Static | ZeroBOX

PE Compile Time

2022-11-02 08:48:22

PDB Path

VNCXVNXMCGJKDF.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00004f54 0x00005000 5.87859418015
.rsrc 0x00008000 0x00001652 0x00001800 5.00611924732
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000091c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000091c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00009630 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%&N@)
v4.0.30319
#Strings
VNCXVNXMCGJKDF
AssemblyProductAttribute
System.Reflection
mscorlib
System
String
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GuidAttribute
System.Runtime.InteropServices
AssemblyTrademarkAttribute
ComVisibleAttribute
Boolean
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
AssemblyTitleAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
VNCXVNXMCGJKDF.exe
<Module>
QRWoMg5pcQp0pY0xuF
jSHKr2q2fjujyqxMIf
Object
cZeaRdSgjAPj9JgZSw
zgnEBp874KpvtiO62A
qKy00VLOefx8WeAmv5
O8eL9LGs6AenQy9evT
Attribute
Settings
VNCXVNXMCGJKDF.Properties
ApplicationSettingsBase
System.Configuration
HNyWvuaZn82EXS3ANk
waGxqGl70LYvQGGAMx
J3jfy3oWZjCuapB1oc
h5RON6CFuWEpYJfd1W
fvWs6LZhvcvEEopsUQ
ltqd7wbEJ0KG0DERK7
eww0fw32rB4R3moTMl
yZAHpTtXe6vGP99hKR
hBfljmdTM9tao4CyV1
cTpYYdsucS6Vq202j9
MulticastDelegate
LAkUB7jqFeSmUQTFVX
YqaPgSYkkiw58h4dxI
cBFctErvCVcxpl2jJp
INsJAAEpfo8ATvti6k
RjHIitgL47o3JAOpTZ
FrZGwBmoLkAhRgqX3m
Oju8jyqxM
ResourceManager
System.Resources
BfqLZeaRd
CultureInfo
System.Globalization
get_ResourceManager
get_Assembly
Assembly
QRW5oMgpc
Xp0qpY0xu
PhiESWJYS23Nllwk9n
aBiDnPjcIaPbaD1xw2
aGtrVcG1AcHhLDNF8h
KNhQETEAdrns6HI0m0
XQZFlKv0b7UsPWIbSe
RuntimeTypeHandle
GetTypeFromHandle
xZSSHKr22
ep0xgElTtCfbBVXBkp
defaultInstance
.cctor
get_Default
bVy5ZL1PIdlsKbSi4V
PPZYeHiuKFuiwhyarM
dKLcMO7x0ojCoOsok2
hYmLPfL7seI8OfXU9P
SettingsBase
Synchronized
Default
sjAGPj9Jg
HttpWebRequest
System.Net
WebResponse
StreamReader
System.IO
TextReader
ReadToEnd
ServicePointManager
set_SecurityProtocol
SecurityProtocolType
WebRequest
GetResponse
GetResponseStream
Stream
Encoding
System.Text
get_UTF8
GetType
InvokeMember
BindingFlags
Binder
Convert
FromBase64String
set_Method
Create
jSwaegnEB
jWiwWgQawguvbta114
qeljX6xfFKw1rqP7HK
xnG9Dck4j9UKaDvB4R
MjBNIHUP1TjlcRK6eb
vRggVsNYKyh1xBxVA6
ieeXr7OAHl8i5QVgXg
jAHBf9KUxYk4tos1sG
d40OvdpVN0W5C8WfS5
tuaEGnq2alW07Gw4SW
OmmQMdSvmYufTLkp05
R62oArKy0
LVOCefx8W
w74lKpvti
W6nUA22Rn3vb7LHZOD
YRaLlwfUEYWhAJj8u8
RU0P01MDKu28SJOxfn
GetString
WmRcfP5GpJikqoQnEG
GetExecutingAssembly
sVgKQjcCkLeMYl3DZN
GetManifestResourceStream
ogenDdDwS5oghDoe45
voufmo0UcdRW4A7WJZ
raeZSGm0ursdMPtil9
ksjgxCyyUNsBorepNJ
m7eZ9BgKfJkBKMQ161
get_Unicode
Y3Q8gcZEEtwRIuPpLr
Intern
gGxsqG70L
pvQjGGAMx
J3jYfy3WZ
oCurapB1o
MemoryStream
Ro5ERON6F
DWEgpYJfd
zAmZv5P8e
e9Lbs6Aen
Wy93evTXN
JWvtuZn82
rXSd3ANkF
UInt16
DESCryptoServiceProvider
System.Security.Cryptography
ICryptoTransform
DeflateStream
System.IO.Compression
CompressionMode
Cjw3yL9R4DYrlEjrUe
iHVECotDZyIeIoPGip
T65RhMoDmshJBl4sQT
G4UqBcwK4dFxypHYTK
get_FullName
tbswTeVdgGcWmhtIaZ
IndexOf
Rdyj8ZTdv2hpOya5xV
Substring
XjPBnpu89lEkkPhXP4
DUmm2PCCVYJ5vXaTMu
get_Chars
DdSUlO8SjZnOoseOMC
NumberStyles
KsZUtengacgI5NYHSa
BitConverter
GetBytes
Q5NMYVPwwBy2wH6u56
Reverse
ChaBJF6Elunnk853VD
Monitor
System.Threading
UrRFiGHqAwOtgp2qwy
mtjfeEe1Htpwhaknvs
dIGylIXGElhVrcJyPI
qDMA7BaqvaTBc0vUA6
ReadByte
c0hU5nYRZ6K3v5nquB
PkNpkbdKvNW3YPXO3r
SymmetricAlgorithm
set_IV
QwE9JURLGfj7dkDvTQ
YZw0GH3bmTdlsaY1fw
LYEQGnIqMrEpTX6wZu
set_Key
f0lUBY4V0yfrmrTCCt
get_Length
lcRJTjhoux8fJJTdnl
set_Capacity
I3R11kzN7O2VOrZuKu
set_Position
MA1w3ZBF2dcYtu307wv
CreateDecryptor
nPSu1YBBLJicoBPcS5j
get_InputBlockSize
IwdH8wBWrHOom4BZnTB
get_OutputBlockSize
EDGQZ2BrYhN5I8mClch
get_Position
WAZH4YBbvChR6vVDxyM
TransformBlock
wJqAvtBj9Zx4bk2CbXf
C6AlN3BGCM4csSSTMdi
TransformFinalBlock
V0Fye4BJLIkock5vouv
ToArray
Giwk58h4d
PWGmvWs6L
UInt32
SetLastError
kernel32.dll
YvcnvEEop
IntPtr
CloseHandle
nUQw3tqd7
OpenProcess
uEJi0KG0D
GetCurrentProcessId
qRKp7Lww0
LoadLibrary
Nw2FrB4R3
GetProcAddress
toTHMlBZA
xpTBXe6vG
O99ehKRoB
NljKmTM9t
go4ICyV1S
QpYAYducS
TVqu202j9
StringBuilder
GetClassName
user32.dll
LAkxUB7qF
ToString
zSmUUQTFV
Exception
GhqRaPgSk
O5TaUoBAl0Nl4NOSX4C
qpXoxWBspQ6fBCpA36l
fkqmXSBlbTBErd7oTqj
rkA6NjBi9D6puZykrFb
Compare
fKRZypBETBopf5SxD3S
ftl0jrBvsFsPqWpBCFp
wALtCPB7Wi0EGLm7xD0
get_Capacity
IZOLxAB1RIQ1Vsk9uLm
zF4d0oBL49btJkMMYOd
Format
kNaEpiBQaiN3nScr6Ri
Debugger
get_IsAttached
KiGBf6BxcZSKRjgucuT
Ml1tRnBk8VxA3qTvCmw
op_Inequality
Pq1EqIBULsbfwt4CVb1
lParam
DIqXBFctE
YCVDcxpl2
pJpVVNsJA
Cpfyo8ATv
mi6JkOjHI
utL047o3J
bIROOnBK7H4uYepyN12
Invoke
ProcessHandle
ProcessInformationClass
ProcessInformation
ProcessInformationLength
ReturnLength
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
debugPort
lpOutputString
hProcess
pbDebuggerPresent
lpEnumFunc
zgnEBp874KpvtiO62A.cZeaRdSgjAPj9JgZSw.resources
VNCXVNXMCGJKDF$
DebuggerNonUserCodeAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
STAThreadAttribute
VNCXVNXMCGJKDF
Copyright
2022
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5)
$b176a4fe-8c6f-4ca8-8b42-d77067acf7ab
WrapNonExceptionThrows
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
X;,T<)=
VNCXVNXMCGJKDF.pdb
_CorExeMain
mscoree.dll
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
220511000000Z
330810235959Z0j1
Manchester1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #30
/l}.aQ
https://sectigo.com/CPS0
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
210812000000Z
230810235959Z0
Private Organization1
91320192MA1YED3N921
#Aicho Software Technology Co., LTD.1,0*
#Aicho Software Technology Co., LTD.0
-91320192MA1YED3N920
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Ed5Zs*
w3hdQ{
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
fS`A4^
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
220803135605Z0?
.R;.S;.K;.[
#.;N.C
.+;.3AI
Vk5DWFZOWE1DR0pLREYk
PublicKeyToken=
publickeytoken=
&GRAPHICRATING-KOLORIA-FILE-PDF-ACROBAT
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
ClamAV Clean
FireEye Generic.mg.313850abca30e4b2
CAT-QuickHeal Clean
McAfee Artemis!313850ABCA30
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Trojan ( 005944cf1 )
K7AntiVirus Trojan ( 005944cf1 )
Arcabit Clean
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Agent.DSJ.gen!Eldorado
Symantec MSIL.Downloader!gen7
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Clean
Paloalto generic.ml
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Andromeda.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoaderNET.447
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Andromeda.gen
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34754.cmX@aWUyCZo
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet MSIL/Agent.MNN!tr.dldr
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.9d8fa0
Avast Win32:DropperX-gen [Drp]
No IRMA results available.