Static | ZeroBOX

PE Compile Time

2022-06-24 16:11:35

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000014a4 0x00001600 5.315083979
.rsrc 0x00004000 0x0000de00 0x0000de00 7.26314130682
.reloc 0x00012000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x000116b4 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00011710 0x0000031e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00011a40 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
IEnumerable`1
List`1
<Module>
System.IO
mscorlib
System.Collections.Generic
OpenRead
Synchronized
CompressionMode
DynamicInvoke
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
get_FullName
DateTime
SecurityProtocolType
System.Core
ApplicationSettingsBase
Dispose
CreateDelegate
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
razi.exe
System.Runtime.Versioning
ToString
get_xpfhj
get_xpfhk
set_xpfhk
System.ComponentModel
set_SecurityProtocol
BufferedStream
GZipStream
MemoryStream
System
System.IO.Compression
System.Configuration
System.Globalization
Action
System.Reflection
CopyTo
MethodInfo
CultureInfo
get_vswyo
System.Linq
ResourceManager
ServicePointManager
System.CodeDom.Compiler
GetEnumerator
.cctor
System.Diagnostics
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Mpfzu.Properties.Resources.resources
DebuggingModes
Mpfzu.Properties
GetTypes
Settings
System.Windows.Forms
Object
System.Net
DialogResult
WebClient
get_Current
ToList
MoveNext
get_UtcNow
MessageBox
ToArray
get_Assembly
op_Equality
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
WrapNonExceptionThrows
ICQSetup
$652e4b51-02bd-40f8-b705-c337801f7a30
10.0.45564.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
U1g@DI
~80uyy
v{aaavv
NwvvRJG
3gvtt,Z
5Mklllhh
+///;;
+/<h &
X$e6:D
koookk
jBHNNN~~>cL
mV/S5DR
b6;eY;
YQdUM#
lr`*bD(
<B('7?77
:;;[ZZ@
U5ZLi*
>uO}g[
PGGGCC
]9VUQ0
!r:=`@
nK$b;w
3z<PJc
b1B0!$
T*UYYi
TRN&S]]
Emlhnj
RZ___SS
sLfQQe
+*c<'j
0B"BLS
4(I5M;
!JUUAH
1J1cXQ(P
\rikkkyy
{?84 0
@sssII
i:M5777
{*,MU'M:
(vuuuvv
M&Svv64
zTxKJK
_SSSSS
Pccc{{;
{j5M6:
f_`KRVVVII
&JieeeII
?~|EEEAA
]]]yyy
X,999P
*..njj
***TM#
D:::t"
fsnnnEEEnnn
W]uUKK
V+B(//
h4RJ}>_~~~qq1
cYYYPD
DL&Saa
C^^^^^
e]]]AA
RGGGkkk<
X,V[[{
~}{{{QQ
caa!0aa]M
BHkkk,
;::rss3
+.....
Q `CpN
_1YQrrr
Y^/,H>
:th^^
;::`y8
cnmmM&
Ggr`L&
"@=D)h
lF=x?P
5MSUMUuF"UUM
H$RZZj
Nuuu}}
F[gd477777
^QJ;::
U{p0x'
O?]\\\^^
UUU_|1
Css3L<
#EU***@
BYYYnn.0
.TSSSSSc
JaUUUU
[~~~uu
9UU].'
Z~~>PA
]]]_-^
JKKsrrR
IU5X2w
ijKKsf7
H{{;LZn
QJEIjmm
mkCcsZV
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
IS_y\yy
http://172.245.26.174/razi_Yciohtjb.jpg
Ywmgazdnhd.Gfrdibynokdcgbykdtwkep
Mpfzu.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ICQSetup
CompanyName
FileDescription
ICQSetup
FileVersion
10.0.45564.0
InternalName
razi.exe
LegalCopyright
LegalTrademarks
OriginalFilename
razi.exe
ProductName
ICQSetup
ProductVersion
10.0.45564.0
Assembly Version
10.0.45564.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.MSIL.Seraph.a!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.6021e8882e14bf7f
CAT-QuickHeal Clean
McAfee Artemis!6021E8882E14
Cylance Unsafe
Sangfor Downloader.Msil.Agent.Vszp
K7AntiVirus Trojan-Downloader ( 00594b461 )
BitDefender Clean
K7GW Trojan-Downloader ( 00594b461 )
Cybereason Clean
BitDefenderTheta Gen:NN.ZemsilF.34742.dm0@ay5Idai
VirIT Clean
Cyren W32/MSIL_Kryptik.GRB.gen!Eldorado
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MIC
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DFO22
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Trojan:MSIL/Generic.582248ed
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1232055
MAX malware (ai score=99)
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes MachineLearning/Anomalous.94%
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.