Static | ZeroBOX

PE Compile Time

2022-06-24 02:34:38

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001b60 0x00001c00 5.64806171697
.rsrc 0x00004000 0x0000dc16 0x0000de00 7.26424168393
.reloc 0x00012000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000855c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000855c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000855c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000855c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x0000855c 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x0001163a 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000116c2 0x0000032e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00011a2c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
p+J+O+P+U
+P+Qo/
+&+++0+5+6
v4.0.30319
#Strings
Afsjkfstm.exe
Afsjkfstm
<Module>
mscorlib
Object
System
System.Windows.Forms
Settings
Rwelzy.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
IContainer
System.ComponentModel
Assembly
System.Reflection
ResourceManager
System.Resources
CultureInfo
System.Globalization
MemoryStream
System.IO
HttpWebResponse
System.Net
HttpWebRequest
.cctor
Culture
Default
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
EditorBrowsableState
.resources
Container
ContainerControl
set_AutoScaleMode
AutoScaleMode
System.Drawing
set_ClientSize
Control
set_Text
ServicePointManager
set_SecurityProtocol
SecurityProtocolType
WebResponse
GetResponseStream
Stream
ToArray
IDisposable
String
get_DefaultBinder
Binder
InvokeMember
BindingFlags
Console
WriteLine
get_Text
GetType
System.Net.NetworkInformation
PingReply
PingOptions
Random
NextBytes
WebRequest
GetResponse
Thread
System.Threading
HashAlgorithm
System.Security.Cryptography
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
Encoding
System.Text
get_UTF8
GetBytes
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
Create
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
ICQSetup
$041b3c24-186c-4edb-b23d-9000f04899af
10.0.45564.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
U1g@DI
~80uyy
v{aaavv
NwvvRJG
3gvtt,Z
5Mklllhh
+///;;
+/<h &
X$e6:D
koookk
jBHNNN~~>cL
mV/S5DR
b6;eY;
YQdUM#
lr`*bD(
<B('7?77
:;;[ZZ@
U5ZLi*
>uO}g[
PGGGCC
]9VUQ0
!r:=`@
nK$b;w
3z<PJc
b1B0!$
T*UYYi
TRN&S]]
Emlhnj
RZ___SS
sLfQQe
+*c<'j
0B"BLS
4(I5M;
!JUUAH
1J1cXQ(P
\rikkkyy
{?84 0
@sssII
i:M5777
{*,MU'M:
(vuuuvv
M&Svv64
zTxKJK
_SSSSS
Pccc{{;
{j5M6:
f_`KRVVVII
&JieeeII
?~|EEEAA
]]]yyy
X,999P
*..njj
***TM#
D:::t"
fsnnnEEEnnn
W]uUKK
V+B(//
h4RJ}>_~~~qq1
cYYYPD
DL&Saa
C^^^^^
e]]]AA
RGGGkkk<
X,V[[{
~}{{{QQ
caa!0aa]M
BHkkk,
;::rss3
+.....
Q `CpN
_1YQrrr
Y^/,H>
:th^^
;::`y8
cnmmM&
Ggr`L&
"@=D)h
lF=x?P
5MSUMUuF"UUM
H$RZZj
Nuuu}}
F[gd477777
^QJ;::
U{p0x'
O?]\\\^^
UUU_|1
Css3L<
#EU***@
BYYYnn.0
.TSSSSSc
JaUUUU
[~~~uu
9UU].'
Z~~>PA
]]]_-^
JKKsrrR
IU5X2w
ijKKsf7
H{{;LZn
QJEIjmm
mkCcsZV
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Aijalirbayan.Wsaiigqbxcbnwkcig
http://172.245.26.174/Afsjkfstm_Nqikoyek.bmp
Ioghirxmdpsprostnrfkwv
Wyqrlmqbgenehpnzwhuyzjgw
stackoverflow.com
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ICQSetup
CompanyName
FileDescription
ICQSetup
FileVersion
10.0.45564.0
InternalName
Afsjkfstm.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Afsjkfstm.exe
ProductName
ICQSetup
ProductVersion
10.0.45564.0
Assembly Version
10.0.45564.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.bc3f15241f7b63ed
CAT-QuickHeal Clean
McAfee Artemis!BC3F15241F7B
Malwarebytes Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.77e612
Baidu Clean
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.LCT
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:MSIL/Generic.2aadf336
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Msil.Trojan-downloader.Agent.Pgdb
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
Emsisoft Clean
Ikarus Trojan.MSIL.Krypt
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
GData Clean
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DFN22
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34742.dm0@aCweGXg
AVG DropperX-gen [Drp]
Avast DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.