaxrsxojqtynxn vfiyiewijx
FileVersion
0.7.6.1
InternalName
ETC.exe
LegalCopyright
iqyvtkktosvh ylqxtxnfyvrfbfq
LegalTrademarks
ybunchqobniamuf jftjibeimdst
OriginalFilename
ETC.exe
ProductName
oylbeiieedezrj zcatiqduub
ProductVersion
0.7.6.1
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Tasker.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.01b6e15274bdff55
CAT-QuickHeal Clean
McAfee Artemis!01B6E15274BD
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.MSIL.Tasker.gen
K7AntiVirus Trojan ( 0057f9ce1 )
BitDefender Trojan.GenericKD.37479026
K7GW Trojan ( 0057f9ce1 )
CrowdStrike Clean
Arcabit Clean
Baidu Clean
Cyren W64/MSIL_Troj.BCG.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FGN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
Alibaba Malware:Win32/Dorpal.ali1000029
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.37479026
Rising Clean
Ad-Aware Trojan.GenericKD.37479026
Comodo Clean
F-Secure Clean
DrWeb Trojan.MulDropNET.46
Zillya Clean
TrendMicro TROJ_GEN.R002C0DHP21
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1143065
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/AgentTesla.CHH!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win64.Trojan.Agent.2MWJ7R
TACHYON Clean
AhnLab-V3 Trojan/Win.Generic.C4567184
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
MAX malware (ai score=83)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHP21
Tencent Msil.Trojan.Tasker.Eok
Yandex Clean
Ikarus Trojan-Dropper.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.FGN!tr
AVG Win64:CoinminerX-gen [Trj]
Cybereason malicious.21c836
Avast Win64:CoinminerX-gen [Trj]
No IRMA results available.