Static | ZeroBOX

PE Compile Time

2022-01-18 18:14:20

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001744 0x00001800 5.54224316355
.rsrc 0x00004000 0x0002966c 0x00029800 3.39467600638
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002ba70 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002cf58 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002cfdc 0x000004dc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002d4b8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
1466350393404834
1466350393404834.exe
mscorlib
System.Core
System
WindowsFormsApp82.Properties.Resources.resources
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
List`1
ApplicationSettingsBase
System.Configuration
SettingsBase
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
ProcessStartInfo
ProcessWindowStyle
CultureInfo
System.Globalization
Enumerable
System.Linq
SecurityProtocolType
System.Net
ServicePointManager
WebClient
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
MethodInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
ExtensionAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
String
<Module>
Settings
WindowsFormsApp82.Properties
.cctor
Reverse
ToArray
set_SecurityProtocol
set_FileName
set_Arguments
set_WindowStyle
WaitForExit
GetTypeFromHandle
Replace
GetMethod
Invoke
get_CurrentDomain
GetAssemblies
GetExportedTypes
AddRange
GetMethods
get_Name
op_Equality
get_Assembly
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
$f17f7072-e885-462e-9890-ee985c857899
eCopyright
<4G Mobile Hotspot
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
51.1052.0.0
_CorExeMain
mscoree.dll
IDATx^
u`C7ib$
U+W]9~
}amaOuds}{
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
powershell
-enc YwBtAGQAIAAvAGMAIAB0AGkAbQBlAG8AdQB0ACAAMQA5AA==
DowZnlZoadDZata
http://ozzyingilizce.com/wp-content/sgu/1466350393404834.bin
Rjawkgvxmogxyldatmqw
WindowsFormsApp82.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
4G Mobile Hotspot
FileDescription
FileVersion
51.1052.0.0
InternalName
1466350393404834.exe
LegalCopyright
Copyright
LegalTrademarks
OriginalFilename
1466350393404834.exe
ProductName
4G Mobile Hotspot
ProductVersion
51.1052.0.0
Assembly Version
51.1052.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Noon.l!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.MSIL.PsDownload.gen
K7AntiVirus Trojan-Downloader ( 0058d2a81 )
Alibaba Clean
K7GW Trojan-Downloader ( 0058d2a81 )
Cybereason malicious.5b5042
BitDefenderTheta Clean
VirIT Clean
Cyren W32/MSIL_Troj.BVY.gen!Eldorado
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.KBD
Baidu Clean
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.PsDownload.gen
BitDefender Trojan.GenericKD.38604704
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.38604704
Avast Win32:MalwareX-gen [Trj]
Tencent Clean
Ad-Aware Trojan.GenericKD.38604704
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.8b86e421aeff8726
Sophos Mal/Generic-S
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX malware (ai score=87)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:MSIL/AgentTesla.KA!MTB
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
GData Trojan.GenericKD.38604704
AhnLab-V3 Trojan/Win.MalwareX-gen.R466071
Acronis Clean
McAfee RDN/Generic.dx
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CAI22
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/Agent.KAD!tr
AVG Win32:MalwareX-gen [Trj]
Panda Clean
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.