Static | ZeroBOX

PE Compile Time

2022-07-19 04:32:39

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000429c8 0x00042a00 7.99333820782
.rsrc 0x00046000 0x0005ad40 0x0005ae00 3.09828133865
.reloc 0x000a2000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000a0210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000a06b4 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000a074a 0x00000406 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000a0b8c 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-%&+/+0+1t
+(+)+*
-%&+/+0+1t
+(+)+*
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
,'&+4+5+6t
-'&+4+5+6t
-,&&+;+<
&&+-+.
+*+/u+
5eU\//
jI"/-[
ikb(ue
`^lO7B#
~mSj6c
3ga\PS
>I:=5pS"E
Gqm:Mj
4'Yh$U
,y|v59<
>U9q2d
c7N0b?7
9tR.7m
zgw:9G$
;kiu*=>
=4/M+4
!o|vNi
!%bzB
~lAW!3
9j+Vy
z{ (j%
}k<Sm8
IevH@$;
DGgv;tK/
`3(FKem
uwl:~7)
IEJQU@O
nDsAE8
3:3UX7p
)>\ZGY
pIzcitW
<'ePZ*}
.rQkSj
HZgrO6l
V0+3v;
e6:lTT*
cTm=&O4E3(lZe
.;=Xj2
Cb-C||
w5@8UO
G Gbd7x|
haai$}
]W?.M!
!qiOi
cd@rRH
$s,yZo
|((@:?
89)e`"psu
N53xWt0K
|.PYsXd
.Nx%>1
,05x|J
2FR7%n%
x)cnTe
f"qWRBm
mPY=bp
O2c+6u|
1gbd|~>^VG/<
$o>asx
WW~gR
K/Og8G?
g*M>[g
38>t%v
\o)qI0K
6nCGek0q
{!q#[)
PL?V[5^
\U'd4M
X&qadb?*
5q;M{|
c\tvn3
RJnlp4
%nrLS:S
m;8B>LA
eCj&AK
UJ2x!(
,K&W:R
AD30amr
3GI$j?
38ldv1q
0()9\+
ZV'qpaF3_t
`?&r7P
:!TapG
dZ$:&g
d@R@]
V4N 03
>nsK9#
D;V+sO
3X.`_2
Tc;G8S
9aL[\\VN
0)KYv5
1#@m6/
LH"=h(
UID~f?
2XRBJ)Qvz
%J*<ps
Tq!u\7
I+MlKcw
vw/'x~
(k/t/FE
Z'BA'+w
\aD/n=
Ha P'{
A$$OHTm
5(l!?j
s+{~#r
(Kh]P+
06Ab#+
bj#J;9
&x:r3(
.$}^9h
,p$*?q*
J-d9[!;eRc
*xIG!_
@oW%+\
`GM!p3-
B$md$S]
*,/[#?
)WOQP<
21Kz@X
Vs4WI^D
Y$KPGn
q7%Wwf
WEu<+>
$\JWNk
Rwzg3Q
z@a:T_\Q<
Xrw-R@
c"(9jF|>
l?Q6%1
M|F$rL
NOG@|=
}VvB8n0
D6CT"g
i2Z)P{q
?ClNWS
Xf9'{@
p8Nx"t
";+BV
i!PiQk
Oz?VKe
C(%nO.
=:!@th
br<MXQ52
^=k/72
>+CvC+
"^,'$~h
-91UJD
43OVP\"
"Hs_&4
\P}f8fjfVG
T7mIMg
vljN%d
pwg2R+kKG
;<0eUQ
y&8[7ltG
>DU+&tW
kWL,aO
(|TE~z
SS;q*!
rWM `(
g8YMTP3}
x2S>a~
Mo Yh2^
;xA-?0
D<cm|E
gy!FmIg
6LC~L'
Q"GHwA
JGQfUR
0"\r,,
"(h\Z,_
DQ427K
73d?^ZP
~lKb/G
)Q'+$
QR^-Vm
3a}+;;
$3O\Xgk
c^yWgg
tr\4eg
Lk8VIP
"p5_L_g&
ug>"ue
,{.e-@B
h8-N(;
&q!JBD,
OD|-l*E
pbL!Js
yCGQE@
[M~\)^
IO8N1b
C(-2Gg!Y
nNCJERP
ex,f^C\u$
:PXl@
797WX`
|{?AB5y@
sg^9d!6
>{r0Os
H~$&|`7
V;Q<eu:
H+hs"W8
sXWO:V
C<I4d)'
cWT|j
SJV'Ws
\4]sZj
7gD3F!
'[uQT7w
up0>l
VOvr0)
N|^16Pg
<\EFoP=
$!qJ0<Y?rnO
R[Q^yE
3A+|D
?d)Dc`
t@FitPy
tTE"NS^r^\
eS\U<mo
Nf`~Hf
-#qi&'c
R#<ra'
T"OJL/
K<i"[+_
:j8lC^
.4=@{ {)t
re.fd
VC/aq&
Mj$\}i
K>po+ct
>D,~2|:_
[$O)7<
IwA=+4-HHu
Brb;k~r
@&sAQw
'>QOdmV
3p@yY|
"s+2> ex
zPLco5l
@Xz8}}h
`[Mif/m
~\D3.[
QtXUB4JY
&L>W$
dsmPy3
<p!,Nh
+B|o}%
"*kqz$7"
RAa`Wj
9Y'd7K
oL:~%r
dm@3)2+
./CmCm)<
mX3scP}g
U5zm6pl
P#JZ+jT
f'j)] Mg
5R,,Np6
dFvIKI
E{IOZ~
z` =O'0^
&hlwRPk
~#},|S%
TPxJ]4{`
)rIeT>=.
QHeOe
ohYS3A
)ex^-]
nl|@zZy
x|uluc|o0J
RI5dD+
yZHR[`&
r,H$>y
'c[#0*F
>\S"sg
?#a`({
|q>[ .
G)bQAmT
p)C-N2
aOa+RY
3V!LRb@
Az:pRzx
n:N2rH
$Y}B2o
TW` os
],oneX
$gl,2S
8:4V)G
l (hH/
s{d6\a
d4lM@1Dn"
;>5QX?)(#
@IrC6ST8J
qD\}+x
={,#'"
jty}Tx3h@
1#?7$mi
+,XP+RF
JZ{75
<r<4VSU
PsvKdd
>>2"]o|9
+j\}z"
bRoE#j
p&o@L}
4lX,o/
!h%Q69
l5D$15~
s{XDVV/
=0*E((
VM$OnX
_3[++A
ifvV#D&
UY_-kH&
zji\d^m
w03}/O
'Z<B6D
T=Wd:;
]D^w`b
rl2'5[
D.*5=F
zQR!+q
q7ylBS
&<j/<^]'
=km/|j
C%qg1c'
z4H7>$
1<+.YS)
M^};$`
&7mKb[t"
bxcP:)
6mkr}v%v
X6"4.E
^TUZOt
MsSDdFH_
J(Y@+0
o:^B~#Z
YZ!e;'7
.Fn\JY
PZb@qg
{-7Z=+
gNs>f`
`U|*8@
Sz""e#b
6~cA+*P
td8x@y1v&
rf7%Jg
uez'&CuN
Z6QW(i
x#1Z~O
p.m]>)
%c{!sn
0z${HV
%)5;$B
a057;^,V
#j9kry
N6R^:)y
IS|)@x
vV6'5R
OIv=5V
>mZ}mN
u{yW4.
X55o.Pbo
5ILKOH
PNcg77
b{@k?78
fjA8O{
Vk1eZ
sbF;`;
!ia1Dq
9`M&i
y8+iRz
uL]U+<
9o<D&"
9< M|R
VT0YeA
?cQ7mcM
mT;pu/MY
X=v(|a
F)"=73)
4X'^~
?sX|Ew
R/<vB.V-:s8i
UHOT_qz
s{K(fvq
+vHCQC
\-*_A'Z2t
Y>8#i!
&B3hT>VC
S\B?wC.
K~|n_Cj
"_69Ed
8-V}Vp
o'E9w<
4Wfub
4z$nG+
p*9-f^
TS^Cb|ls
Uc-+D!
hq.j8c
)T n|A
y+k@-[
ERs">8
qb[w"W
<,Gv{h
AGHZhZ~Ia
ZN+^I3g
@RBEz@{
DjV`E|
lAAtf
|tYb6F
RL> *Nm
j~7<&gb
~B?Z1p<
tjIZAe
FI,2Z(
`i\-r)kn
%ZK#S'
vh3_ce
\bX2)5e,
xyq(=F
BjQ+UYI-
b10[u
vR'55[
~!m&em
]>.67Z
B8g+b[b
q,q"q.
q%q-q+
~b#q>q%
~L<Gl
sa-q[HY
\@\B\J
AvCMv3
MvWX?0
<+~820
NUK`'I6C5Z%)RSK
*oWPy/
0!92<E
F|+/~&0
_uuEd7e
UB/a.q
{qtj<B*R
XNtSlmw'
z15gad
}`Ln7&(I
)pBk&R
RH1B>n=
wp6fa_
i{KB|BY
Y<rSX*1
<NMmj
i<|{4?n
4_2-znC
.t;|j_
@tDW%+
D:#Dk[
/CFfNg$
=^`ck[
puz+K&IsIP
KQ8,1
a~SM(C
#,'\Cx?
%BDXB(
"\MXAXIXE
n$l"@E
0&KEye
,)slNfO
<.xTpBpZp
v4.0.30319
#Strings
Dzodhr-FREE-3.exe
Dzodhr-FREE-3
<Module>
mscorlib
ValueType
System
Object
Settings
Dbwyzr.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
EventHandler
ResourceManager
System.Resources
CultureInfo
System.Globalization
EventArgs
.cctor
AssemblyTitleAttribute
System.Reflection
AssemblyFileVersionAttribute
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
System.Core
ExtensionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
DebuggerNonUserCodeAttribute
System.Diagnostics
GeneratedCodeAttribute
System.CodeDom.Compiler
CompilerGeneratedAttribute
STAThreadAttribute
Dbwyzr.Properties.Resources.resources
Delegate
Combine
Interlocked
System.Threading
CompareExchange
Remove
Invoke
MemoryStream
System.IO
Stream
CopyTo
IDisposable
Dispose
ToArray
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
WebClient
System.Net
DownloadData
Component
System.ComponentModel
Assembly
Action
MethodInfo
GetTypeFromHandle
RuntimeTypeHandle
CreateDelegate
DynamicInvoke
Convert
ToInt32
Console
WriteLine
GetMethod
GetType
get_Assembly
SettingsBase
Synchronized
Hostname APP
10.0.17763.1
$7765c8f2-8e63-4f95-8847-22846426aa79
Microsoft Corporation. All rights reserved.
&Microsoft
Windows
Operating System
Microsoft Corporation
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
a8"D6
001w111
555u333
667l444
111[222
111`111
DDD`HHH
444`555
+++`+++
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`,,,
---`///
667`>>?
445]222
656S444
000@000
>>>B@@@
333B444
+++B+++
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B,,,
...B000
666B99:
545<222
888&999
222'222
,,,',,,
---'-.-
---'---
---'---
---'---
---'---
---'---
---'---
---'---
---'---
---'---
,,,',,,
...'///
556%667
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
Yanaspzjo
Tpoqbxiyrwzkhez.Dionlyhdoselo
Dbwyzr.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Hostname APP
CompanyName
Microsoft Corporation
FileDescription
Hostname APP
FileVersion
10.0.17763.1
InternalName
Dzodhr-FREE-3.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Dzodhr-FREE-3.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17763.1
Assembly Version
10.0.17763.1
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.145186629cf226ca
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.6a8dc0
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MQO
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.moderate.ml.score
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34806.Nm0@aCyFhnk
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.