Static | ZeroBOX

PE Compile Time

2088-01-10 04:31:24

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00183e64 0x00184000 3.34390192506
.rsrc 0x00186000 0x000002ac 0x00000400 2.19280585544
.reloc 0x00188000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00186058 0x00000254 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Evaginates
Evaginates.exe
<Module>
Annotation
Evaginates.Filter
Object
System
mscorlib
Registry
Evaginates.Serialization
<>c__DisplayClass2_0
BaseTestMapping
Evaginates.Maps
IdentifierTestMapping
<>o__4
ListenerTestMapping
Definition
Evaginates.Common
<>o__5
ValSystemExpression
Evaginates.Expressions
Template
StrategySerializer
MulticastDelegate
Property
AuthenticationRegistryFilter
Process
ComparatorTestMapping
RefTestMapping
Connection
SystemExpressionClass
Params
AttributeSerializer
TaskTestMapping
Exporter
CodeTestMapping
ValueType
StubRegistryFilter
Client
Evaginates.Classes
Account
AttrTestMapping
ItemTestMapping
RegistryExpressionClass
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=1572940
CheckAnnotation
String
EntryPointNotFoundException
ManageAnnotation
PrintAnnotation
InterruptAnnotation
config
Func`1
Boolean
IntPtr
Invoke
InvalidOleVariantTypeException
System.Runtime.InteropServices
_Printer
SetAnnotation
UInt64
UInt32
UInt16
op_Explicit
Marshal
SizeOf
Application
System.Windows.Forms
get_ExecutablePath
op_Inequality
Thread
System.Threading
ToInt64
GetTypeFromHandle
RuntimeTypeHandle
AllocHGlobal
FreeHGlobal
expression
method
.cctor
ComputeAnnotation
_Facade
Replace
FindAnnotation
PostAnnotation
instance
Binder
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Convert
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`3
CallSite
Create
Target
ToCharArray
RemoveAnnotation
FromBase64String
Encoding
System.Text
get_UTF8
GetString
VisitAnnotation
_Visitor
CreateAnnotation
StringBuilder
ToChar
Append
ToString
InvokeAnnotation
PopAnnotation
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Exception
CloneAnnotation
Action
reference
InsertAnnotation
TestAnnotation
worker
AssetAnnotation
IncludeAnnotation
CSharpArgumentInfo
CSharpArgumentInfoFlags
InvokeMember
IEnumerable`1
System.Collections.Generic
Func`4
slitUdeeFnoitacidnySledoMecivreSmetsyS96506
Func`5
m_Reader
_Object
m_Context
_Wrapper
_Iterator
repository
_Creator
WriteAnnotation
LoadLibrary
kernel32.dll
SelectAnnotation
FreeLibrary
DestroyAnnotation
GetProcAddress
kernel32
product
SortAnnotation
RateAnnotation
GetDelegateForFunctionPointer
Delegate
ReflectAnnotation
_Indexer
second
hProcess
isWow64
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
selection
lpBaseAddress
lssalCyalpsiDcypoCkluBlqStneilClqSataDmetsyS75594
lpNumberOfBytesWritten
exitCode
handle
counter
hToken
lpApplicationName
lpCommandLine
lpProcessAttributes
lpThreadAttributes
bInheritHandles
dwCreationFlags
lpEnvironment
lpCurrentDirectory
lpStartupInfo
lpProcesetatSegarotSsepyTlqSataDmetsyS11948
hNewToken
hThread
pContext
ProcessHandle
BaseAddress
ZeroBits
RegionSize
AllocationType
Protect
connection
nCmdShow
container
_Callback
_Setter
parameter
m_Adapter
exception
m_Customer
request
m_Specification
m_Page
_Serializer
mapper
m_Base
identifier
listener
m_Attr
m_Item
comparator
observer
server
proccesor
_Candidate
m_Manager
_Interceptor
m_Model
mapping
m_Struct
m_Order
_Schema
m_Reponse
factory
m_Algo
m_Decorator
invocation
_Policy
PublishAnnotation
VerifyAnnotation
C810F8A5B09EC2C1987F19DD8FBCE4244E6534A3
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
ParamArrayAttribute
DynamicAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
CompilerGeneratedAttribute
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
BcisaBteNmetsyS79014X0AFRUlHyknPzoTPgguHw==
BcisaBteNmetsyS79014iEEBxUPPi8wAgsV
NcisaBteNmetsyS79014XwcAC4QGzY/DTkQPX0AFhR4JS8OAiUfBiIQHyE/dGc=
McisaBteNmetsyS79014ggAFRUfJS8zHSEKMQccGi56HyAJMk5b
NcisaBteNmetsyS79014X0uGhR6HxMzEkYNBggDUQ==
NcisaBteNmetsyS79014xcYNBV7KmgkAzEfBn0YABR7BGc=
McisaBteNmetsyS79014CEEOhUleDIJAykWPhcyPC0kBzYzdiEWBn1iUQ==
McisaBteNmetsyS79014CEELhUPMSwzdzVWPhkMHBQmG2szEgsoPhhnGhQmImc=
McisaBteNmetsyS79014nwcHBMPHwsJKEoMPhcYFiMfHy4IdjlT
McisaBteNmetsyS79014n1vXzkiGxIwHSEzBQccAC4fGx4Id0ZWPhc+XA==
NcisaBteNmetsyS79014n0AXCEPISMwEjUNNX1vGRMPH24OBE5b
McisaBteNmetsyS79014n1vXzkiGw4wHSEzBQccAC4fGx4Id0ZWPhc+XA==
McisaBteNmetsyS79014X0AXCEPISMwEjUNNX1vGRMPH24OBE5b
McisaBteNmetsyS79014SIAFhMfeDY8AhsfPhgQBw==
cisaBteNmetsyS79014
NcisaBteNmetsyS79014n0AXCZ6cC8Jd0oVPhkyHBUlGywOMk5b
AcisaBteNmetsyS79014BcYABQiBCMmKCEVBg5rUQ==
McisaBteNmetsyS79014X0+GhN5LSoIKCEQADhrUQ==
slitUdeeFnoitacidnySledoMecivreSmetsyS96506
Replace
FromBase64String
GetString
dOVlwHIZjEsf
VcisaBteNmetsyS79014FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUtXMi9wQUFBQUFBQUFBQUFPQUFEZ0VMQVRBQUFMZ0dBQUFHQUFBQUFBQUFYdFlHQUFBZ0FBQUE0QVlBQUFCQUFBQWdBQUFBQWdBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFBZ0J3QUFBZ0FBQUFBQUFBTUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFCRFdCZ0JMQUFBQUFPQUdBS3dDQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBSEFBd0FBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFaTFlHQUFBZ0FBQUF1QVlBQUFJQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQUt3Q0FBQUE0QVlBQUFRQUFBQzZCZ0FBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQUFBSEFBQUNBQUFBdmdZQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUJBMWdZQUFBQUFBRWdBQUFBQ0FBVUFpQzRBQU5neEFBQURBQUFBQVFBQUJnQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQ
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Evaginates.exe
LegalCopyright
OriginalFilename
Evaginates.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.Generic.30205242
FireEye Generic.mg.ee98c1f6708926a1
CAT-QuickHeal Trojanpws.Msil
ALYac Trojan.Generic.30205242
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 0057fbdb1 )
Alibaba Trojan:Win32/Kryptik.ali2000016
K7GW Trojan ( 0057fbdb1 )
Cybereason malicious.3a4b98
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34170.Hn0@aybxjWc
Cyren W32/MSIL_Kryptik.FNI.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACCF
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
BitDefender Trojan.Generic.30205242
NANO-Antivirus Trojan.Win32.Kryptik.jcjjla
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.Generic.30205242
Emsisoft Trojan.Generic.30205242 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.972
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos ML/PE-A
Ikarus Trojan.MSIL.Crypt
Jiangmin Clean
MaxSecure Clean
Avira HEUR/AGEN.1144480
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/AgentTesla.JPX!MTB
SUPERAntiSpyware Trojan.Agent/Gen-Falint[Cont]
ZoneAlarm Clean
GData MSIL.Trojan-Stealer.Redline.I816PD
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4628732
Acronis Clean
McAfee GenericRXPZ-PJ!EE98C1F67089
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CC0DIO21
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ACCF!tr
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.