Static | ZeroBOX

PE Compile Time

2043-08-28 16:52:54

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00004ff4 0x00005000 6.10474417682
.rsrc 0x00008000 0x00002f38 0x00003000 4.93094926218
.reloc 0x0000c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00009aa8 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000a950 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000a9ac 0x0000039e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000ad4c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
X gHE@a
la AH^
r)2Y
#_ER
b d%H%a
v4.0.30319
#Strings
XXXXX43$#f
XXXXX43$#f.exe
<Module>
Connection
Utiteqzllhwefrwpjya.Common
System.Windows.Forms
Expression
XXXXX43$#f.Maps
Object
System
mscorlib
DispatcherEventInstance
Utiteqzllhwefrwpjya.Instances
DefinitionResolverConsumer
MulticastDelegate
XlSortDataOption
ExpressionComposerID
Exception
ValueType
ProccesorMapItem
<>c__DisplayClass26_0
StubComposerImporter
Utiteqzllhwefrwpjya.Importers
Resources
Utiteqzllhwefrwpjya.Properties
Settings
ApplicationSettingsBase
System.Configuration
<Module>{012e4b82-72c7-43d5-b90e-aba17d2fea1d}
IContainer
System.ComponentModel
ConcatStatus
CallVal
EventArgs
Dispose
Boolean
dosetup
IDisposable
FillVal
ContainerControl
set_AutoScaleMode
AutoScaleMode
System.Drawing
Control
set_Name
String
SuspendLayout
EventHandler
IntPtr
add_Load
ResumeLayout
set_Text
Single
set_AutoScaleDimensions
InterruptStatus
CollectStatus
ManageStatus
set_ClientSize
LoginStatus
GetVal
ProcessStartInfo
System.Diagnostics
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
Process
WaitForExit
SortVal
InstantiateVal
SearchStatus
OrderStatus
PrepareStatus
IWin32Window
m_Composer
ForgotStatus
MapVal
DialogResult
MessageBox
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
PublishVal
UpdateVal
MessageBoxButtons
SearchVal
MessageBoxIcon
VerifyVal
second
MessageBoxDefaultButton
PushVal
config
asset2
first3
MessageBoxOptions
RegisterVal
CollectVal
PrintVal
caller
template
AwakeVal
param2
InitVal
instance
selection3
VisitVal
filter
setup4
connection5
CompareVal
Assembly
System.Reflection
UInt32
InvokeMember
BindingFlags
Binder
op_Inequality
get_Handle
WebClient
DownloadData
GetTypes
ValidateVal
connection
GetTypeFromHandle
RuntimeTypeHandle
Marshal
System.Runtime.InteropServices
PtrToStructure
StartVal
SetVal
WriteVal
Encoding
System.Text
get_UTF8
GetString
LogoutVal
Rectangle
get_Height
get_Width
System.Threading.Tasks
get_Factory
TaskFactory
Action
StartNew
.cctor
PrintStatus
VerifyStatus
MapStatus
InsertStatus
SetStatus
ResolveStatus
Convert
FromBase64String
InstantiateStatus
Replace
Invoke
wParam
lParam
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
value__
DisableVal
visitor
GetWindowThreadProcessId
user32
LoginVal
GetWindowRect
DefineVal
lengthrole
flags_map2
removeIVK3At
SetWindowPos
RateVal
version_ident
attr2_Z
SetWindowsHookEx
ComputeVal
UnhookWindowsHookEx
EnableVal
b_Position
CallNextHookEx
_Printer
worker
m_Resolver
_System
m_Parser
m_Broadcaster
m_Order
RunStatus
SetupVal
PatchStatus
StartStatus
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
_Filter
ResourceManager
System.Resources
CultureInfo
System.Globalization
VisitStatus
get_ResourceManager
get_Assembly
get_Culture
set_Culture
FlushStatus
ReflectStatus
Culture
defaultInstance
DisableStatus
get_Default
SettingsBase
Synchronized
EnableStatus
NewStatus
Default
m_b970e93018224dd18f36d20dda959d9b
m_6c081dc345b9424d9bc8fc71730ccfb6
m_80f290ceb9fc40bc945c69876b793d3c
m_84aa62ce9d16478da4ffd2603fa9f1d3
m_fd50053cce3248f5a246c348261159ab
m_97de1961a56449ff9793237c3c364fa9
m_6388edbeed9b4e058cb584ca2e563352
m_b8e2abf303e7419f9b1f9a597fba4e4a
m_293975d53b4d4b7c9222903e96799b92
m_54c84bba5136463fbaceec55b1726b95
m_a3f1b0f6d52148189806f986e3d38d33
m_b2c24c2f5c0b4ae58d60df956e40ed5d
m_6d59c0982707402fb47d3bd768fe19f7
m_5e645a354cdc46cca30448791a9ad895
m_9a4bedcc80d04db89f0ede61aa73b9c7
m_039b927b86d644739705f5ee424e6d3d
m_47c8b72ab91441b394222c14c6232d44
m_ef761b47d1544b148cd09f50627bdd26
m_f018ebbf3ec74870a52fc33fc6706782
m_096a38661f6244da9751c5aaa798634f
m_a2fb403327a9415d84c6f31d782325cd
m_4eb0d4d1b6d9496e8d5a37c5ef397661
m_e254cbc7d1314ffa93cb4244b1e4951e
m_4498b3e2c7b14c7d964cb87476f3eb47
m_180c81c4750a45ae8fcd85627888c88f
m_4b1e950e57734ea2b8ec74a0f3f2085b
m_1bd1ba5109a34dfd8f244ff87edd8e28
m_a03e09fe8790454ea41d692f68d5cb10
m_2feb9e33a3e74213a84f6d8bee0b5697
m_1706eb52eba748128e5f09ca3010f538
m_3d2d07f2779a4ec3abcaa0e9e5326a45
m_1109b3dd7cde41e7b4f528ef86810da7
m_38ff1537ef5f418c9fceca5c1c938a58
m_50949194cef142289ff3d4d53cc35b9b
m_031caaacef9543f6bad51f6ff22932dc
m_1bafe3d136fb4264a1d39892a20eff36
m_62018da7f38c40e983939d995f5a7283
m_753c38a157fd46d3ab722da39ed47d42
m_bdf2300038d34058ac9ddd7c1d8b7502
m_3d0b7d5298084ebc9d3dd4ffb7510157
m_40a1e51ffd9647ee9e55b424b5170610
m_f6c6c95cab974b2aa23c3cc5ad883287
m_95280b8969e8445a8dd6d7276b9308f9
m_d78c6ab0288243ecaeed051809a5c1d3
m_81c039b8958344f2b0e82f2784172b9a
m_24421280d96747f5b57044990fad806a
m_ac9d1cfe00524925be3a70ddf1d4ddf9
m_e6804b82117c4c4790b779298644e69b
m_328adf662cd943d5bb6da883e4a951fe
m_a09bc2ad3a5146f5968bf1f92539d85e
m_44959af466d34260b0302701eef13c78
m_26cd390a00f747859cb1d08a4cd05be2
m_479160f144304f2ca28cb45fecd02b58
m_3baa59ba7d0a499c9765a60373f32f7e
m_6d530b4842ec4bdeb7b060efe8dd39da
m_a488e01e373247fba89c9a91dddae8a9
m_ed9fd3d49ae14f589ab0f86d8771b6b8
m_214d4bc6f3ff479694e853c50baa7b51
m_d32c9a78fc9a4dec8efe4d48fa0073b6
m_345f738bf91e47489236f81b09189660
m_7480352edb494a66a20bf66e0649a6e6
m_af6693ed6e0a4f7da89463af4f01b689
m_d887f14e6e934f0aac16ce137532f01f
m_641fcbee260541bdb49a0a1c0f18fa6f
m_c10731a23c9c4730a1679d6144b2a698
m_7a1ed8f5f4c7490f860a99562a40801c
m_e5ff55d434b1472485be78f92c1d2a40
m_0c032a7dd6bf4d80bf6de1546bf1f475
m_8e74e6fbcd6649cf93f57517dc038f22
m_c9b8f2e9c82d4452976351aca8f7a59a
m_b37b4843e11f481ca79f2b658adad7ef
m_34aff2d70eef4dd5a240d100e1257a19
m_69a63172fe5147e0af31bfee594366fd
m_efc01ea8219d4825999c51d5d2dbedfd
m_aa5962af7bda43feb3e881df1b8988fb
m_4dce8c63db654456b4af0a209fec56d8
m_05edff6ac14c4663bd28116cc19bdf86
m_7e886c52e3b045d79172dea697544c8e
m_2230fe019fbb46398997f4267f2aeac7
m_c580cc6453764177ae3003c12c3decd0
m_54599f3ff3cf4a7a94be5dd83b1685af
m_715dca24a9b64a7b90e69a2fbeb8ae80
m_afb8036739b74beaada9b5dc88173b2b
m_bd69e14dca3945d497e014e9b180b4b9
m_ea372fc56bca4b44950172725eb9c033
m_021dc3d5337e41dc90e775936dc5af99
m_33f68d0d7bd645eca7e80f6ea3a7877e
m_413e7d9c2fff4ecf8d031ea5b89dc6d7
m_44e10507a2024439879e89940ec0defa
m_668080eaaf4f462486a9399c0516e706
m_aa87c9a2bcd944f6951dfbebd718e743
m_8496bce62eb14ddaabbc3760c5d00eab
m_63e81bc6e63c42c286997988c03824bc
m_362544f7655d4d3d80feef72312e17b2
m_ed624cc5a1fc4d039163de7968d876c8
m_a555a9d8cbee4959b472229d0f824642
m_91a077b9f22149138ae5a67960d20a17
m_6f03ea3346e440c58581eba46dc0e24c
m_9a1a39332f594275bf8646cbebe9f051
m_0338c166946f478c9e0eeb5b09f103e2
m_e0271c38929142c19fe441aad32e6e43
m_2b9f638ee9f54a428211615faf54b644
m_dc03d4a231b74688bee0f0dcac2cd64e
m_aeed48189ef14f6d82658f0d6a552f1a
m_56aebc2c5e764c1f9e0f220aae4fad4b
m_f122e19541de492880310aa7ce7a7e19
m_6b2a9874a7194dc09a55832ce61eb5bb
m_c9b646d30f11491f8e07f01c695f411d
m_36400c58276c4314afb585a1ebb010ae
m_b809d896ed754e9e97634e4533a23e61
m_10903130bb5a41ffad03c86661923b78
m_c3a35b6135e748e2b1763968362d97e5
m_262d955a9e9545e29d30e8ce21653d4f
m_c610bbb31f824ed789d15f44c7219eab
m_22f4d4e51cec4deca4fbe034cca46e58
m_b0d3437ee683448f860be763822de8ca
m_dca9cbdabc8b4d0aa4044fafedefd683
m_3d9d54ee39554512aa90cba0d4fb4140
PublishStatus
ef1f8757db5ff405286368fca7c7c6b34
UpdateStatus
DeleteStatus
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
EditorBrowsableState
FlagsAttribute
Utiteqzllhwefrwpjya.Common.Connection.resources
Utiteqzllhwefrwpjya.Properties.Resources.resources
WrapNonExceptionThrows
Google Update Setup
Google LLC
Google Update
Copyright 2018 Google LLC
$1ae5edd3-0f9c-4bdd-8d17-36711d6a3ba2
1.3.36.102
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
wwwwww
wwwwwx
**"(wz
nnnnnnnh
www
###7777_{
###77777777
###8888777v
###____777
###____87Y
###````87{
###````_7v
###````_7v
###````_7v
]]]]]]V
]]]]]]V
]]]]]]
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
powershell
Start-Sleep -Seconds 3
Start-Sleep -s 15
FlushTest
https://store2.gofile.io/download/658884da-8dd7-4781-9455-8aaf61fcb244/Atftigkvqscpv.dll
Utiteqzllhwefrwpjya.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Google Update Setup
CompanyName
Google LLC
FileDescription
Google Update Setup
FileVersion
1.3.36.102
InternalName
XXXXX43$#f.exe
LegalCopyright
Copyright 2018 Google LLC
LegalTrademarks
OriginalFilename
XXXXX43$#f.exe
ProductName
Google Update
ProductVersion
1.3.36.102
Assembly Version
1.3.36.102
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.49af0abba03a7d55
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34170.cm0@amTe4Ep
Avast Clean
CrowdStrike win/malicious_confidence_80% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.