Static | ZeroBOX

PE Compile Time

2091-05-31 22:33:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001b08 0x00001c00 5.50326949884
.rsrc 0x00004000 0x00010f0c 0x00011000 5.16118586343
.reloc 0x00016000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004100 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00014938 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001495c 0x000003ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00014d1c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
70016103621110
IEnumerable`1
IEnumerator`1
IList`1
get_UTF8
<Module>
DownloadData
mscorlib
System.Collections.Generic
Thread
Synchronized
<Name>k__BackingField
<Url>k__BackingField
<Offices>k__BackingField
Auckland
Office
defaultInstance
get_Message
AddRange
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
set_Name
WriteLine
SecurityProtocolType
System.Core
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
EditorBrowsableState
Website
website
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
70016103621110.exe
System.Threading
Encoding
set_ObjectCreationHandling
set_ConstructorHandling
System.Runtime.Versioning
String
System.ComponentModel
UserViewModel
set_SecurityProtocol
get_Url
set_Url
Program
System
resourceMan
AppDomain
GetDomain
System.Configuration
System.Globalization
System.Reflection
ArgumentNullException
Newtonsoft.Json
CultureInfo
InvokeMember
Binder
buffer
get_ResourceManager
ServicePointManager
Handler
System.CodeDom.Compiler
IEnumerator
GetEnumerator
.cctor
Consturctor
System.Diagnostics
ExtensionMethods
get_Offices
set_Offices
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Ajjbtaahcizcu.Properties.Resources.resources
DebuggingModes
Ajjbtaahcizcu.Properties
List_Types
GetExportedTypes
GetBytes
BindingFlags
JsonSerializerSettings
System.Collections
DeserializeObject
System.Net
get_Default
WebClient
get_Current
ParameterizedThreadStart
JsonConvert
MoveNext
System.Text
Ajjbtaahcizcu
get_Assembly
WrapNonExceptionThrows
WinRAR archiver
Alexander Roshal
WinRAR
'Copyright
Alexander Roshal 1993-2019
$f4778331-01b0-49b9-a0ed-3fd800730a68
5.71.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4A
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
90!U?4#
NA+|PD.
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
{'Url':'http://www.google.com'}
https://store2.gofile.io/download/6d09093e-3140-4f91-86bc-50e2ec5aba70/Spxetbpourfw.dll
SCEPT0sfbU
'Name': 'James',
'Offices': [
'Auckland',
'Wellington',
'Christchurch'
Auckland
Wellington
Christchurch
Kgyingqfjfupoiyhni
website
Ajjbtaahcizcu.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
WinRAR archiver
CompanyName
Alexander Roshal
FileDescription
WinRAR archiver
FileVersion
5.71.0.0
InternalName
70016103621110.exe
LegalCopyright
Copyright
Alexander Roshal 1993-2019
LegalTrademarks
OriginalFilename
70016103621110.exe
ProductName
WinRAR
ProductVersion
5.71.0.0
Assembly Version
5.71.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Trojan.DownLoader43.46758
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37818547
K7GW Clean
CrowdStrike win/malicious_confidence_80% (W)
BitDefenderTheta Gen:NN.ZemsilF.34218.em0@a4BD5ql
Cyren W32/MSIL_Kryptik.FVA.gen!Eldorado
ESET-NOD32 a variant of MSIL/Kryptik.ADFA
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.NanoBot.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Trojan.Win32.Z.Small.77824.B
Tencent Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.5139e24e3fa4d06a
Emsisoft Trojan.GenericKD.37818547 (B)
SentinelOne Clean
GData Win32.Trojan.Agent.0Y3SBC
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MSILKrypt.C4705454
Acronis Clean
McAfee RDN/Generic Downloader.x
TACHYON Clean
VBA32 Trojan-Downloader.MSIL.gen
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Small
eGambit Clean
Fortinet MSIL/Kryptik.ADFA!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.