Static | ZeroBOX

PE Compile Time

2022-05-16 20:00:39

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00002384 0x00002400 5.45654953348
.rsrc 0x00006000 0x0000dc5e 0x0000de00 7.26717595869
.reloc 0x00014000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a55c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000a55c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000a55c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000a55c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000a55c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x0001363a 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000136c2 0x00000376 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00013a74 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+E+J+K
+C+D+E+F
"@++$+
+!+&+'+,+--
+&+++0+5+6
v4.0.30319
#Strings
Nzzgmmjy.exe
Nzzgmmjy
<Module>
mscorlib
Object
System
ValueType
System.Windows.Forms
Settings
Zstkrj.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
Assembly
System.Reflection
MethodInfo
IContainer
System.ComponentModel
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
downloadPage
parentFolder
fileId
fileName
Culture
Default
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
STAThreadAttribute
EditorBrowsableAttribute
EditorBrowsableState
.resources
IDisposable
GetType
GetMethod
Dictionary`2
System.Collections.Generic
get_Values
ValueCollection
System.Core
Enumerable
System.Linq
ToArray
IEnumerable`1
Container
ContainerControl
set_AutoScaleMode
AutoScaleMode
System.Drawing
set_ClientSize
Control
set_Text
Action
GetTypeFromHandle
RuntimeTypeHandle
Delegate
CreateDelegate
DynamicInvoke
DateTime
get_Now
AddSeconds
op_LessThan
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
WebClient
DownloadData
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
PureCrypter
PureCoder
Copyright
2021
$c5166b78-a763-40cb-a9dd-4e33ab02e9df
2.0.8142.35751
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
U1g@DI
~80uyy
v{aaavv
NwvvRJG
3gvtt,Z
5Mklllhh
+///;;
+/<h &
X$e6:D
koookk
jBHNNN~~>cL
mV/S5DR
b6;eY;
YQdUM#
lr`*bD(
<B('7?77
:;;[ZZ@
U5ZLi*
>uO}g[
PGGGCC
]9VUQ0
!r:=`@
nK$b;w
3z<PJc
b1B0!$
T*UYYi
TRN&S]]
Emlhnj
RZ___SS
sLfQQe
+*c<'j
0B"BLS
4(I5M;
!JUUAH
1J1cXQ(P
\rikkkyy
{?84 0
@sssII
i:M5777
{*,MU'M:
(vuuuvv
M&Svv64
zTxKJK
_SSSSS
Pccc{{;
{j5M6:
f_`KRVVVII
&JieeeII
?~|EEEAA
]]]yyy
X,999P
*..njj
***TM#
D:::t"
fsnnnEEEnnn
W]uUKK
V+B(//
h4RJ}>_~~~qq1
cYYYPD
DL&Saa
C^^^^^
e]]]AA
RGGGkkk<
X,V[[{
~}{{{QQ
caa!0aa]M
BHkkk,
;::rss3
+.....
Q `CpN
_1YQrrr
Y^/,H>
:th^^
;::`y8
cnmmM&
Ggr`L&
"@=D)h
lF=x?P
5MSUMUuF"UUM
H$RZZj
Nuuu}}
F[gd477777
^QJ;::
U{p0x'
O?]\\\^^
UUU_|1
Css3L<
#EU***@
BYYYnn.0
.TSSSSSc
JaUUUU
[~~~uu
9UU].'
Z~~>PA
]]]_-^
JKKsrrR
IU5X2w
ijKKsf7
H{{;LZn
QJEIjmm
mkCcsZV
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Jxfsvhqodnqqvmwxldz.Ukyvjfdyydjozugzt
Szajvj
Guiciqokdlbvpyghxmht
http://example.com/Nzzgmmjy_Shkxumyu.bmp
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
PureCrypter
CompanyName
PureCoder
FileDescription
PureCrypter
FileVersion
2.0.8142.35751
InternalName
Nzzgmmjy.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
Nzzgmmjy.exe
ProductName
PureCrypter
ProductVersion
2.0.8142.35751
Assembly Version
2.0.8142.35751
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.49029941
FireEye Generic.mg.24ec18a308154964
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.49029941
Cylance Unsafe
Sangfor Trojan.MSIL.Seraph.gen
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.49029941
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZemsilF.34682.em0@aeMh5uk
VirIT Clean
Cyren W32/MSIL_Kryptik.GMZ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.FUQO
Baidu Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CEG22
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Trojan:MSIL/GenKryptik.d293e856
NANO-Antivirus Clean
ViRobot Clean
APEX Malicious
Tencent Clean
Ad-Aware Trojan.GenericKD.49029941
Emsisoft Trojan.GenericKD.49029941 (B)
Comodo Clean
F-Secure Trojan.TR/Kryptik.uvets
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic Dropper
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Inject
GData Trojan.GenericKD.49029941
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.uvets
MAX malware (ai score=82)
Antiy-AVL Trojan[Downloader]/MSIL.Seraph
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Trojan.Generic.D2EC2335
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic Dropper
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/GenKryptik.FUQO!tr
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.bf6122
Avast Win32:DropperX-gen [Drp]
No IRMA results available.