Static | ZeroBOX

PE Compile Time

2022-01-20 11:33:57

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001a68 0x00001c00 5.50135760577
.rsrc 0x00004000 0x0002965a 0x00029800 3.78543747133
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0002b98c 0x000014e8 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002ceb0 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002cf70 0x000004c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002d470 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+"+'+(+)
+8+9+:(
+&+++0+5+6
v4.0.30319
#Strings
121Oyzuedk.exe
121Oyzuedk
<Module>
mscorlib
Object
System
WindowsFormsApp70
Settings
WindowsFormsApp70.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
<>9__5_0
ThreadStart
System.Threading
List`1
System.Collections.Generic
Assembly
System.Reflection
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
GetTextModel
Tutorial
Assemblies
Culture
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Console
WriteLine
Thread
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
AppDomain
get_CurrentDomain
System.Core
Enumerable
System.Linq
Reverse
IEnumerable`1
ToArray
GetDomain
GetAssemblies
AddRange
GetEnumerator
Enumerator
get_Current
GetExportedTypes
GetMethods
MethodInfo
MemberInfo
get_Name
String
op_Equality
MethodBase
Invoke
MoveNext
IDisposable
Dispose
GetTypeFromHandle
RuntimeTypeHandle
Replace
GetMethod
ProcessStartInfo
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
Process
WaitForExit
WebClient
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
<4G Mobile Hotspot
eCopyright
$f54b259b-5fe5-41b5-93f2-6ca09ea45b17
51.1052.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
IDATx^
u`C7ib$
U+W]9~
}amaOuds}{
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Sxlexep
Ffbnenjoymtoysmqokzecbk
/C ping google.com
AyrrDowAyrrnlAyrroadDAyrrataAyrr
http://trietlongvinhvien.info//.tmb/ID4/121Oyzuedk.bin
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
4G Mobile Hotspot
FileDescription
FileVersion
51.1052.0.0
InternalName
121Oyzuedk.exe
LegalCopyright
Copyright
LegalTrademarks
OriginalFilename
121Oyzuedk.exe
ProductName
4G Mobile Hotspot
ProductVersion
51.1052.0.0
Assembly Version
51.1052.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Strictor.267735
FireEye Generic.mg.dce983778e604b79
CAT-QuickHeal Clean
McAfee Artemis!DCE983778E60
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Strictor.267735
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/Faker.Q.gen!Eldorado
Symantec MSIL.Downloader!gen7
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.KBQ
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Strictor.267735
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownloaderNET.288
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
CMC Clean
Emsisoft Gen:Variant.Strictor.267735 (B)
Ikarus Clean
GData Gen:Variant.Strictor.267735
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1133936
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MSILKrypt.R466822
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34160.km0@aCZPdlf
ALYac Gen:Variant.Strictor.267735
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Agent.KBQ!tr.dldr
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.99b0b8
Avast Win32:DropperX-gen [Drp]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.