Static | ZeroBOX

PE Compile Time

2022-05-20 19:19:22

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000168c 0x00001800 5.37857457404
.rsrc 0x00004000 0x00004d7c 0x00004e00 4.7664131435
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008198 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008198 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008198 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00008198 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00008600 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00008640 0x00000588 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00008bc8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
Zzrfmn
Zzrfmn.exe
mscorlib
System
System.Windows.Forms
System.Core
System.Drawing
Uzmoew.Properties.Resources.resources
Action
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
Dictionary`2
System.Collections.Generic
ValueCollection
IEnumerable`1
Container
System.ComponentModel
IContainer
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DateTime
Delegate
DebuggerNonUserCodeAttribute
System.Diagnostics
Double
CultureInfo
System.Globalization
IDisposable
MemoryStream
System.IO
Stream
Enumerable
System.Linq
SecurityProtocolType
System.Net
ServicePointManager
WebRequest
WebResponse
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MethodInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
AutoScaleMode
ContainerControl
Control
<Module>
Settings
Uzmoew.Properties
Dispose
.cctor
get_Now
AddSeconds
WriteLine
op_GreaterThan
get_Tag
GetTypeFromHandle
CreateDelegate
DynamicInvoke
set_Text
set_Name
get_Text
GetType
get_Name
GetMethod
set_Tag
set_AutoScaleMode
set_ClientSize
set_SecurityProtocol
get_Values
ToArray
Create
GetResponse
GetResponseStream
CopyTo
get_Assembly
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
$1f57c585-cf57-4fca-bea9-84e04e0d9f76
dCopyright (C) 2008-2017 EveryonePiano.com
<EveryonePiano
<EveryonePiano.com
<EveryonePiano Setup
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
1.2.11.30
_CorExeMain
mscoree.dll
///bppp
$$$aSSS
###`)))
***b;;;
###bDDD
555p///
:::o???
333p???
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Vjygujcqyaebmgcuamrjiycx.Uuotwyupxfapmblfph
Gpnnqz
http://darley.ml/h/Zzrfmn_Kyaogqlh.bmp
Uzmoew.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
EveryonePiano Setup
CompanyName
EveryonePiano.com
FileDescription
EveryonePiano Setup
FileVersion
1.2.11.30
InternalName
Zzrfmn.exe
LegalCopyright
Copyright (C) 2008-2017 EveryonePiano.com
LegalTrademarks
OriginalFilename
Zzrfmn.exe
ProductName
EveryonePiano
ProductVersion
1.2.11.30
Assembly Version
1.2.11.30
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Multi.Generic.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.50316481
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.50316481
Cylance Unsafe
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.50316481
K7GW Trojan-Downloader ( 005931bb1 )
K7AntiVirus Trojan-Downloader ( 005931bb1 )
BitDefenderTheta Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.HHG.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.LWL
Baidu Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DEK22
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:MSIL/Keylogger.36fc5a1a
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.50316481
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen17.54626
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Formbook
FireEye Generic.mg.61d8380734dab62a
Emsisoft Trojan.GenericKD.50316481 (B)
APEX Malicious
GData Win32.Trojan.Agent.GQY2F0
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1249297
MAX malware (ai score=85)
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Ransom.Win32.Wacatac.sa
Arcabit Trojan.Generic.D2FFC4C1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Dropper/Win.DropperX-gen.C5137801
Acronis Clean
McAfee RDN/Formbook
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.FormBook
Ikarus Trojan-Spy.Keylogger.AgentTesla
Panda Clean
Zoner Clean
Tencent Msil.Trojan-downloader.Agent.Wozw
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.LWL!tr.dldr
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.e277e2
Avast Win32:DropperX-gen [Drp]
No IRMA results available.