Static | ZeroBOX

PE Compile Time

2022-08-03 06:09:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000012d4 0x00001400 5.34424314722
.rsrc 0x00004000 0x0000de00 0x0000de00 7.26277756042
.reloc 0x00012000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_ICON 0x00008600 0x000090a2 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGB, non-interlaced
RT_GROUP_ICON 0x000116b4 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00011710 0x00000316 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00011a38 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<>9__0_0
List`1
<Module>
get_ASCII
DownloadData
mscorlib
get_trtb
System.Collections.Generic
get_oslc
get_Id
Thread
Synchronized
get_osld
set_osld
GetMethod
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
DockStyle
get_ProcessName
GetType
MethodBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
SetApartmentState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
66.exe
get_Tag
set_Tag
System.Threading
Encoding
System.Runtime.Versioning
ToString
get_Length
set_Dock
System.ComponentModel
Control
System
Application
System.Configuration
System.Globalization
System.Reflection
MethodInfo
CultureInfo
ResourceManager
System.CodeDom.Compiler
WebBrowser
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Tcvlys.Properties.Resources.resources
DebuggingModes
Tcvlys.Properties
GetBytes
Settings
System.Windows.Forms
GetCurrentProcess
Object
System.Net
WebClient
Component
ThreadStart
System.Text
ToArray
get_Assembly
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
WrapNonExceptionThrows
ICQSetup
$7c41b429-2caf-47ca-b9df-4af7a180c411
10.0.41010.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
U1g@DI
~80uyy
v{aaavv
NwvvRJG
3gvtt,Z
5Mklllhh
+///;;
+/<h &
X$e6:D
koookk
jBHNNN~~>cL
mV/S5DR
b6;eY;
YQdUM#
lr`*bD(
<B('7?77
:;;[ZZ@
U5ZLi*
>uO}g[
PGGGCC
]9VUQ0
!r:=`@
nK$b;w
3z<PJc
b1B0!$
T*UYYi
TRN&S]]
Emlhnj
RZ___SS
sLfQQe
+*c<'j
0B"BLS
4(I5M;
!JUUAH
1J1cXQ(P
\rikkkyy
{?84 0
@sssII
i:M5777
{*,MU'M:
(vuuuvv
M&Svv64
zTxKJK
_SSSSS
Pccc{{;
{j5M6:
f_`KRVVVII
&JieeeII
?~|EEEAA
]]]yyy
X,999P
*..njj
***TM#
D:::t"
fsnnnEEEnnn
W]uUKK
V+B(//
h4RJ}>_~~~qq1
cYYYPD
DL&Saa
C^^^^^
e]]]AA
RGGGkkk<
X,V[[{
~}{{{QQ
caa!0aa]M
BHkkk,
;::rss3
+.....
Q `CpN
_1YQrrr
Y^/,H>
:th^^
;::`y8
cnmmM&
Ggr`L&
"@=D)h
lF=x?P
5MSUMUuF"UUM
H$RZZj
Nuuu}}
F[gd477777
^QJ;::
U{p0x'
O?]\\\^^
UUU_|1
Css3L<
#EU***@
BYYYnn.0
.TSSSSSc
JaUUUU
[~~~uu
9UU].'
Z~~>PA
]]]_-^
JKKsrrR
IU5X2w
ijKKsf7
H{{;LZn
QJEIjmm
mkCcsZV
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Xropnpduvejrv.Hvbmspeakvd
Agpotsltavekrydnexo
http://20.48.118.182/66.bmp
Xjjfmblepfixsqfathrgz
Tcvlys.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ICQSetup
CompanyName
FileDescription
ICQSetup
FileVersion
10.0.41010.0
InternalName
66.exe
LegalCopyright
LegalTrademarks
OriginalFilename
66.exe
ProductName
ICQSetup
ProductVersion
10.0.41010.0
Assembly Version
10.0.41010.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Downloader.MSIL
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (D)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34582.dm0@aeBlsIi
VirIT Clean
Cyren W32/MSIL_Kryptik.HIU.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan-Downloader.MSIL.PsDownload.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Generic/MSIL@AI.97 (RDM.MSIL:D3eHH1Oq5/aAC74IA+D+JA)
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Clean
APEX Malicious
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1221675
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
ViRobot Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!EE71C964FF63
TACHYON Clean
VBA32 Clean
Ikarus Trojan.MSIL.Inject
Panda Clean
Zoner Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
Cybereason Clean
Avast Clean
No IRMA results available.