Static | ZeroBOX

PE Compile Time

2022-06-16 13:05:51

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001918 0x00001a00 5.40972957438
.rsrc 0x00004000 0x00011fd4 0x00012000 6.76643429915
.reloc 0x00016000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00015574 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000159dc 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00015a54 0x000003cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00015e20 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
999.exe
mscorlib
System
System.Core
Wdfelyl.Properties.Resources.resources
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
ApplicationSettingsBase
System.Configuration
SettingsBase
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
ProcessStartInfo
ProcessWindowStyle
Func`2
CultureInfo
System.Globalization
IDisposable
MemoryStream
System.IO
Stream
StreamReader
TextReader
IntPtr
Enumerable
System.Linq
HttpWebRequest
System.Net
HttpWebResponse
WebRequest
WebResponse
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
MethodInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
ExtensionAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Thread
System.Threading
<Module>
Settings
Wdfelyl.Properties
.cctor
GetDomain
Reverse
Create
GetResponse
GetResponseStream
ToArray
Dispose
GetTypeFromHandle
get_Assembly
get_StartInfo
set_FileName
set_Arguments
set_CreateNoWindow
set_WindowStyle
set_UseShellExecute
set_RedirectStandardOutput
get_StandardOutput
ReadToEnd
GetType
GetMethods
Invoke
get_Name
op_Equality
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
WrapNonExceptionThrows
$1892451f-6b88-4c46-8d8e-ab1721bbf858
5Copyright Microsoft Corporation. All rights reserved.
Microsoft Edge
Microsoft Corporation
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
102.0.1245.39
_CorExeMain
mscoree.dll
z3/+?9HL
2hzq&Z
SZnz=s
McdV]bz
>Q`}^!X
.U++`F
G~t3`*
'?'3u8s
1][;c`z
5PYdw|
`gXzw
2+,\Ks
_8r,=A89n
$W{6tH
l}h;zS}'
~Z_~9b
3W*%/S
i@]-U_
'cTX|]
6G Pb=
dUMO=e
I1ayyY
n@r"02
`T 0_K
~/TL A
lQ:k6!
d, [l1h
mJ4W
Kh.o.@
r=,u~|=
M#|>|
'6,tEVh
k.ZYQ8
o+@C`L
/,(}?UQ
.ZK'K3
}l717nQ
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
https://www.uplooder.net/img/image/94/365c557dbb0fa37ee848c74b3f23fa8a/999-Pmmugalz.png
Wdfelyl.Properties.Resources
powershell
Start-Sleep -Seconds 10;Start-Sleep -Seconds 10;
Uhpovunsecttjxra.Odwdixcmeqntziktwnfcjti
Zzttbhaiakims
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Microsoft Edge
CompanyName
Microsoft Corporation
FileDescription
Microsoft Edge
FileVersion
102.0.1245.39
InternalName
999.exe
LegalCopyright
Copyright Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
999.exe
ProductName
Microsoft Edge
ProductVersion
102.0.1245.39
Assembly Version
102.0.1245.39
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan IL:Trojan.MSILZilla.20681
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.20681
K7GW Clean
Cybereason malicious.19c2bd
BitDefenderTheta Gen:NN.ZemsilF.34742.em0@a0eMXLf
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MEW
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware IL:Trojan.MSILZilla.20681
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.lh
SentinelOne Static AI - Malicious PE
Trapmine Clean
FireEye Generic.mg.05f3c1eab22d9fe9
Emsisoft IL:Trojan.MSILZilla.20681 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData IL:Trojan.MSILZilla.20681
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1248320
Kingsoft Clean
Gridinsoft Clean
Arcabit IL:Trojan.MSILZilla.D50C9
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.ZAT!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!05F3C1EAB22D
MAX malware (ai score=87)
VBA32 Clean
Malwarebytes Clean
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.MES!tr.dldr
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.