Static | ZeroBOX

PE Compile Time

2021-09-16 06:32:20

PDB Path

c:\Users\PE\AppData\Local\Temp\hCdRkFBziAAPbCk.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001054 0x00001200 4.85702486182
.rsrc 0x00004000 0x00000638 0x00000800 3.54248855584
.reloc 0x00006000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000040a0 0x000003a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004448 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
https://cdn.discordapp.com/attachments/879141740978769922/887025913261359164/runpe.png
v4.0.30319
#Strings
<Module>
hCdRkFBziAAPbCk
Program
WPFUserFamilyAdresses1
mscorlib
System
Object
TRZyCnTBBjWEczT
System.Reflection
BindingFlags
Shkarko
merkkijono
Deskargatu
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Microsoft.VisualBasic
Microsoft.VisualBasic.CompilerServices
Conversions
ToInteger
ToDouble
Microsoft.Win32
Registry
GetValue
Environment
SpecialFolder
GetFolderPath
String
Concat
System.IO
GetDirectoryName
Directory
Exists
DirectoryInfo
CreateDirectory
System.Windows.Forms
Application
get_ExecutablePath
SetValue
STAThreadAttribute
System.Net
ServicePointManager
SecurityProtocolType
get_SecurityProtocol
set_SecurityProtocol
WebClient
System.Text
Encoding
get_ASCII
GetString
DownloadData
Assembly
GetType
Binder
InvokeMember
<PrivateImplementationDetails>{4D33E133-2C44-441D-843C-E47C84F910A2}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=86
$$method0x6000004-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
DownloadString
Convert
FromBase64String
Boolean
DismProv.dll
&Microsoft
Windows
Operating System
10.0.18362.0
WrapNonExceptionThrows
c:\Users\PE\AppData\Local\Temp\hCdRkFBziAAPbCk.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
EngineeringProjects0
210914151528Z
310915151528Z0
EngineeringProjects0
m*Pqak
EngineeringProjects
X`Tz8!
Y!M[%
&_qg0E
G^Arhh
20210915221611Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210915221611Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
}b3jT-N
abO4}g
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
uFzgJpBbCZdobdR
\LpEwT\eLAKB.exe
ediskcz.ediskfiles
GetFiles
https://a.uguu.se/WmccEYfL.txt
C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
DismProv.dll
CompanyName
DismProv.dll
FileDescription
DismProv.dll
FileVersion
10.0.18362.0
InternalName
hCdRkFBziAAPbCk
LegalCopyright
Microsoft
Windows
Operating System
OriginalFilename
hCdRkFBziAAPbCk
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.18362.0
Assembly Version
0.0.0.0
<<<Obsolete>>
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Bladabindi.m!c
Elastic Clean
Cynet Clean
CMC Clean
CAT-QuickHeal Backdoor.MSIL
ALYac Trojan.GenericKD.37592847
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37592847
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Tiny.BGM
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
Alibaba Backdoor:MSIL/Bladabindi.1f3827b4
NANO-Antivirus Trojan.Win32.Bladabindi.jceykg
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37592847
Tencent Clean
Ad-Aware Trojan.GenericKD.37592847
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Downloader.Tiny.Win32.21850
TrendMicro Clean
McAfee-GW-Edition RDN/Generic Downloader.x
FireEye Trojan.GenericKD.37592847
Emsisoft Trojan.GenericKD.37592847 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37592847
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Generic.D23D9F0F
ViRobot Clean
ZoneAlarm HEUR:Backdoor.MSIL.Bladabindi.gen
Microsoft Trojan:Win32/Sabsik.TE.B!ml
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic Downloader.x
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Cylance Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R011C0PIM21
Rising Clean
Yandex Trojan.DL.Tiny!JfxORCMMQ/4
Ikarus Trojan-Downloader.MSIL.Tiny
eGambit Clean
Fortinet Malicious_Behavior.SB
BitDefenderTheta Gen:NN.ZemsilF.34170.am1@a8LaG8
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
MaxSecure Clean
No IRMA results available.