Static | ZeroBOX

PE Compile Time

2021-10-07 02:16:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001358 0x00001400 5.47199485328
.rsrc 0x00004000 0x000046e0 0x00004800 2.27025236716
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x00008158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000816c 0x000003be LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000852c 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
PLT_107510013098613
PLT_107510013098613.exe
mscorlib
System.Core
System
Caktrcxcfelzgfjsritw.Properties.Resources.resources
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
List`1
Enumerator
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
Convert
DebuggerNonUserCodeAttribute
System.Diagnostics
CultureInfo
System.Globalization
IDisposable
SecurityProtocolType
System.Net
ServicePointManager
WebClient
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
MethodBase
MethodInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
ExtensionAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Encoding
System.Text
Thread
System.Threading
<Module>
Settings
Caktrcxcfelzgfjsritw.Properties
Caktrcxcfelzgfjsritw
.cctor
Synchronized
get_UTF8
GetString
Replace
FromBase64String
set_SecurityProtocol
WriteLine
GetType
GetTypeFromHandle
GetMethod
DownloadData
Invoke
GetTypes
AddRange
GetEnumerator
get_Current
InvokeMember
MoveNext
Dispose
get_Assembly
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
$d964d1a5-4950-4132-b0fb-174cbbd6a29d
'Copyright
Alexander Roshal 1993-2019
WinRAR
Alexander Roshal
WinRAR archiver
5.71.0.0
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
@p 0Bn
DpKDn x
Ds"<Fp f
Eu 0Gs!]
Ft!Hv!NFw"x
Hw"<Iw"i
Hw"<Iw"i
Ft!Hv!NFv!{
Fs#3Eu `
Eq ?Dq!l
$BnQCo
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
System.Reflection.Assembly
https://store2.gofile.io/download/08448b06-8e80-4c63-a89d-8c121652b7b1/Wugwolitpcyoklhvxmgi.dll
PrepareCode
Caktrcxcfelzgfjsritw.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
WinRAR archiver
CompanyName
Alexander Roshal
FileDescription
WinRAR archiver
FileVersion
5.71.0.0
InternalName
PLT_107510013098613.exe
LegalCopyright
Copyright
Alexander Roshal 1993-2019
LegalTrademarks
OriginalFilename
PLT_107510013098613.exe
ProductName
WinRAR
ProductVersion
5.71.0.0
Assembly Version
5.71.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37738311
FireEye Generic.mg.fc1ac30e0bd33f65
CAT-QuickHeal Clean
McAfee RDN/Generic Downloader.x
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005889081 )
BitDefender Trojan.GenericKD.37738311
K7GW Trojan-Downloader ( 005889081 )
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
Cyren Clean
Symantec MSIL.Downloader!gen7
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.IZT
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Downloader.24576.DN
Rising Clean
Ad-Aware Trojan.GenericKD.37738311
Emsisoft Trojan.GenericKD.37738311 (B)
Comodo TrojWare.Win32.UMal.udxlf@0
F-Secure Clean
DrWeb Trojan.DownLoader43.36915
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.37738311
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Dldr.Agent.qhgxn
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.sa
Arcabit Trojan.Generic.D23FD747
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
Microsoft Trojan:MSIL/AgentTesla.RV!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Backdoor.Crysan.Eddq
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
eGambit Unsafe.AI_Score_96%
Fortinet MSIL/Agent.IZE!tr.dldr
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.a0b26d
Avast Win32:PWSX-gen [Trj]
MaxSecure Clean
No IRMA results available.