Static | ZeroBOX

PE Compile Time

2022-03-25 11:23:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000019b0 0x00001a00 5.67953989199
.rsrc 0x00004000 0x00028daf 0x00028e00 3.24670894834
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002c1b3 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0002c657 0x00000148 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002c7db 0x000003ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002cbc5 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+#+$+)+*+++0+5
+&+++0+5+6
v4.0.30319
#Strings
Aailqgn.exe
Aailqgn
<Module>
mscorlib
Object
System
Process
System.Diagnostics
Settings
Nzalyv.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
Culture
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Stream
System.IO
CopyTo
MemoryStream
ToArray
WebRequest
System.Net
Create
GetResponse
WebResponse
GetResponseStream
IDisposable
Dispose
System.Collections
Single
List`1
System.Collections.Generic
GetEnumerator
IEnumerator
get_Current
Console
WriteLine
MoveNext
AppDomain
get_CurrentDomain
Assembly
ProcessStartInfo
ServicePointManager
set_SecurityProtocol
SecurityProtocolType
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
WaitForExit
String
Stack`1
Enumerator
IEnumerable`1
Queue`1
Enqueue
InvokeMember
BindingFlags
Binder
GetAssemblies
GetTypes
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
Google Chrome
Google LLC
/Copyright 2022 Google LLC. All rights reserved.
$2e51f700-4b74-413a-b178-38bc5400bb7e
99.0.4844.82
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
&&&&&&
bbbbbb
&&&&&&
bbbbbb
&&&&&&
bbbbbb
A,6=7#C
""w;z}
|GMT*K
d1=7#].
!Ws{o7
Ib<)O|"
3_=^x(
Fr?Fr_Fr
Fr?Fr_Fr
Fr?Fr_Fr
Fr/Fr?Fr
FrFr?;Z
Fr?Fro;Z
FrFr?FroFr
Fr?FrOFr
Fr?4J
Fr?4J
Fr?FrOFr
Fr?FrOFr
Fr?6P
Fr?6P
Fr?6P
Fr/1D!
"fFrFr?Fr
"`Fr?FrOFr
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Welcome
Tutlane
powershell
-enc UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMgAwAA==
https://www.ocpi.com.my/smoke/loader/uploads/Aailqgn_Gpbardej.png
Pvtcxjzvgzuq
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Google Chrome
CompanyName
Google LLC
FileDescription
Google Chrome
FileVersion
99.0.4844.82
InternalName
Aailqgn.exe
LegalCopyright
Copyright 2022 Google LLC. All rights reserved.
LegalTrademarks
OriginalFilename
Aailqgn.exe
ProductName
Google Chrome
ProductVersion
99.0.4844.82
Assembly Version
99.0.4844.82
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agent.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!9AA3FB9A528A
Malwarebytes Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.GMM.gen!Eldorado
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
Cynet Clean
Kaspersky UDS:Trojan-PSW.MSIL.Agensla.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.FakeChrome!1.9C7B (CLASSIC)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.9aa3fb9a528a1289
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet MSIL/Agent.LAM!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34294.km0@aiNc@!f
AVG TrojanX-gen [Trj]
Avast TrojanX-gen [Trj]
No IRMA results available.