Static | ZeroBOX

PE Compile Time

2022-06-23 16:51:09

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001934 0x00001a00 5.546324999
.rsrc 0x00004000 0x0000dbf4 0x0000dc00 7.28643009242
.reloc 0x00012000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008630 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008630 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008630 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008630 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008630 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x000116d4 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00011720 0x0000031e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00011a40 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
kubar.exe
mscorlib
System
System.Windows.Forms
System.Drawing
Qmqzulr.Properties.Resources.resources
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
Container
System.ComponentModel
IContainer
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DebuggerNonUserCodeAttribute
System.Diagnostics
CultureInfo
System.Globalization
IDisposable
MemoryStream
System.IO
Stream
HttpWebRequest
System.Net
HttpWebResponse
System.Net.NetworkInformation
PingOptions
PingReply
SecurityProtocolType
ServicePointManager
WebRequest
WebResponse
Object
Random
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
CipherMode
System.Security.Cryptography
HashAlgorithm
ICryptoTransform
MD5CryptoServiceProvider
SymmetricAlgorithm
TripleDESCryptoServiceProvider
String
Encoding
System.Text
Thread
System.Threading
AutoScaleMode
ContainerControl
Control
<Module>
Settings
Qmqzulr.Properties
Dispose
.cctor
get_UTF8
GetBytes
ComputeHash
set_Key
set_Mode
CreateDecryptor
TransformFinalBlock
set_SecurityProtocol
GetResponseStream
ToArray
set_Text
set_AutoScaleMode
set_ClientSize
NextBytes
get_Text
GetType
get_DefaultBinder
InvokeMember
WriteLine
Create
GetResponse
GetTypeFromHandle
get_Assembly
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
$0943f44c-5c47-4876-ae9b-7c5980b56973
ICQSetup
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
10.0.45564.0
_CorExeMain
mscoree.dll
U1g@DI
~80uyy
v{aaavv
NwvvRJG
3gvtt,Z
5Mklllhh
+///;;
+/<h &
X$e6:D
koookk
jBHNNN~~>cL
mV/S5DR
b6;eY;
YQdUM#
lr`*bD(
<B('7?77
:;;[ZZ@
U5ZLi*
>uO}g[
PGGGCC
]9VUQ0
!r:=`@
nK$b;w
3z<PJc
b1B0!$
T*UYYi
TRN&S]]
Emlhnj
RZ___SS
sLfQQe
+*c<'j
0B"BLS
4(I5M;
!JUUAH
1J1cXQ(P
\rikkkyy
{?84 0
@sssII
i:M5777
{*,MU'M:
(vuuuvv
M&Svv64
zTxKJK
_SSSSS
Pccc{{;
{j5M6:
f_`KRVVVII
&JieeeII
?~|EEEAA
]]]yyy
X,999P
*..njj
***TM#
D:::t"
fsnnnEEEnnn
W]uUKK
V+B(//
h4RJ}>_~~~qq1
cYYYPD
DL&Saa
C^^^^^
e]]]AA
RGGGkkk<
X,V[[{
~}{{{QQ
caa!0aa]M
BHkkk,
;::rss3
+.....
Q `CpN
_1YQrrr
Y^/,H>
:th^^
;::`y8
cnmmM&
Ggr`L&
"@=D)h
lF=x?P
5MSUMUuF"UUM
H$RZZj
Nuuu}}
F[gd477777
^QJ;::
U{p0x'
O?]\\\^^
UUU_|1
Css3L<
#EU***@
BYYYnn.0
.TSSSSSc
JaUUUU
[~~~uu
9UU].'
Z~~>PA
]]]_-^
JKKsrrR
IU5X2w
ijKKsf7
H{{;LZn
QJEIjmm
mkCcsZV
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPAD
Cmbcuxdtogyjthcftsbvxzn
http://172.245.26.174/kubar_Uneiaqzw.png
stackoverflow.com
Ssxzpsusjxemzdvtjc.Obkyyjmczwxsrdyei
Rchekopxiiljsmpuyh
Qmqzulr.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ICQSetup
CompanyName
FileDescription
ICQSetup
FileVersion
10.0.45564.0
InternalName
kubar.exe
LegalCopyright
LegalTrademarks
OriginalFilename
kubar.exe
ProductName
ICQSetup
ProductVersion
10.0.45564.0
Assembly Version
10.0.45564.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.49231900
FireEye Generic.mg.2fc87b78d28e5590
CAT-QuickHeal Clean
McAfee Artemis!2FC87B78D28E
Cylance Unsafe
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005903241 )
BitDefender Trojan.GenericKD.49231900
K7GW Trojan-Downloader ( 005903241 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.34742.dm0@aeRZmY
VirIT Clean
Cyren W32/MSIL_Kryptik.GXH.gen!Eldorado
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MHT
Baidu Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DFN22
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/Generic.8a648a15
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Msil.Trojan-downloader.Agent.Hwdk
Ad-Aware Trojan.GenericKD.49231900
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
SentinelOne Static AI - Malicious PE
Trapmine malicious.moderate.ml.score
Emsisoft Trojan.GenericKD.49231900 (B)
APEX Malicious
GData Trojan.GenericKD.49231900
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Dropper/Win.FDIL.C5178501
Acronis suspicious
VBA32 Clean
ALYac Clean
MAX malware (ai score=88)
Malwarebytes Clean
Panda Clean
Zoner Clean
Rising Trojan.Generic/MSIL@AI.98 (RDM.MSIL:mCC0V7QgpQ0KjkRRbLlBsA)
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Clean
Fortinet MSIL/Agent.MHM!tr
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.906e45
Avast Win32:DropperX-gen [Drp]
No IRMA results available.