Static | ZeroBOX

PE Compile Time

2021-09-27 11:26:22

PDB Path

c:\Users\Administrator\AppData\Local\Temp\2\DTqCJ.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000eb4 0x00001000 4.85744021643
.rsrc 0x00004000 0x0005d460 0x0005d600 4.05099676813
.reloc 0x00062000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000609e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00060e50 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00060ee4 0x00000390 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00061274 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
Program
Arabalar
mscorlib
System
Object
QuickShort
Parcalama
baslang
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
STAThreadAttribute
System.Net
WebClient
ServicePointManager
SecurityProtocolType
get_SecurityProtocol
set_SecurityProtocol
System.Windows.Forms
Application
get_ExecutablePath
String
DownloadData
Console
WriteLine
WebHeaderCollection
get_Headers
Assembly
GetType
BindingFlags
Binder
InvokeMember
<PrivateImplementationDetails>{D8464740-4278-435E-A04D-700A8F54B6DB}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=24
$$method0x6000004-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
Concat
ConsoleKeyInfo
ReadKey
IDisposable
Dispose
NoxPlayer Installer
Duodian Technology Co. Ltd.
NoxPlayer
;Copyright (C) 2021 Duodian Online Inc. All rights reserved.
7.0.1.5
WrapNonExceptionThrows
RSDSmv
c:\Users\Administrator\AppData\Local\Temp\2\DTqCJ.pdb
_CorExeMain
mscoree.dll
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
ZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZZ
Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_ZZ
Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z_Z__Z
___NNNONNNONNN_________________Z__
__________________________________
__________________________________
___NNNNNNNNNNN____________________
__________________________________
__________________________________
_3.3.3.3.3.3.3.3.3.3.3.3.3.3._
+__a_a_`_N_a_`_a_N_a_`_a_`_3___
_``aNa_`a_``Na_`a_``a_3aa_
_a_Nb`b_
_aN`b_
N`bbb_
a.NNNNNNNNNNNNNNNNNNNNNNNNNN.`
_.NNNNNFNNNNNNNNNFNNNNNNNNNN.
#VNV#-4NVVNVVOVVVVOV.
.RRRRRRRRNRRRRRRRNRRRRRRRRR.
+...........................
FNFNNNFNNNN
DNNNFNNNFNN
NNNNNNNNNNN
FNNNNNNNNNN
XXJA02D
>">(J_$'?0&
0]]IYCTT?-Z
.................+.+.+....Q
7777777777777777777777
7777777777777777777777
7;///////;;;;;;;;;;;;7
;7;7;7;7;7;7;7;7;7;7;;
;;///////;;;;;;;;;;;;;
;;;;;;;;;;;;;;;;;;;;;;
=;>;>;/====/====
;>>>/;;=;/;=;=
;>;/>>==/=;==
>>>/>=;
./../...//#/./)/
444444/4444.4444
111111#1111.1111
/..///#
/./#/..
#.)./..>
././/#/>

!!!!!!!!!
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
http://31.210.20.22/xxm/bin.exe
https://cdn.discordapp.com/attachments/888348114673598475/890866414997635092/TNG.dll
User-Agent: Mozilla 4.0
s1 s2'den b
s1 s2'den b
TNG.YJND
LVLARRT
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
NoxPlayer Installer
CompanyName
Duodian Technology Co. Ltd.
FileDescription
NoxPlayer Installer
FileVersion
7.0.1.5
InternalName
LegalCopyright
Copyright (C) 2021 Duodian Online Inc. All rights reserved.
OriginalFilename
ProductName
NoxPlayer
ProductVersion
7.0.1.5
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
Cynet Clean
FireEye Generic.mg.59a50d997d0b4a35
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37665056
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/MSIL_Kryptik.EHH.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Generik.MUPTVFL
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/Agensla.019c154d
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.37665056
Rising Clean
Ad-Aware Trojan.GenericKD.37665056
Emsisoft Trojan.GenericKD.37665056 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37665056
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D23EB920
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34170.xm0@am74Dlb
ALYac Trojan.GenericKD.47058292
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07IR21
Tencent Clean
Yandex Clean
Ikarus Trojan.SuspectCRC
eGambit Clean
Fortinet MSIL/Tiny.BGM!tr.dldr
AVG Win32:Malware-gen
Cybereason Clean
Avast Win32:Malware-gen
MaxSecure Clean
No IRMA results available.