Static | ZeroBOX

PE Compile Time

2054-12-20 01:33:57

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00045700 0x00045800 7.97956708987
.rsrc 0x00048000 0x0003bf78 0x0003c000 6.70892734139
.reloc 0x00084000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00083404 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0008387c 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00083910 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00083d88 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Plugin01
Class1
ConsoleApp82
<Module>
System.IO
mscorlib
Thread
Synchronized
defaultInstance
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
get_Name
AssemblyName
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
ConsoleApp82.exe
System.Threading
System.Runtime.Versioning
String
NiceHash
System.ComponentModel
Ziyvzfbegvrrmp.Plugin01.dll
GetManifestResourceStream
MemoryStream
Program
System
resourceMan
AppDomain
get_CurrentDomain
Plugin
System.Configuration
System.Globalization
Action
System.Reflection
CopyTo
CultureInfo
Ziyvzfbegvrrmp
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Ziyvzfbegvrrmp.Properties.Resources.resources
DebuggingModes
Ziyvzfbegvrrmp.Properties
Settings
ResolveEventArgs
Contains
Concat
GetObject
get_Default
Prefix
ToArray
get_Flsdjdbahtouiqtyrdbky
get_Assembly
GetExecutingAssembly
WrapNonExceptionThrows
Adobe Acrobat DC
Adobe Systems Incorporated
Adobe Acrobat DC
VCopyright 1984-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
$23af43fe-ebab-4290-b209-8a767f29604e
19.10.20069.49826
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
ns$C,6
Z@fA[}
4KgY\
qa*2F
@<,BC6>x_
"sp`Y+
$7nMFr
jmi8])
$tX*RW
+U$=eh
MX9u?&}&0
b&tW`--N$4v
&ae[Z:@
#8_h9P
9:&CW
:,of]K2L?h
)sHKm/
3SKS6RG
Ev#80m
N;r[,7
Jp/<zk
6&[Iwn
d/P,\"
giH/F`c
QJK[UOh3
=6`FmA
8BK%45
,hCN93
nKL [R=
B<6Oa2
B:#nfw
7of-|C
"M'Oi#P
9m~sr$V?
aJ-H(y
PT68V6
K9Wv`?
kr>11H
TY4$+J
wl#%]b_
LJ3heY
-@{}$*
O(=i]gjC*
MjYZ"o
JGo_*d
"4GO8D
ZVNk7Z
;V$8cn
uz,8r
bb;bv$
1V.} w#
o!Q[:?
:g#'5pB
*;7H>)
?j7.Fe,
E`PSFn
Y]?^w/m
X\HdQn
n-~K_G
L?tXW]
]AYs&U
TgPP]s
P1-0`dI
3)S|lM
6@<$<t
")G]HyP
!_GwjU
MkUvzkl
.G3/XT
l_|Ee9
!)KCo;
GDGpSvM
,$,>oP
U4MzYP
hO'Jlem
m*bGjo
`cdVe5.
so*kO\
e0nx65`qI
4/izO*S
Z&R=u.!b]z^
Z@d1!'
!,wFKWfb
{TtH2>]0
qLpjhU
-R3naa`
"TVU:k.
DEh)ld&
5(p':t
(e)yR
g<f:Gcr
|*Nq2,
7d):D}V
cr[zhD
o?MqSt
G5V3t:z
Q"tV{Yf
hP>9vxY
bT7&8a
7ylYC#9
T4r;ZD
jF6EM'M
g,r'>6+e
zj\#h$
<CV*r7
2]XP5u
MZ}3)2vd'
\XYRC-T
!cey\gm
1~+6-61
#D?uH+
EQ/$}B4p
$]KamAjg
rZR!XH
2av~#S3
FQ2=V8
/K,zWO
uDrO:(
s:N5pS
a'm%9x;
-BH_K{
:LeSy>
]K}D9#
zqpoU"
%cSv^6%<
K@~v;C
Unvx$d
-X>5Lu
n^E=8DO
cOfUs6
H(H>|$
Vpj8}K
nXKz;lC
!49vfl
ej]yZ8J
^_jt|x(
R;"b5LA
@m:}4$iz:
Uby(#Q
LTj*6m
:nTi{1
92ch:O
*'mY+C+
tB8y6O
~i(=7U?
q$6&[#
L2vi9y
~1%B3D
gP/,];H
R~E;8E
&y:O=y
d1aiv]
hg@{&$
Aw; S<
"n.[g}
)0O@Vlx
^N4gyT
D1X$q#
X@R*lM
r3bs7{D}Y
RURcC?
EOkocW
i}t|jaL
H?)X+i
6tDzDj
IL`Xg@*
#b}"TK
+7%pgz
d:iqN\
&_cR0.
N 2hYZ
JHt0;
hs$!\<
Y_xY 8
FZ]VC8
19,<k{Ak
GE">q60
{xx0^Q
>3u@3l
E"gQ6`%
\WMozg
t/jF7A
Fp~`YmX
79/;L"
4L&nKK
PW#,g
%3?Rm-
b9stZ]Ga
@Ij{EL@
,?@bzY
Kyg?@|C
g~\z&}Q
V3l|aU
ZTdX's
\nn\Y
TQ.mSa
ClYe+{!
A`&xJlX2
KjP~;[
cwK1u*G
c9Gz9>(
9>8 [a
*EvYd
0N/\iR
YcI;?E
BL-~%T
LI{vL-m+
v+l42c
pfMm5?B
'UAIR\
0&<-sC
)JYh)CT
j4h$$h
NUv|g
ugc<Oup0c
UXB }n
:S(!z
(8>eVF
k(4l`m8f=7
];tUt[y
p_3M*I
!k[|{
Jng 0K
oRaDWZN,I
Y\d(-ts7
.B2VF
+-|R!>
kO!<W:
RZ:|8s
,QY--hG
yq$I$'T
Fnmg:;
Ezhv@`
4=Sw}i$,;
KdY3\WA
;+jH|g>8
~NJL4n
Buo6yb
1(7.9ol
\3UF@B
nRk]^Hr<
H?)*Xo
F &XrsKU
E*$*oN
j%q:jzvV
;d(,kkB
=/}MF_
\%NH$d
?8a!XQ
>;br<1JK
AZbQym
E\"[(5+
UW){[u
+@M4[[
6in>:`
jK%ycu
1T7q>}
sB9Jo8
>2s*Tl"
?oDl%J
FHY8M]A
YeGC\d-H
JXZ:r;
];x*Ss
%QHC7A@
*HY85t
H.'6f=>
C8b4Z!
EJFNE?
JHQT/Y
p@.X)f
N8j>|S.
MXgp`lO
f'0Jf``
_rKbia
Oi_piu
qp0])A
km4K_w
cU+>B6
eb}g^5_
N?%SKc
2/gf[Mc
'kZ<wc
0[j\XV
@%Mlfb
bzt#3
I\2!CM
qXX'Hza
h#`oj0
~CS:og
uvT<dK6
%A_de~
o|kZB/Z
ht*RX,
x(&n8Z7
-4LfUF
CPi.&n
iSK*"X_]
c{Sx:B
lqgi%hw
l|'1Y|
$^X`)q
o7]W,
`b3kD{f
x89JJ+,
z?r(~T|x|A
YW]m4$
J84a^z
Y:"[]Gr+g
L)M[,1
=0[Wl;
W~2CNk
%RQSx&<
2/w-t&(
I8>(URu
Aj`Qv|
fO# JEa
]ad"hZ
7w*;CL,
v;}eSS
&7eGUX
ScIurK
DdEU&A
A%+5{Ot
$#>,ol
Kx30-)
'76;'$)
@(b8Z@
mnre7,2
n?4/Ak
m-^#.W
Vta"D2!y1y
jMB~(f
xt$uS,Q
@aWS:5
8@e3_/
=:F.=A
Vs_ ( m9
%k9V}(^
;T4*$z=~N
e_a}>`
Hco]'iZ
W)Q'P\
b*W<q0+
Q2BIi]
EadqX#
*f:lt
-5MZ?OL
p !]Gx))t(
GuOVp,sK9
bm4~#,
e,P*9p
'F =D\
%-InzR
eY8%PG
yftN#_
m}]k+AM
(.n|<N
Gk~Db~
6o[F%{{
=WzWm7
'gL1~qQ
Uh/fQ&
yZ'h`?L
xI4d\=
@yE/g;P
~N{bGd
fCI$,:
( dJ?Y
G.?L[b-
( 9nqq
Trfa[U
+>9C1
DGcQ17
7'e4Xb
@6!*B"66
a:4J'S[
Ygl!h*
m:8hY=!
[1B`Xy
TmVPy8}
!QZUOe
z(YZz:
[ux.5W^
it2?R
k5R?M8
Xr3j|TS
UP@G8rj
FI17?N
W}1o,[F
{iiv s
&}HlkM
;d?M_G
3+<'|u
qTYlL.
5og'fl
Z=eR\}<f
|$Vx=Sl
z'$6F!Hy
)"{{yP
"lG%p@
8Y-7r7
oB<ZB:
)3Vf1*lg
W&6(N<U#
vNOIut
3tL)^g
)S3AT=Z
o)$RF;=
{qORc>
ekS6RW
Rh;>wF~
Z'm 9sg
^"6jb
C/Sr/J
"~Q'?F
O/={WgN
;5U,m}}
o}'"{e
qn@H&y
#vL5Cz
aQ/x~B
&7MCQ%
QR@I;#6
cx,3 st
KdU9 3
\EyQ`K
E}.hQPI^
J)mT>{
^Oy4NFj_
&/gjGn
SEbnX9Ol
YS.9,a+
jq'|m$`}
ArLq^G
_=BaI7U
X,$!*BU
KN=}pf
\'%U!>
M Py[5
_+[gE*
ZhJD3`-1|
ffU[\:
9d%^nF%
'1-IIr%
OiO#3l
o7qp%4
4Y{t$V
V<3wK=n
l;9k<,e5
&.wxhf
e@H)bH
2 5Gy]
Xi'7U|Q^]E_
}CkCtG-
1E8)"H+
;SAA9e
P\V-jF
ix5?:L/2Z6
;A8_?GAyYy-
V&}y@Y"
$eP1M
qg??$.
IS{(zX
:jmp"^
]Q/q=~jd
PGK1M/
*XW%A4\
zffuDc
M<k{f
,[@{Uq
v+\>}a"
\xD?v^^D
hp{*$%
K8B5 *hG
MQ41b"
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v2.0.50727
#Strings
Plugin01
Class1
get_UTF8
<Module>
mscorlib
methodName
typeName
GetType
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Encoding
Plugin01.dll
System
Plugin
System.Reflection
Exception
InvokeMember
Binder
GetBuffer
buffer
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetBytes
BindingFlags
Object
System.Text
Assembly
WrapNonExceptionThrows
Plugin01
Copyright
2021
$03189a77-bd0f-47ce-aca1-3cc88f79aae5
1.0.0.0
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
DJ:2$){
>tnR`f
|MemtV
|`.NS
a?iu{i
QZk;#Q+
KHiO~m+
{^v,!$
b{0`'q
<W-W>z
EPZCYf
Tsbve
=2>:~abr
64xAf`
0V_0v~
0S&V%J
_Y]=4R
T"`Df4)
>351=]*
8IRSo4:
lombmy
mlmaks
u=GH?I
BBHt;m
cQ*ajj
VMW`c
5ZHY2%
IDATq#
F]0za-
*e]iM`
t:C[KQ
[[HXYU
]:QD x
vvagZZ
u%U [I
S;"NUU~
G\<s&]
[V%UY1
5E]:4Z
%$J:XI
N2]UOYH'
bU#==G
vmDUSU
,B>D#p
E*QJJ!d
:*4J:%_
DXW2'>xr:
GZ7Pr]
XYYMVz
z5WWUWW
51HUEU=y
z5h{n\?
(|uV8{Ns
zG''8:
,2 Q%Q2G
Fmhe.&
&&h0Q
s]%mQjH
F9s%IZ
bnv^eQ
X[yFm3A
$I&L"c
s7"mIz
8Y&s_2;
8sT!*`%eG
,;u`n2
-AALJ!
33 +Qt
{*NNN
(U:u{
-YTY+E\
}|p0yx|2
% 3P*m
7u5TV
,PU"nS
ch"`20
kW.^ZY)
*HD(FFg<k
Rd)Td%v
XO/.|3
E|n{Lazn
o'HK!9R[
x0<5Z(K
s6u4IA
'um. u
)pNaVy]e
5/lQ_d
*/%]~@
/>,rcP
III\:%
-H%7is
[X~Enyh
cu_D8P
<52TnE
_Vpw-
E-3uxJ
Z=0.i3G
!8]{mu
>{?u_zm
3vn-~n
G8_9+<
h?EY"E
M.o6he)
%W_Mk|
e7ggg9z
s3n$8q
-VJ!/H
v;"m!>
"Z4(aX9
zLWDH|5
(IipB&
ium-E~
wQ07?_1;
I(.;P~
\EJc1Fc
JY_[C`Qi
=hc(r[
'N2=7_s
Jw.v0q
/Vkffg
p?=_"l
oIDAT?
<'__gyy
(XZX`na
Yffg9==
XY^fyy
###dYF#
%VWVX]Y
m&&'X[]cey
2J%hQ{
/pZ|BU
uHBi++
nm(#aP
V0\aAIYG
m%%:*SB
@[#1vG
[hMYzy
4hc-eQ
;SAO.J
+K88<"r
lkV!ts\M}|ag
fdwv]KooZ#nnZ
ecJ@iiS
kkRJhgS
{2kqk+
~3\fa*
d_*_XU&
^Z'TNK$
TO"HCA"
{*LwsA9tqK!
+"xq!pxwd
10 265,
RN}DC5
sm"\mkW
}BwihR
-, bXXO
}f3ut`
gfNMnmX
mmTTihT
qk)OVR%
tm(AFD"
YXNu98%
FD*N\\S
mmV9{zc
rqZ;kkW
EB!yYU"
kkTTxxb
poXYiiU
zs'8LI"
xvfUcaM
_[3/_^T
jd%4RO!
pk-%baS
~jFjiU
]X".]X
wsL;\X3
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Plugin
Ziyvzfbegvrrmp.
Ziyvzfbegvrrmp.Properties.Resources
Flsdjdbahtouiqtyrdbky
lAqrjryXbs1mopglkKZ.eSwdfLyubw8IpKKK7E9
SAiy9giLVU
Zorugbjecnbkoczabcn
Flsdjdbahtouiqtyrdbky
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
Plugin01
FileVersion
1.0.0.0
InternalName
Plugin01.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
Plugin01.dll
ProductName
Plugin01
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Adobe Acrobat DC
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Acrobat DC
FileVersion
19.10.20069.49826
InternalName
ConsoleApp82.exe
LegalCopyright
Copyright 1984-2018 Adobe Systems Incorporated and its licensors. All rights reserved.
LegalTrademarks
OriginalFilename
ConsoleApp82.exe
ProductName
Adobe Acrobat DC
ProductVersion
19.10.20069.49826
Assembly Version
19.10.20069.49826
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Seraph.a!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37886468
FireEye Generic.mg.d475a16d7396c788
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37886468
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005898311 )
BitDefender Trojan.GenericKD.37886468
K7GW Trojan ( 005898311 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilF.34236.Gm0@aOP0ZBb
Cyren W32/MSIL_Kryptik.FYO.gen!Eldorado
Symantec MSIL.Packed.9
ESET-NOD32 a variant of MSIL/Kryptik.ADHJ
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Trojan:Win32/Maldoc.ali2000008
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37886468
Emsisoft Trojan.GenericKD.37886468 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Loader.892
Zillya Clean
TrendMicro TROJ_GEN.R002C0DJU21
McAfee-GW-Edition RDN/Generic Downloader.x
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.37886468
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1143694
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2421A04
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/Tnega.KA!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Mardom.C4731509
Acronis Clean
McAfee RDN/Generic Downloader.x
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes MachineLearning/Anomalous.95%
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DJU21
Tencent Clean
Yandex Trojan.Kryptik!6dhKpzKw6hM
Ikarus Trojan.MSIL.Krypt
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ADHC!tr
Webroot Clean
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.