Static | ZeroBOX

PE Compile Time

2022-01-19 11:18:39

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001600 0x00001600 5.6870823684
.rsrc 0x00004000 0x0002965a 0x00029800 3.37973238983
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002ceb0 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002cf70 0x000004c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002d470 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
X+d+e
-A+?8h
+$+)+*++
+&+++0+5+6
v4.0.30319
#Strings
9678012459.exe
9678012459
<Module>
mscorlib
Object
System
Settings
WindowsFormsApp10.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
System.Reflection
.cctor
GetAssemblies
GetData
GetTypes
GetString
Culture
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Thread
System.Threading
GetDomain
AppDomain
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MethodInfo
MethodBase
Invoke
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
WebClient
String
Replace
System.Core
Enumerable
System.Linq
Reverse
IEnumerable`1
System.Collections.Generic
ToArray
get_FullName
op_Equality
GetExportedTypes
GetMethods
MemberInfo
get_Name
get_Length
Console
WriteLine
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
<4G Mobile Hotspot
eCopyright
$58323aaa-add8-4f83-b885-ecac96034b0c
51.1052.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
IDATx^
u`C7ib$
U+W]9~
}amaOuds}{
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
IDowInlIoadDIataI
http://trietlongvinhvien.info//.tmb/ID4/9678012459.jpeg
Adnmertpchlom.Main
Xekneuwaerrfgfuquvspswi
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
4G Mobile Hotspot
FileDescription
FileVersion
51.1052.0.0
InternalName
9678012459.exe
LegalCopyright
Copyright
LegalTrademarks
OriginalFilename
9678012459.exe
ProductName
4G Mobile Hotspot
ProductVersion
51.1052.0.0
Assembly Version
51.1052.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Strictor.267735
FireEye Generic.mg.af4fc86d0d07bba1
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Downloader
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/Faker.Q.gen!Eldorado
ESET-NOD32 a variant of MSIL/GenKryptik.FPYG
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Remcos.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL:eno83vFk2SpgEdhoIX7SEQ)
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Emsisoft Gen:Variant.Strictor.267735 (B)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=84)
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!AF4FC86D0D07
TACHYON Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
Fortinet W32/Agent.KAD!tr
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
No IRMA results available.