Static | ZeroBOX

PE Compile Time

2022-06-12 21:51:21

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001444 0x00001600 5.37668918832
.rsrc 0x00004000 0x000149d8 0x00014a00 7.25056362724
.reloc 0x0001a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00017f1c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00018384 0x000000bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00018440 0x000003e4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00018824 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<Module>
System.IO
mscorlib
Thread
Synchronized
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
DateTime
ValueType
GetType
ApplicationSettingsBase
HttpWebResponse
GetResponse
Dispose
Reverse
Create
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Jjsrvou.exe
System.Threading
System.Runtime.Versioning
GetResponseStream
MemoryStream
System
op_GreaterThan
AppDomain
GetDomain
System.Net.NetworkInformation
System.Configuration
System.Globalization
System.Reflection
CultureInfo
InvokeMember
Binder
ResourceManager
System.CodeDom.Compiler
.cctor
System.Diagnostics
AddSeconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Qlknu.Properties.Resources.resources
Qlknu.Properties
BindingFlags
Settings
IPStatus
get_Status
Cmmckp.dat
Object
System.Net
HttpWebRequest
Jjsrvou
get_Now
ToArray
get_Assembly
PingReply
Internet Explorer
WrapNonExceptionThrows
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
Microsoft Corporation
11.0.9600.18817
$49fcbd6a-431a-4f2b-8126-405e27cb2faa
Microsoft Corporation. All rights reserved.
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
_CorExeMain
mscoree.dll
;BDDNRRGE;
=DNbfjnnjojutrR;
nnqqqqqzqqqojiUR:
hpzzzz
zzzqqiiPE
I?(((()(((((
+?@(IJ
0-ZZW$
'fhimmmhf+%
}G/-4X
DE4/4////////---
DF443333130
4CEHH90
$DkynC&
.ENNNG.
x\3.N,:
\q=AP\
!#4VBc9
/[z`X[
fC|_t@;1
[n?rhf
u!Ug4X}
a.ry.v
Z5&s&7
;X;y'+
L$XzKH
b[P,kG
(xk0ql
b}k!kB
T:E6m2A
3$zBPs
4wNOu{
6wi g"
M>8Hcp
gdMkS7
'?tBRp
\zq5%`
l.igM4
@&0&_g
3w2!_a|
~bMkd`!
VEXM$
lRwSjH4_?
L(}^$A>#
g Sk?eY
AFR#@.2#$
qYFnrm
kwE*PPB_
Q Gt.9
q1"hifge],
Rp$RCJ
c4Z'Ej[ 5"
@$/t"T
<"dzNZ
f?[I/f
(2Wt[9pd
C?&f{fp
0;jx|
*B 8W]P
Lb m6X
\-0XH1*
By}H&C'
UJ_Pbp
5]1LrT
;Ye/(u&
l>(UuSI
e&V"%JA
Fy_Bc=
!U@d5cZ
?h:81
kW)/Z0
pC{yu5
IDAT9#
%JVzI5)
?1%SGf
P2}_nA
*#k*~#
K\|7_i
$eO&iK
1F$A"w
`X"8|N
1Ywfcp
"HMtcX
pIDAT7
1Igjzu
['/FWL
IWL=Eevm
eZzjUfj
V9fB0,
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
.+^.3^.;
Dsuhwiuyu
google.com
http://23.229.34.114:81/Jjsrvou_Rudctjfs.bmp
Qlknu.Properties.Resources
Zkrlaiuyelpaalslf.Meduufdowjwrnafkcmaa
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Internet Explorer
CompanyName
Microsoft Corporation
FileDescription
Internet Explorer
FileVersion
11.0.9600.18817
InternalName
Jjsrvou.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Jjsrvou.exe
ProductName
Internet Explorer
ProductVersion
11.0.9600.18817
Assembly Version
11.0.9600.18817
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Generic.mg.6e26dd07bb0c9e44
Emsisoft Clean
Ikarus Trojan.Inject
GData Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
MAX Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34712.fm0@ae9ASxf
AVG DropperX-gen [Drp]
Avast DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.