Static | ZeroBOX

PE Compile Time

2021-11-11 01:55:22

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
$ 1)b|\x1c\x0f 0x00002000 0x00004058 0x00004200 7.99081251468
.text 0x00008000 0x00006d58 0x00006e00 5.07823833895
.rsrc 0x00010000 0x00000a36 0x00000c00 4.28162092888
0x00012000 0x00000010 0x00000200 0.101910425663
.reloc 0x00014000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000100a0 0x000007ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001084c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x412000 _CorExeMain

!This program cannot be run in DOS mode.
$ 1)b|
`.rsrc
`.reloc
#TvxW@
^r*E<%@
fg^,8u>
N.bR 9
>~aJfg
ISdL;e
I9BnVW
>Q'MGS<%I
VW7q[b/
`~@0P'n
J:1d1gM
]X+=N(
7D6e`_
MV$s[gk
b@?8^HD]
[LK@pK
o4=g,wt
s+_X*5
-KM@.kG
eJy%hr
I!yL;j
Q@_w?
8%d{|(
Q2!#;]IN
o~0Fv4x
5*ZT(9
nd9`1
:V[viZ
A5Chr;
vMSk?!
-3?3Z
v"Ya8f
Z |-9|a8
Z -+-wa8
?XX%&8
S|,a8v
ZZ )0NNa8
j %&8q
4cZa8(
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
IEnumerable`1
List`1
UInt32
get_UTF8
<Module>
GetHINSTANCE
System.IO
DownloadData
mscorlib
System.Collections.Generic
Thread
CreateInstance
Invoke
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Module
get_Name
get_FullyQualifiedName
get_FullName
ValueType
GetElementType
MethodBase
Dispose
GuidAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
add_AssemblyResolve
System.Threading
Encoding
GetString
get_Length
Marshal
kernel32.dll
MemoryStream
System
AppDomain
get_CurrentDomain
System.Reflection
Intern
MethodInfo
MemberInfo
ParameterInfo
Buffer
ResolveEventHandler
Activator
.cctor
IntPtr
System.Runtime.InteropServices
System.Runtime.CompilerServices
ResolveEventArgs
Equals
get_Chars
RuntimeHelpers
GetParameters
Object
VirtualProtect
System.Net
op_Explicit
WebClient
get_EntryPoint
ParameterizedThreadStart
System.Text
InitializeArray
ToArray
GetCallingAssembly
GetExecutingAssembly
BlockCopy
op_Equality
op_Inequality
1.0.0.0
$2c0e0a2e-3994-43dc-8f76-18ae2f3db990
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.0db3251c697b3c25
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Trojan ( 0058a5241 )
Cybereason malicious.ac118e
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34266.du0@aK8lqog
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FNJS
Baidu Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DKE21
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-spy.Stealer.Jcl
Ad-Aware Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Trojan.Agent.Win32.1352707
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Drixed.ph
CMC Clean
Emsisoft Clean
APEX Malicious
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Gridinsoft Trojan.Heur!.03013281
Microsoft Trojan:Script/Phonzy.C!ml
SUPERAntiSpyware Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!0DB3251C697B
TACHYON Clean
VBA32 CIL.StupidPInvoker-1.Heur
Malwarebytes Clean
Ikarus Clean
Panda Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_96%
Fortinet Clean
Webroot Clean
AVG Win32:CoinminerX-gen [Trj]
Avast Win32:CoinminerX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.