Static | ZeroBOX

PE Compile Time

2021-08-30 02:22:36

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00006e8c 0x00007000 7.74298422889
.rsrc 0x0000a000 0x00000638 0x00000800 3.6519004501

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000a0a0 0x00000400 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a4a0 0x00000198 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
^6,&';)D
[1t\pR
5-k=a7t
pbh]e3
{p#-?G
d.*#\zf)>R1
9)SX;b
3+z_b.
8kj_-_
[UbB]k
y\L{mN
+3vUx#
yW;:j=
.Sn#@_#"
z}fKj\
C7Q|D`
>RJ%:Ft|d
M^|B^Y
FF8l>d
.nv?v$V?
h~{=Bm3Of>
dzAQ00#
2Q67>R9
]Py~/+
_kOgLf
ZNk.Y
~m_zl30
?2C]c67
va[;P/
Nq|XKf
_~N,2:
.~#K:
RG%x]c
s{V^qhWG}
ZN7/Nj~
Z~rTI
:LopotZ
x|kH}eY9
v4.0.30319
#Strings
<Module>
eth.exe
knlzxijufbwwyoezuo
mscorlib
System
Object
lmudxskfdxdxarpkiaatbfpmz
pzgwnnmmpnzqvgourjxmkghgluaeti
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
System.Runtime.InteropServices
GuidAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
System.Diagnostics
ProcessStartInfo
set_FileName
System.Text
Encoding
get_ASCII
Convert
FromBase64String
GetString
set_Arguments
ProcessWindowStyle
set_WindowStyle
set_CreateNoWindow
set_UseShellExecute
set_RedirectStandardOutput
Process
System.Threading
Thread
System.IO
GetTempPath
Combine
Assembly
GetExecutingAssembly
System.Resources
ResourceManager
GetObject
WriteAllBytes
String
GetEntryAssembly
get_Location
Concat
Environment
SpecialFolder
GetFolderPath
set_WorkingDirectory
Exception
MemoryStream
System.Security.Cryptography
RijndaelManaged
SymmetricAlgorithm
set_KeySize
CipherMode
set_Mode
GetBytes
Rfc2898DeriveBytes
DeriveBytes
ICryptoTransform
CreateDecryptor
CryptoStream
Stream
CryptoStreamMode
IDisposable
Dispose
ToArray
ffufdedxdrmwguqwilbkh.Resources
ConHost
Microsoft
Windows
Microsoft Corporation
(Microsoft Corp.).
10.0.19041.1165 (WinBuild
$01ac6c4c-421c-4947-84e7-972a66dd8339
WrapNonExceptionThrows
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
otkdstyylyurpislwqecczepjjbq
XcJ4iY7b8jCdTNELXUg8NhVX4bQS7kF9anQ8VgPDhlrVdUsmaK+meoTFF/Ype1Jx4Wq/UlXEb8VItwa7IrEbiwiVwwoYcyUXgIcrns0H0TTTod3LTyUOMpGZtcq8d2L8iaw6+mpHXXAGDmqy6ZFiy3sjOHT0tTwfF+Y5dkcPX/fmzfxRQPAxOLYaTFn23IFG9GWcfTlpRqxpgbwXehXIuw07n2Thyo2L4xbnc0OUHRxP50HWRawFWc55DdtB4YyMNeWEvjUXuqhWeGTZ21SgIEGSvD1FHzd4119q9vW0tpXEiXFSWfRd0zsU17rweB0fxc0S8LlvBLfQdPfxyfV/dO+bcF91ghdPVn4IacGrL6xJ9ozjRfjPSh14XMlSmthB
FKjLOXjH5lyRSOdSqycoVw==
ffufdedxdrmwguqwilbkh
otkdstyylyurpislwqecczepjjbq
sckkbbcxwrlugtdjxoinkpzcyrlvhrygknhuhviaquhhnqdbvxtvphglxwpltsmxxgkqlrsdaieprnfgwtzjxoesiconfltlvkjusptqvwbsnebgjtxasrzjmjmwbjxpfdbhttdozuwybqjgsrtiqrjwlavbzdyurfxoiuimwjaedewqzyqlmllivectokpvsndpwuyrbnhfenkvutbwmhvfnlbgpfsftgwklpxwacrxdhgsfaxgelfbxxxdmqmp
mdukwatcyeqvmxsufnaohcohayqwnboi
fnhauvifrsuaxjdz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Microsoft
Windows
FileDescription
ConHost
FileVersion
10.0.19041.1165 (WinBuild
InternalName
eth.exe
LegalCopyright
(Microsoft Corp.).
OriginalFilename
eth.exe
ProductName
Microsoft Corporation
ProductVersion
10.0.19041.1165 (WinBuild
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.5c28e053a7702cad
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37505152
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Trojan ( 0057f9ce1 )
BitDefender Trojan.GenericKD.37505152
K7GW Trojan ( 0057f9ce1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Clean
Cyren W64/MSIL_Troj.BCG.gen!Eldorado
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FGN
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
Alibaba Malware:Win32/Dorpal.ali1000029
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.37505152
Rising Clean
Ad-Aware Trojan.GenericKD.37505152
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.MulDropNET.46
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.GenericKD.37505152 (B)
APEX Malicious
GData Win32.Malware.Guimpost.H871DA
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1143065
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D23C4880
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.CHH!MTB
SentinelOne Static AI - Malicious PE
AhnLab-V3 Trojan/Win.Generic.C4567184
Acronis Clean
McAfee Artemis!5C28E053A770
TACHYON Clean
VBA32 Trojan.MSIL.Tasker
Malwarebytes Clean
Panda Clean
Zoner Clean
Tencent Msil.Trojan.Tasker.Swbg
Yandex Clean
Ikarus Trojan-Dropper.MSIL.Agent
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Agent.FGN!tr
Webroot W32.Coinminer.Gen
AVG Win64:CoinminerX-gen [Trj]
Cybereason malicious.b95495
Avast Win64:CoinminerX-gen [Trj]
No IRMA results available.