Static | ZeroBOX

PE Compile Time

2022-01-18 14:16:51

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000019b8 0x00001a00 5.62761575659
.rsrc 0x00004000 0x0002964a 0x00029800 3.3794062033
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002ceb0 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002cf70 0x000004b4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002d460 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+*+?+@
+*+/+0+5
- +3+4+9+>+?
+5+6+7+
+&+++0+5+6
v4.0.30319
#Strings
Jbbmfq.exe
Jbbmfq
<Module>
mscorlib
Object
System
Settings
WindowsFormsApp23.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
MethodInfo
System.Reflection
Assembly
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
MethodInfos
Assemblies
Arrays
Culture
Default
System.Core
ExtensionAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
GetExportedTypes
List`1
System.Collections.Generic
AddRange
IEnumerable`1
ToArray
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
ProcessStartInfo
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
Process
WaitForExit
MethodBase
Invoke
MemberInfo
get_Name
String
op_Equality
GetMethods
AppDomain
GetAssemblies
get_CurrentDomain
Enumerable
System.Linq
Reverse
WebClient
GetTypeFromHandle
RuntimeTypeHandle
Replace
GetMethod
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
<4G Mobile Hotspot
eCopyright
$984d4fb1-0240-4ca5-bef8-96d2ded9b327
51.1052.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
IDATx^
u`C7ib$
U+W]9~
}amaOuds}{
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
powershell
-enc YwBtAGQAIAAvAGMAIAB0AGkAbQBlAG8AdQB0ACAAMQA5AA==
Dkhsgvianokpdkwcmhef
DowEnlEoadDEata
http://ozzyingilizce.com/wp-content/sgu/Jbbmfq.bin
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
4G Mobile Hotspot
FileDescription
FileVersion
51.1052.0.0
InternalName
Jbbmfq.exe
LegalCopyright
Copyright
LegalTrademarks
OriginalFilename
Jbbmfq.exe
ProductName
4G Mobile Hotspot
ProductVersion
51.1052.0.0
Assembly Version
51.1052.0.0
Antivirus Signature
Lionic Trojan.MSIL.Quasar.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.38592473
FireEye Generic.mg.c467bc0aecc324a9
CAT-QuickHeal Clean
McAfee RDN/LokiBot
Cylance Clean
VIPRE Clean
Sangfor Trojan.MSIL.Quasar.gen
K7AntiVirus Clean
BitDefender Trojan.GenericKD.38592473
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W32/Faker.Q.gen!Eldorado
Symantec MSIL.Downloader!gen7
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.GO
Baidu Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CAI22
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Quasar.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.92 (RDM.MSIL:Cm1eOs25c0p6ggcvKOKwXg)
Ad-Aware Trojan.GenericKD.38592473
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen16.35415
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.GenericKD.38592473 (B)
APEX Malicious
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Woreflint.A!cl
SentinelOne Static AI - Malicious PE
AhnLab-V3 Trojan/Win.Agent.C4403060
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/Agent.KAD!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.