Static | ZeroBOX

PE Compile Time

2021-08-24 15:54:38

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000aa5c 0x0000ac00 7.8601645122
.rsrc 0x0000e000 0x000006a8 0x00000800 3.64040321752

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000e0a0 0x0000042c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e4d0 0x000001d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
f5QTF55_
Y|l%)
5ZRoJARx5i
b4<N!h
%@')*3B
2S6x-gZG/
GO&vSpD
6Cb",H
''go_]
PvU_k]
8+1U`]G
A[xCov-
ahWI)<
k\w/(S
Oc4q`>m
dPk8!dx.
K9vGAU
X a+joj
}i/`g2j["
8&wWcS
Wocc`|
Ts+-%z+g0lA
9zJQ?C
.%(8)
Cqi; +E
ibn5|
wA]5^
0&vAwf
O2m%jJ
54n}=3d
87P#sYm
BI+&ZR
76``9o
JF"%@Uj
y3"Qx
-M8_=2
:o64.$
%3<sfB
hfxXVT&
+)c97y
I*XKQ
>XGs[u
7VvaKG
x95B6B
Shn8D|
rdf-Fn
eOp3.i
=W]fRcww
9!`M"`
nwbe@{
2PBQJn
]:N'1n3!
A[m9d{
=_Ju8oD
Cw#+QY
oni/P~;^
8))UA
C"{..m
NmZxK~0%*W
n;$M~g
&u~fHzm8C4
kUGaj~
2ls}D}
3f#|v)
k0c|;l
OV31SL
v4.0.30319
#Strings
<Module>
XMR.exe
meibbqzpp
mscorlib
System
Object
sisyxtpohlanyugzruqtiaeopkwogifntejkj
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
System.Runtime.InteropServices
GuidAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
System.Diagnostics
ProcessStartInfo
set_FileName
System.Text
Encoding
get_ASCII
Convert
FromBase64String
GetString
set_Arguments
ProcessWindowStyle
set_WindowStyle
set_CreateNoWindow
set_UseShellExecute
set_RedirectStandardOutput
Process
System.Threading
Thread
System.IO
GetTempPath
Combine
Assembly
GetExecutingAssembly
System.Resources
ResourceManager
GetObject
WriteAllBytes
String
GetEntryAssembly
get_Location
Concat
set_WorkingDirectory
Exception
MemoryStream
System.Security.Cryptography
RijndaelManaged
SymmetricAlgorithm
set_KeySize
CipherMode
set_Mode
GetBytes
Rfc2898DeriveBytes
DeriveBytes
ICryptoTransform
CreateDecryptor
CryptoStream
Stream
CryptoStreamMode
IDisposable
Dispose
ToArray
fxetgolisuddiwcvirmikzfwxvcxvmg.Resources
urzwetevcducuuvmsqm ykvkvnbzjgc
nyppiwqfdaxidm eweyzsvwkiptoorum
cvoeiwhrxi yjlczrbvxwywokcnd
ffsvgdoausy hgfawybicqcfw
nhcedgnlgwff htkblrmxcdkrpqraf
$idhgendgfdolwpbil qeykqqvduzwbkkaota
5.0.0.5
$6dab033d-f5aa-4840-a97a-7d418d22a229
WrapNonExceptionThrows
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="Program.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
atuofgjfpihqexspgymdqwsvabgdpmmkwugcljh
yR7nKjZpBj2tFI7LIuUaVgAJiSkZ45jNDwK8lTWb/eUsFRvkODXmRbfb2FNlEG+NItvcVfVYHLi68mtRVP6s3HaWBx70sOO1xiRTIAzsyjPxQ/CD4aT0Qs82fBy6lpo4TE0QPwwcSTsXdFtIw/SkuNxFOm0XB+mADUgOlJB+nOz57PpoN6YLel6hOLCcJXiHvtqcaJ6kbzWnGuCZgXLmZbcId+KL177bdhBmPiTqqqLInpXIZ7JbuOsFhdTyNQ7xtJNhZaDOZMoU3ztPG4tRSmxTVbvClAga08eO6kJ6EtFaHwc+ky79wimXeTOEoyFI6rNwWC2r5yh49eHF1zjbXl5os31Q+cZqC/yEINHynoa0yBj7gP0VsI57+C+xSA2T
MOorkkwJkxwrdn2RserULQ==
fxetgolisuddiwcvirmikzfwxvcxvmg
atuofgjfpihqexspgymdqwsvabgdpmmkwugcljh
lmwnuettmlttxplmygimturunobqfntbkkfkatvuxqtcywvoftjbtmppjnacifqxbpjoyapalsbfdusqnfjuyplyywshrxxnaydbghddnhtecuiopifrcmwfwpdfzryqdsftrjhusfblgviznwtbbrvjgzeedxdlogqvefgretenxdxtsfquzptigcqtnmtdatiarntohawlsdldacqzutlzimoymipoalmeecskupqxkhudykrvqytrgowmdzcu
lmlplvifvdqcfqoeguzrfbkenjjmtkhi
bniyvvmpiqakgiqb
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
nyppiwqfdaxidm eweyzsvwkiptoorum
CompanyName
cvoeiwhrxi yjlczrbvxwywokcnd
FileDescription
urzwetevcducuuvmsqm ykvkvnbzjgc
FileVersion
5.0.0.5
InternalName
XMR.exe
LegalCopyright
nhcedgnlgwff htkblrmxcdkrpqraf
LegalTrademarks
idhgendgfdolwpbil qeykqqvduzwbkkaota
OriginalFilename
XMR.exe
ProductName
ffsvgdoausy hgfawybicqcfw
ProductVersion
5.0.0.5
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Bsymem.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46866808
FireEye Generic.mg.0f23f1451e66b86b
CAT-QuickHeal Clean
McAfee Artemis!0F23F1451E66
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.MSIL.Bsymem.gen
K7AntiVirus Trojan ( 0057f9ce1 )
BitDefender Trojan.GenericKD.46866808
K7GW Trojan ( 0057f9ce1 )
Cybereason malicious.cf137f
BitDefenderTheta Clean
Cyren W64/MSIL_Troj.BCG.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FGN
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Bsymem.gen
Alibaba Trojan:MSIL/AgentTesla.d03fd055
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46866808
Emsisoft Trojan.GenericKD.46866808 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen14.64783
Zillya Clean
TrendMicro TROJ_GEN.R002C0DHP21
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Dropper.MSIL.Agent
GData Trojan.GenericKD.46866808
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1143065
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2CB2178
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Bsymem.gen
Microsoft Trojan:MSIL/AgentTesla.CHH!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.AgentTesla.C4588715
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Clean
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHP21
Tencent Msil.Trojan.Bsymem.Gln
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Agent.FGN!tr
AVG Win64:CoinminerX-gen [Trj]
Avast Win64:CoinminerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.