Static | ZeroBOX

PE Compile Time

2021-09-06 17:29:02

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001a314 0x0001a400 7.80882486923
.rsrc 0x0001e000 0x00000640 0x00000800 3.38645363563

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001e0a0 0x00000408 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001e4a8 0x00000198 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text

!This program cannot be run in DOS mode.
`.rsrc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
}s .f
H_2lT'
U$wflf
;6rDio
K'y<m
<"6ew=3Oso
oj\wQO=
kjyqfP-
.MpmO
bAtJQl
<F!1o=Fg,
y97Jt6O[
I`DS\X]
8Z,g>M
'.S^Kzc
!/AZS"f
ANnGK:
~{A4s@
=h*<;>@c
Xas!zK
z3;W|C
Qa{h%6
,2W`B=
-iynZhew
O~46Lh
~^]J)L
s9yv\X{H
QR\\$KY
SpkrK,?
$}9q/[
jg$EL`
X-VG9w
&]3;G{`
n+<y,
mZnp8!8#
r*zbW!N
Vqny!D
Uj 9{)
'a+d\V?
+ K~#:
VGUR?@
Vn~ruX(
]V:_)}
_jd[/G
xW9os:
M![e:/
fFUo2s[
m18Vi5G
9)dljt
_spMS'RM"
%M[7?B
rkUOwue
egg!22
0GwJ$
T;jh5Q-b
"v1O14
e`2|'</
_7fYlx
0haiqb
jc|k~l8
ioC$_p
aT2 &d/kJ
prK%YD
zgM^?<
=w#oHk
~4W@*s
-$~U7
vMT4%c
Gmi"8;
u?kL#`^
B;gQIu
N,@[4A
J_m,#$K
sN b}[
+6E`+t
`bG(a<
o2IPoX4
?QvGVH
R8?q.V
3iq SV
<G[04~
}|y|9I
bK-gTa\
45HxjEQ
Y<D-l5
+ a-#e
}DEW\4p
@8$ y!,Q
iM+X6#
GNH0IS
:3WFME
qL)\2&
:6!Vr-
,s`aIn!8E
}"fZB^Ft
Kvt@z%/
6$He!8o
mc$7Ht
l.h7KnQ
_ZR9Oh
_>72iIK
"5VbFGo
-}T8>HU
9L%]i*
0p_Y+,
,^!T["
w-[Vty
(xB(!TM
o3[&ci;
0yA@{%
w?eE.U
Vmze;C
@su%ug
%Xq'd_
$ nEu@?.
C?Vf8L7
>WFZ:Tv
Bv)78~9
%!X3\)
]3~X~v
,Q.=.k
LI$aN4
L`8[Kn
n59,i;
|}KczP
Fy~c5[
HBSC}"
CS1+\
R57(v
zY_)%/
8Y: e:CGk
P2E#G`vP
cl3pVz
J=U]T{W
rx$P44
Rf^|.X
e0+"eN{[
TKSTy_
4*d'z_
'@,*W0b
2E*:s>
Z~b6RUq
E%Bp0CpYn[
IpM0yo
]y,ab
|A>r98E\U{
'<*2HTR
U"QaKZ
TziS;)
\!NiXm
,m|o t
0*Tc
L_:>9k
Kpp)oQ)
[1\l)X
/ct,Qd#V
]>a+dA
}F8]b_
3HLs).
TKXgKp
B]tQP+
?$QVx:|
v4.0.30319
#Strings
Form200
Form210
Form220
Form230
mn34Kj3WhGWQnZygsq30
Form240
Form250
Form260
Form270
Form280
Form290
8zELOh41KbIjg4NovtZ0
Form201
Form211
Form221
Form231
Form241
Form251
Form261
Form271
Form281
Form291
bcAZ6sMiujlDvodgt2Z1
oEkRwKrW630OG8QZ6tv1
Form202
Form212
Form222
Form232
Form242
Form252
Form262
Form272
Form282
Form292
8KKDT4GJcXOTnGCccsC2
I6r0Hxp4xDOoBd3VSpS2
3CEUIFFJ68MVLRlDHZh2
0NFtZK8FQBTzzImSG6q2
Form203
Form213
Form223
Form233
Form243
Form253
Form263
Form273
Form283
Form293
kYaGfGe0D2ifB5dKjXP3
AvuXBxG15AFAakoFmgP3
7uynO9TuQMQwBXsBCTU3
tLkhYB85iaaEXTJnhdY3
aN5mGaFVbvhoqoTZEka3
Form204
Form214
Form224
Form234
Form244
Form254
Form264
Form274
Form284
Form294
Form205
Form215
Form225
Form235
Form245
Form255
Form265
Form275
Form285
Form295
t2pByeBW4NswuzWvTPQ5
wBhiWdPF0jVSckKnnHU5
iWXH9XHG0bkvK0OMolY5
eSmp4ULyUkxtmd3Vtdc5
J5jOs1iGPauP67pMXmm5
oFzDiv9Kc3OEC55zsrq5
Form206
Form216
Form226
Form236
Form246
Form256
Form266
Form276
Form286
Form296
aa4Pm7TuqfmkQZzH8oC6
rzswjgvsfwWA3kyGDaO6
wbjzysjqzKiVyZsMLht6
Form207
Form217
Form227
Form237
Form247
Form257
Form267
Form277
Form287
Form297
Form208
Form218
Form228
Form238
Form248
Form258
Form268
Form278
Form288
Form298
get_UTF8
rt6q3XKcp5KwhdQYPjV8
mmty4RBxLpZcDtKzfCW8
Form209
Form219
Form229
Form239
Form249
Form259
Form269
Form279
Form289
Form299
eF3iNI9120MuXNFOOnT9
e00BlwXmS1brJRHdYlW9
jq22OAi7nqc523ixtWe9
KXrF7VpDN7aGHlerTRi9
<Module>
znMPEiXxPL0v09XnRD3A
zxk5g8PRKa2VenbubHVA
YaLyddneuhfq1DTGS0gA
Z1S7CLdqrRQ4h2Krrf1B
uo825OL7rpZ6cDbLI4RB
UZ4Oo5l5tASMYwZZyaiB
p7mp21ROedIUk3W9H4mB
BCNzQ4UWqrYmy1Pf22tB
laQOCrBsrd2r0H49ah2C
IjoWtumzE1kbWbP10jkC
kqUGIV3An5yQ1U9gRH0D
oK5jo4NWgCn9fv3pvl8D
B50oo8pZFzSO8B5fOTDD
j2PvTCwdNoxmphOKLmGD
MrFcmnmLqwlwFN7R2lID
jlEEgYqC5NmwpSEQieqD
tRp7dNss1yrlAXgpe2rD
dykjIdUXheinpKy5IDjE
8ZneCmS4yB12uRV9erDF
wQMjtGUwS4fbHqMWf0EF
JmU2L37pmkYPLHhIQXSF
J5D8PcT8NURcEG3qwGCG
gtcNnegLoR4o9LbovdCG
VsQK6QCGQZgzTYdiRUDG
Ey1q7islG44KFhOSjqDG
H2Ov2VI7MwTqXXWwMsIG
qXY5QMgTsfYE4ZtYvCPG
m7T7ZWufKrhriS2g6ReG
EBz2QCJi4diTGorcWUlG
OjlzXaS9yCoMW5pqC5EH
kmpx0qvK2cEcuN971HHH
UaDMkI1fBXkGCsc896fH
uiCMppjDPfwbyuERQRnH
xNQThWl9AY1ou1R2ewtH
URwfrUNajeXIsff0dnHI
get_ASCII
7MNsv4BhzieYYim27h6J
383rFWjhfs44dohdIDeJ
ilV2Zas6KmA58mKkJbvJ
Ys5IXaF4OsJ9gmnuPi6K
eAisKFUwEZenl3ZnZVNK
xIOqvShhYb2AppOIhYYK
zOTBmOa7CXu2KnaS5DoK
iTdMJp3HL7tknKmzmjoK
3fTLRb9loRU8qzM6KV5L
FP53Ya2Wqw99iYTylqPL
AZGc7pSroqxUvKv85HfL
AdPVDLggWjxlDnJX7uqL
IgJb5JzjLngtBx6wyyDM
2Js6G2S9FM4KQR1Qa7JM
zKIfXI1mJAP0tswPwDWM
nlIhujAIyDXd9doKU0SN
wAE7SlQxXWkafPlBbdaN
h49hrM8dVC6Ux2z4lskN
OOAZlN3XVYYALNB1syoN
System.IO
MLuRqN08d1KB0UFTmvRO
vKXU57x5GKjbVk1yJs1P
r8E2GBmINQc5fgO3kHCP
M90el3PGOITsJpNd5HRP
jX8BUm68Px9dcuzYptdP
3MTftfWdL6NBcfL5LTiP
QfE7PxmJmFpoVeihun4Q
SA8LyscdNVYcDJtqYhhQ
DZ1ThGGUljCwX0EeiMoQ
9yAYj3QoffuuiEwjeVxQ
rqXYPivU1Ts7O6weBB9R
8YyvCPvakeLecsl09YcR
ow8MgkMLsymz3rG9PIjR
vxtJqhu5SPq1scr0JauR
n1SFN5XjUqq9SH352OHS
gBQpSdmnHOeKyJGYoeNS
8JiGQw8O53u7rbjsC1ZS
Liugn7g6AnzLThQI3ChS
2lPA57M6m5y29tXoNvrS
qf5z5mIsdOVLO9fy1JyS
lZjTtEAYe0CpmPbxei0T
fpD3KtnwWRpYR36NrWNT
7Yc5N6JmFBtd1yzOSOXT
noxKHSBcEmfj0wVCXmdT
SfjSr98Su6pMzNlhsN3U
f3ACOwOW6T0FZ1zmR74U
L7RzRgmXzDl7fY4YeW6U
bEQGKiBQarYAVhISAl9U
izMvQFYebnzdpgnKEqFU
83SDGnW2c78H9h4x5jMU
0We4yUkxRBXguSoQj03V
2Fs5Cd8Hj09KaZr3iRBV
lOW12iFaqy7kn4hjFUCV
T4TGNRcJpdXs63mjBuDV
kuAu1cwrfd4j3ZiECIOV
cQ9lvzq79WYH35UkpCUV
GDztk5hMl0m7dFTmC1KW
yTAWGvMMt7Dxm3mEPDXW
Td9qVAYlzuy5CgyEi4cW
V99nuHcJHGnfHJSD18rW
BlEymN1nobmcLKE7zqsX
pN3m0yK16EJqdIUvKaXY
5biGfIm5xGEyuYTGVTtY
IQKT2cXg5TyGBAm0RT6Z
yx3KqFdvJUzBlaoQGSiZ
s4AiEuSdDR1G3ov5afwZ
jTacU895ZisWCWIxcQ6a
EoyB4gNo1M3ZGVGhjLHa
0mpo8jQ1fm73XMAgMJca
faLzBihDvXkfnOgrtrma
XQDgGQq9XEs6WI3lEHZb
ekiAz4YVWbCiowT0gBab
mscorlib
nN0CVIopgUTgPcyxlorb
zMxTPxeCzJ8zUgMCF6wb
e0CsyqSmrA3VwAF6zaLc
TV6do1IlK8fZ1PO4L5ic
E4YyFZ6alIajTzZjxDZd
Thread
RijndaelManaged
rcQaHpDzhaQiK0QIOdhd
bkcgtfhbalfmhwsfacurjkd
NetGuard
lxA7sZWiLkFtjFl5jnzd
LhF1mgk8N01nSOctsEAe
ZVJfSiZ8SE1SL9YhCCZe
set_Mode
CryptoStreamMode
CipherMode
Xenocode.Client.Attributes.AssemblyAttributes.ProcessedByXenocode
IDisposable
set_WindowStyle
ProcessWindowStyle
set_FileName
Combine
Dispose
GuidAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
BabelAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
AssemblyInfoAttribute
YanoAttribute
DotNetPatcherPackerAttribute
BabelObfuscatorAttribute
CryptoObfuscator.ProtectedWithCryptoObfuscatorAttribute
DotNetPatcherObfuscatorAttribute
DotfuscatorAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
PoweredByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
set_KeySize
gwp8gbxmy2dJiH617DQf
3DECWP6N0r2KhTZ1yWSf
System.Threading
Encoding
FromBase64String
GetString
4VgWmgHZiDn4YXnHz1tg
WbkHBJNc2ISc2i6ivd4h
tPiQWEhzJ7RbIV83e1mh
GetTempPath
GetFolderPath
ObfuscatedByGoliath
EluxGukgfzN3K7XdxsYi
FqEMDZIMmbk7SEL9Zzai
7QIhHvmKVjIe1FFP2Hpi
6Pcbcr3HjCAJuAVULV1j
jNOUqG1RimzRZDV1gPBj
e3rQNWHFlGBqUi0v4yIj
T1zDytuHh6eOOiPezSKk
WP78bxR6sghK0iCpOhRk
AZA72KpTBKImUqGhAWlk
jTS5p4lyXDVbhhDJH46l
IFthNXWQjsGPtZyZpnrl
vBH1bR7oYcf4TYyIgL9m
nUxhPGNb33gkezYGrcPm
CryptoStream
MemoryStream
System
SymmetricAlgorithm
ICryptoTransform
4D12TiTxB96q4SwuK6en
DI6AxKYekCXxPYZxCojn
RgU6hYw8I6WC614cSokn
get_Location
NineRays.Obfuscator.Evaluation
System.Reflection
Exception
ProcessStartInfo
6DUwnouJgNZP2G9Al3no
56ybUDPVo4ejQNNxGM7p
g3cd59XJoJilIuYaZJUp
C07FPKY4rvqEtKEooljp
Q6xXlFDKAecsMI8hwUPq
cfgheqsjwrhjmhhagdkaq
iV1QZdlRrWavLNgRpMBr
VJ1SusGqpxShau2PfkQr
VIGO9YMiYAaUZCgXNnQr
SpecialFolder
ResourceManager
vggcjqedor
ObfuscatedByVapor
dotNetProtector
CreateDecryptor
DETztqglP7mHQaGa9jpr
BUGHx1X4HjRJvExWKhqr
XMsKB2AjWAIdfiAeEvvr
Q2nzH3JUd6ZCkkcK0hwr
Ty7vDGz8OGulhRUzvQNs
U530Q9Z0BT8ZPoG85wXs
System.Diagnostics
oyjXl8mhXykk4Uipcfds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
efsccbegigqqbyftxqavfanehnetqqgvvysyws.Resources
Rfc2898DeriveBytes
WriteAllBytes
GetBytes
Process
set_Arguments
vSbOpLe2wvWKkVpargGt
TGyH4TN7MxwZXFwexqNt
Concat
wnGKgWr8S2utzUEgdmbt
GetObject
tFpIU8vBZIOhzLP4Lxft
ImRwxBfwNQFcN9WAmkit
Environment
Convert
set_RedirectStandardOutput
System.Text
5bzkjelol6Ruoj1whROu
rNEeX880cSJUaSynmuSu
gIsbnIfoOiwmpbNfdT9v
5rwKbL9v6mU7srybn4Uv
kXevktoVQQIqYnHx0rdw
set_CreateNoWindow
YZwJQBH7LwwTnd1kf2Zx
TH5SxI5WbikfF9FLDAbx
qud4hANVW1ThK7PbSqqx
bIhhk0IceQoA1XM4hgtx
WkcqR5dbViTcaryEyXMy
cMRkh4BE6PEUZ5wjr9Ny
ToArray
System.Security.Cryptography
GetExecutingAssembly
GetEntryAssembly
set_WorkingDirectory
tzZes8PKwcXC7B0yYLCz
LbkzrGfvunr3sxv70VJz
yIp4vxX9cnzoqICiZCVz
2GHLlfT6BCTFoDGDwmnz
bPyBIenS4M5ewkF1Casz
VLC media player
VideoLAN
/Copyright
1996-2018 VideoLAN and VLC Authors
KVLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
3.0.3.0
$6a31c651-e222-4542-8a88-2670c55f4f70
WrapNonExceptionThrows
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
tewlfrpexqvewrbtivpwnfkyry
=.#'.+K.3
N2ZHZlZxeHgzU1VqZ2RieVF3aWNBanhwc2V1MFkyclVvelYrajVRallJM2RFOVduZUlBYmtyRXVncDlsNGRqdWZCclZyanJZaUZQSWl1K2JsMUczTDRBdmV4cWVUeVZwd1FwZEZBdFFvQ3NpWGR1ZHYrY0M4d2FkVEpTNVFyU240c0VHREp4WUpDUkhVc0xMRVV4QnRhOHpTeU9nZ2luckNFLzMxU1UyQkxqenI5aTl4SjE5RmUzdGdJOGw0ZGtVN1hMZE5zOVJBK3FLMXVaT3hhK3c5Nyt2SklYc3cydGFnaERxZG9KMFBHODZucHN5K0VZcjF5cEdGRlcwK3p3cm1ZTnB4Yng5UWJERU1YV1cvYkZmR05BUm1xRUo2T215b2hKVWJ1MmwxNkRPVGRYNnhaaEFGVzNkeDNzM210dEk1MkNqRDUxek1iM01FeTd5YkxSQ0RxS3B3UU0vMjI4U0prVVJ0MVA0cUlFb1hZSlcyck9mQ1c3d3R2Q3RSL3A5
MlA4azV2aDdPeEl3cURteE1LMU9vUT09
ZWZzY2NiZWdpZ3FxYnlmdHhxYXZmYW5laG5ldHFxZ3Z2eXN5d3M=
dGV3bGZycGV4cXZld3JidGl2cHduZmt5cnk=
b3FhcmZxd3JkdG1wYm54dWxqdGFtcnpxaWN2eWp3emN2ZGVkYnduemp6a2V4c3ZqcG5kZXRwcmhxb3ZodGJqb3R2dnBxYm1jcnRtbWd0ZXlzdWJla3l3ZnVobWd5eXJlbXVjc2hmdnZzaHp6enBhYmprZ2N6bnF6ZW1kZmR5cXhhbGF1dXFxY216cWR5ZWdjZ2N4anF1ZXhoeGlyYW1tdGJzeG9wZWhjeGpnYWVqZWF5aHpnaWR5ZXZzd29tdmN6aHZrdHJyZ21wc2tkZXd0eHR1Y2JteWNwcnRub2F0ZmRxZ255emN5ZGFocnlicmFydGVnZnpkaG96eWF6cHRwZw==
Y2hwa2l6eHVzYm55ZGxjYXJsZnlsYWRreGZ1ZXZ5cXQ=
dGtvaW1tYnl0dWRna291bw==
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
VLC media player
CompanyName
VideoLAN
FileDescription
FileVersion
3.0.3.0
InternalName
bro.exe
LegalCopyright
Copyright
1996-2018 VideoLAN and VLC Authors
LegalTrademarks
VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
OriginalFilename
bro.exe
ProductName
VLC media player
ProductVersion
3.0.3.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.668351
FireEye Generic.mg.6557d0d59d2e4dee
CAT-QuickHeal Clean
McAfee Artemis!6557D0D59D2E
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.668351
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren W64/MSIL_Troj.BCG.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FHJ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.668351
Emsisoft Gen:Variant.Bulz.668351 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.CoinMiner.cc
CMC Clean
Sophos Clean
Ikarus Trojan.MSIL.CoinMiner
GData Gen:Variant.Bulz.668351
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1143065
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Bulz.668351
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
Avast Clean
No IRMA results available.