Static | ZeroBOX

PE Compile Time

2022-06-19 18:56:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001fb4 0x00002000 5.78125013764
.rsrc 0x00004000 0x000089fc 0x00008a00 6.14390553048
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c440 0x00000028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000c468 0x00000068 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000c4d0 0x00000378 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000c848 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
azne.exe
mscorlib
System.Core
System
Microsoft.CSharp
Xwtavu.Properties.Resources.resources
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action`2
Activator
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
IEnumerator`1
IEnumerator
System.Collections
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DebuggerNonUserCodeAttribute
System.Diagnostics
Func`2
Func`3
CultureInfo
System.Globalization
IDisposable
MemoryStream
System.IO
Stream
IntPtr
Enumerable
System.Linq
HttpWebRequest
System.Net
HttpWebResponse
SecurityProtocolType
ServicePointManager
WebRequest
WebResponse
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
ILGenerator
MethodBuilder
ModuleBuilder
OpCode
OpCodes
TypeBuilder
MemberInfo
MethodAttributes
MethodBase
MethodInfo
ParameterInfo
TypeAttributes
ResourceManager
System.Resources
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
ExtensionAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Thread
System.Threading
<Module>
Settings
Xwtavu.Properties
.cctor
Reverse
set_SecurityProtocol
GetResponseStream
ToArray
Dispose
GetDomain
Create
GetResponse
WriteLine
GetType
get_CurrentDomain
GetAssemblies
GetTypes
GetMethods
get_Name
Collect
WaitForPendingFinalizers
get_Assembly
get_FullName
DefineDynamicAssembly
DefineDynamicModule
DefineType
GetEnumerator
get_Current
GetParameters
get_ReturnType
Select
DefineMethod
GetILGenerator
MoveNext
CreateType
CreateInstance
GetTypeFromHandle
InvokeMember
Target
Invoke
Convert
get_ParameterType
Equals
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
$46822bba-2fd7-4786-8540-b0e16a623faf
-Copyright (c) 2015-2022 Exodus Movement, Inc.
Exodus
Exodus Movement Inc
WrapNonExceptionThrows
22.5.21.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
/!;5#!
/" 13"
5+*3"!
5#!T5#!
E20Wk^]
1%$+*
Q@>cA+*
6#!I6$"
E20M,!
:.-z3"
8.,G2"
4$#r4#!
F31yk^]
7#!56#"v6%"
E20yE209D60
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADD
http://phila.ac.ug/azne_Rnnztqgs.bmp
Aznsmemudsorazavoxrqkp.Sfrajwvraq
Pfwqpgrnbizduuyimuhzajbh
Xwtavu.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Exodus
CompanyName
Exodus Movement Inc
FileDescription
Exodus
FileVersion
22.5.21.0
InternalName
azne.exe
LegalCopyright
Copyright (c) 2015-2022 Exodus Movement, Inc.
LegalTrademarks
OriginalFilename
azne.exe
ProductName
Exodus
ProductVersion
22.5.21.0
Assembly Version
22.5.21.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.7f989e
Baidu Clean
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MFP
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
FireEye Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1216679
MAX malware (ai score=99)
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!9C779AFF9633
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34742.cm0@aqHdW3f
AVG BootkitX-gen [Rtk]
Avast BootkitX-gen [Rtk]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.