Static | ZeroBOX

PE Compile Time

2022-06-14 11:26:17

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000179c 0x00001800 5.53488706026
.rsrc 0x00004000 0x0000aa7c 0x0000ac00 7.22410270275
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00007c78 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c78 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c78 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c78 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0000e4ac 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000e4ec 0x000003dc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e8c8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
yours20
yours20.exe
mscorlib
System
System.Core
Kyczsp.Properties.Resources.resources
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
ApplicationSettingsBase
System.Configuration
SettingsBase
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
ProcessStartInfo
ProcessWindowStyle
Func`2
CultureInfo
System.Globalization
IDisposable
MemoryStream
System.IO
Stream
StreamReader
TextReader
IntPtr
Enumerable
System.Linq
HttpWebRequest
System.Net
HttpWebResponse
WebRequest
WebResponse
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
MethodInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Thread
System.Threading
<Module>
Settings
Kyczsp.Properties
.cctor
value__
Reverse
Create
GetResponse
GetResponseStream
ToArray
Dispose
op_Inequality
Invoke
get_StartInfo
set_FileName
set_Arguments
set_CreateNoWindow
set_WindowStyle
set_UseShellExecute
set_RedirectStandardOutput
get_StandardOutput
ReadToEnd
GetDomain
op_Equality
GetTypes
GetMethods
get_FullName
get_Name
GetTypeFromHandle
get_Assembly
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
$8f57bd65-3c42-4d27-a01d-89e5873dc726
5Copyright Microsoft Corporation. All rights reserved.
Microsoft Edge
Microsoft Corporation
102.0.1245.39
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
o+-pj**<
T>vzVLM
IDATx^
*)&%L.)M
`x]U7g
3=AE"
?1{5$e
{g'dd-
F(JiQNU@p
"PqxM4
Ioay0
M`)de-
>B;o(u>
a'IL m
.,[UWt
!5EF (+
^f# Y4
o]Xj~(H?
8L <fB
f.OKQ9
}E~o4*
|#2vlTH
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
https://www.uplooder.net/img/image/36/c84826e53f475f5c282fbf42e49704ff/yours20-Cybunddd.jpg
powershell
Start-Sleep -Seconds 18
Elbqglhlrmdayncfd.Xmkxwxxafhrlospg
Ygjfkcihxiurfwra
Kyczsp.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Microsoft Edge
CompanyName
Microsoft Corporation
FileDescription
Microsoft Edge
FileVersion
102.0.1245.39
InternalName
yours20.exe
LegalCopyright
Copyright Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
yours20.exe
ProductName
Microsoft Edge
ProductVersion
102.0.1245.39
Assembly Version
102.0.1245.39
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!D7A7EB6C5F82
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_60% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.HIU.gen!Eldorado
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Avast DropperX-gen [Drp]
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.qc
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:MSIL/AgentTesla.ZAT!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.34712.dm0@aOP6Twg
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Clean
Fortinet Clean
AVG DropperX-gen [Drp]
Cybereason malicious.ae4012
Panda Clean
No IRMA results available.