Static | ZeroBOX

PE Compile Time

2083-09-28 23:26:14

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001f84 0x00002000 5.27567188964
.rsrc 0x00004000 0x0000ab68 0x0000ac00 7.19001754431
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00007c48 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c48 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c48 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00007c48 0x00006834 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0000e48c 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000e4dc 0x0000048a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e978 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Microsoft.Win32
<Module>
messageID
System.IO
System.Data
DownloadData
mscorlib
Synchronized
GetMethod
get_Instance
defaultInstance
CompressionMode
DynamicInvoke
DataTable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
IsInRole
WindowsBuiltInRole
Console
WriteLine
LocalMachine
GetType
get_Culture
set_Culture
resourceCulture
InternalDataCollectionBase
ApplicationSettingsBase
Dispose
CreateDelegate
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetValue
Qvfaes.exe
System.Runtime.Versioning
ToString
Gggfzph
RegistryKeyPermissionCheck
System.Security.Principal
WindowsPrincipal
System.ComponentModel
System.Data.Sql
BufferedStream
GZipStream
MemoryStream
Program
get_Item
System
resourceMan
System.IO.Compression
System.Configuration
System.Globalization
Action
System.Reflection
ManagementObjectCollection
DataRowCollection
System.Data.Common
CopyTo
MethodInfo
CultureInfo
LogSystemInfo
LogOSVersionInfo
LogUserInfo
LogSQLServerInfo
getProcessorInfo
buffer
get_ResourceManager
ManagementObjectSearcher
System.CodeDom.Compiler
SysInfoHelper
IEnumerator
DbDataSourceEnumerator
SqlDataSourceEnumerator
ManagementObjectEnumerator
GetEnumerator
.cctor
Ntwjtfsuopur
System.Diagnostics
Qvfaes
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetDataSources
System.Resources
Gggfzph.Properties.Resources.resources
DebuggingModes
Gggfzph.Properties
Settings
System.Collections
get_Rows
Concat
ManagementBaseObject
ManagementObject
System.Net
get_Default
WebClient
System.Management
get_Current
GetCurrent
MoveNext
DataRow
ToArray
OpenSubKey
RegistryKey
get_Assembly
Registry
op_Inequality
WindowsIdentity
WrapNonExceptionThrows
Thunderbird
Mozilla Corporation
Thunderbird and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.
5Thunderbird is a Trademark of The Mozilla Foundation.
$e32e3217-4bf0-4330-ae3b-70c96104cc20
91.10.0.8180
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
o+-pj**<
T>vzVLM
IDATx^
*)&%L.)M
`x]U7g
3=AE"
?1{5$e
{g'dd-
F(JiQNU@p
"PqxM4
Ioay0
M`)de-
>B;o(u>
a'IL m
.,[UWt
!5EF (+
^f# Y4
o]Xj~(H?
8L <fB
f.OKQ9
}E~o4*
|#2vlTH
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
https://www.uplooder.net/img/image/31/ca8d9d906f76a6c950c1f4a1ecdbbebc/Qvfaes-Hkxzfaej.png
Jrgztnjylnjb.Mzzpihxuo
Mhpeebsfxtn
select * from Win32_OperatingSystem
Caption
OS Name :
OSArchitecture
Architecture :
CSDVersion
Service Pack :
--------------Operating System Info--------------
Displaying Processor Name....
Hardware\Description\System\CentralProcessor\0
ProcessorNameString
Processor
----------------------------SQL Source----------------------------
Server Name:
ServerName
Instance Name:
InstanceName
Is Clustered:
IsClustered
Version:
Version
------------------------------------------------------------------
----------------------------User Information----------------------------
User Name: WindowsIdentity.GetCurrent().Name
Is Administrator? :
--------------------------------------------------------------------------
Gggfzph.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Thunderbird
CompanyName
Mozilla Corporation
FileDescription
Thunderbird
FileVersion
91.10.0.8180
InternalName
Qvfaes.exe
LegalCopyright
Thunderbird and Mozilla Developers, according to the MPL 1.1/GPL 2.0/LGPL 2.1 licenses, as applicable.
LegalTrademarks
Thunderbird is a Trademark of The Mozilla Foundation.
OriginalFilename
Qvfaes.exe
ProductName
Thunderbird
ProductVersion
91.10.0.8180
Assembly Version
91.10.0.8180
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (moderate confidence)
Cynet Malicious (score: 99)
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!1DF7FC81095A
Malwarebytes MachineLearning/Anomalous.94%
VIPRE Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec MSIL.Downloader!gen7
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Generic/MSIL@AI.100 (RDM.MSIL:/Cn87/r6JdcZH0GrIY1Swg)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.qh
Trapmine Clean
Sophos Mal/Generic-S
Ikarus Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1249960
Kingsoft Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34786.dm0@a4NDfqo
AVG MalwareX-gen [Trj]
Avast MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.