Static | ZeroBOX

PE Compile Time

2090-10-22 21:32:50

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000690d4 0x00069200 3.74170585967
.rsrc 0x0006c000 0x000002a4 0x00000400 2.19555845275
.reloc 0x0006e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006c058 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Boughpots
Boughpots.exe
<Module>
Interceptor
Boughpots.Roles
Object
System
mscorlib
Policy
<>c__DisplayClass2_0
RoleAlgoStrategy
Boughpots.Strategies
Configuration
Boughpots.Properties
<>o__4
RulesAlgoStrategy
<>o__5
TagStatus
Boughpots.States
Definition
Boughpots.Common
RepositoryCandidateProperty
ItemAlgoStrategy
MulticastDelegate
Product
WrapperPolicyRole
AlgoCandidateAttribute
ParameterInterceptorDeSerializer
Client
Prototype
StrategyPolicyRole
Callback
Facade
Decorator
ListenerCandidateProperty
AuthenticationPolicyRole
ValueType
Attribute
ValPolicyRole
AnnotationPolicyRole
SystemStatus
InterceptorCandidateAttribute
Boughpots.Attributes
Wrapper
Publisher
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=412528
CollectIndexer
String
EntryPointNotFoundException
ViewIndexer
InvokeIndexer
PatchIndexer
Func`1
Boolean
IntPtr
Invoke
InvalidOleVariantTypeException
System.Runtime.InteropServices
_Class
InsertIndexer
UInt64
UInt32
UInt16
op_Explicit
Marshal
SizeOf
Application
System.Windows.Forms
get_ExecutablePath
op_Inequality
Thread
System.Threading
ToInt64
GetTypeFromHandle
RuntimeTypeHandle
AllocHGlobal
FreeHGlobal
candidate
method
.cctor
ComputeIndexer
startcounter
m_Pool
instance
Replace
ListIndexer
ExcludeIndexer
Binder
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Convert
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`3
CallSite
Create
Target
ToCharArray
GetIndexer
get_Length
FromBase64CharArray
Encoding
System.Text
get_UTF8
GetString
VerifyIndexer
_Worker
CallIndexer
StringBuilder
get_Chars
Append
ToString
InterruptIndexer
InitIndexer
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Exception
ReadIndexer
Action
config
PrepareIndexer
ReflectIndexer
m_Parser
ConnectIndexer
CloneIndexer
CSharpArgumentInfo
CSharpArgumentInfoFlags
InvokeMember
IEnumerable`1
System.Collections.Generic
Func`4
ekovnIezinorhcnySIledoMtnenopmoCmetsyS11436
Func`5
Func`6
GetMember
m_Exception
request
iterator
status
_Record
m_Broadcaster
proccesor
exporter
StopIndexer
LoadLibrary
kernel32.dll
SetupIndexer
FreeLibrary
IncludeIndexer
second
GetProcAddress
kernel32
m_Resolver
StartIndexer
RestartIndexer
GetDelegateForFunctionPointer
Delegate
DestroyIndexer
m_Message
selection
hProcess
isWow64
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
caller
lpBaseAddress
ltluseRcnysAegasseMetirWrepleHnoitcennoCgnimaertSslennahCledoMecivreSmetsyS2791
lpNumberOfBytesWritten
exitCode
handle
hToken
lpApplicationName
lpCommandLine
lpProcessAttributes
lpThreadAttributes
bInheritHandles
dwCreationFlags
lpEnvironment
lpCurrentDirectory
lpStartupInfo
lpProcessmhtiroglAtcennoCslennahCledoMecivreSmetsyS96261
hNewToken
counter
hThread
pContext
ProcessHandle
BaseAddress
ZeroBits
RegionSize
AllocationType
Protect
connection
nCmdShow
_Proxy
server
_Template
m_Writer
m_Issuer
_Params
global
m_Watcher
_Specification
dispatcher
_Serializer
authentication
annotation
strategy
comparator
factory
helper
setter
predicate
_Registry
m_Creator
m_Visitor
getter
m_Customer
container
m_Interpreter
m_Singleton
identifier
m_Rule
_Thread
m_Rules
EnableIndexer
SelectIndexer
BF9A5509377165BEAD6D0D6427009B374C44D911
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
ParamArrayAttribute
DynamicAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
CompilerGeneratedAttribute
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
KrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS289103gGLDI7DyArDzwDHioyOQ==
KrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910CQCPjIRLiY8Mg0F
GrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS289103kaOQkOCz8zPT8AHV8cMDNlPCM9FDAMFxsCHhw9bWg=
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910A0GLDIBNSY/LScaESUAPAlnBiw6JFtI
GrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS289103goIzNkDxo/IkAdJiofdw==
GrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910RIeDTJlOmEoMzcPJl8EJjNmHWs=
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910iQCAzI7aDsFMy8GHjUuGgo5HjoAYDQFF0RwUA==
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910iQCFzIRISU/RzNGHjsQOjM7AmcABB47LyF1GykkO2g=
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910HkaJTQRDwIFGEwcHjUEMAQCBiI7YCxA
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910HhpZh48Cxs8LScjJSUAJgkCAhI7YVNFLy4sXQ==
GrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910HgGZQYRMSo8IjMdFV9zPzQSBmI9EltI
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910HhpZh48Cwc8LScjJSUAJgkCAhI7YVNFLy4sXQ==
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS289103gGZQYRMSo8IjMdFV9zPzQSBmI9EltI
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910ycGLzQBaD8wMh0PHjoMIQ==
rPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910
GrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910HgGZQFkYCYFR0wFHjsuOjI4AiA9JFtI
LrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910hIeOTM8FCoqGCcFJix3dw==
HrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS289103g4IzRnPSMEGCcAIBp3dw==
ekovnIezinorhcnySIledoMtnenopmoCmetsyS11436
Replace
FromBase64CharArray
ToCharArray
Length
GetString
JJPUPVYSfuuvDm
VrPegasseMtxetnoCtseuqeRslennahCledoMecivreSmetsyS28910FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUFsMHlyc0FBQUFBQUFBQUFPQUFBZ0VMQVRBQUFLd0JBQUFNQUFBQUFBQUFJcklCQUFBZ0FBQUE0QUVBQUFCQUFBQWdBQUFBQkFBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFBZ0FnQUFCQUFBSlBVQkFBTUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFOQ3hBUUJQQUFBQUFPQUJBTndFQUFBQUFBQUFBQUFBQUFDOEFRRDRDQUFBQUFBQ0FBd0FBQUMwc1FFQUhBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFxS29CQUFBZ0FBQUFyQUVBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQU53RUFBQUE0QUVBQUFnQUFBQ3dBUUFBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQUFBQ0FBQUVBQUFBdUFFQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQU
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Boughpots.exe
LegalCopyright
OriginalFilename
Boughpots.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Convagent.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.78553
FireEye Generic.mg.e7302252512b968f
CAT-QuickHeal Trojanpws.Msil
ALYac Trojan.GenericKDZ.78553
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005888331 )
BitDefender Trojan.GenericKDZ.78553
K7GW Trojan ( 005888331 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren W32/MSIL_Troj.CY.gen!Eldorado
ESET-NOD32 a variant of MSIL/Kryptik.ADAC
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Convagent.gen
Alibaba Trojan:Win32/Kryptik.ali2000016
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-qqpass.Qqrob.Ajbc
Ad-Aware Trojan.GenericKDZ.78553
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.972
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gz
CMC Clean
Emsisoft Trojan.GenericKDZ.78553 (B)
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1144480
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Microsoft Trojan:MSIL/AgentTesla.DAC!MTB
Gridinsoft Clean
Arcabit Trojan.Generic.D132D9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Convagent.gen
GData Trojan.GenericKDZ.78553
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4628732
Acronis Clean
McAfee GenericRXPZ-UA!E7302252512B
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DJF21
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ACCF!tr
BitDefenderTheta Gen:NN.ZemsilF.34218.Am0@a4t6mdk
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
MaxSecure Clean
No IRMA results available.