Static | ZeroBOX

PE Compile Time

2022-11-01 08:34:51

PDB Path

XCXCBBDFDHHD.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000e5d4 0x0000e600 5.9246386037
.rsrc 0x00012000 0x0002a2e6 0x0002a400 4.51431913565
.reloc 0x0003e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003b8d4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0003bd3c 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003bdc0 0x0000033c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003c0fc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Z )}S$a8
Z tTg}a8
4Z i[Q`a8
018+%&
)iVS
,DK%&8Q
(rZ L~
!;5Z r
s(Z ]Mtua8
_bj2
_bY*
aP%&8B
(Z ?bkea8
;:tB%+
f:Z ]3
4=]fZ
Z 1.7ja8
Z ?m9{a8
Z [!4@a8
Z_bX
%`X?Z
:HQnZ
Y_cX*
E!tZ u
JX&Q ?
H?oR%&8K
FakZa8
:_1u
P;'a8/
G0a86
xtTu%+
wW5>%+
@)#J%&
,+od%&
-j%&8g
H{%&8N
;!-5%+
CHZa8l
Z &z]ga8#
6<wt%&8(
Z AZEa8%
:'Yz%+
LQ%&8A
G{va8#
v4.0.30319
#Strings
XCXCBBDFDHHD$
mYaLnc'J_4kKoi+2ioB'>0<^0
UInt32
ToInt32
c00d9a2ae2456b52e9d40d8e138292982
ccbb3937f02f0ca2f7bca210c1f4eaca2
c552cd917c580b1405430250845e4a9b3
c680b9036b0a899875a10e922fcfcb244
cd20365536cd185241beeb68ae0d3da54
c66d97aeae628603c8ab3b764b791af57
c1616e3a6d40b86a7cf988618c97f8e08
get_UTF8
c49ad79e7f7b9da94586445c9ec726ff8
c94ce2391c1592bef3cf60d6d1c2105c9
<Module>
XCXCBBDFDHHD
System.IO
set_IV
c243b1773522677ac282548669a1daa8b
mscorlib
cc0b7a61df39cce0d170b62aa7135e98c
get_CurrentThread
thread
get_IsAttached
Synchronized
ReadToEnd
set_IsBackground
set_Method
GetMethod
distance
CreateInstance
CompressionMode
get_Unicode
Invoke
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
get_FullName
ValueType
SecurityProtocolType
GetType
GetElementType
get_Culture
set_Culture
MethodBase
ApplicationSettingsBase
WebResponse
GetResponse
Reverse
Create
EditorBrowsableState
posState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
XCXCBBDFDHHD.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
windowSize
dictionarySize
IndexOf
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
System.ComponentModel
set_SecurityProtocol
GetManifestResourceStream
GetResponseStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
AppDomain
get_CurrentDomain
System.IO.Compression
System.Configuration
System.Globalization
System.Reflection
get_Position
set_Position
Intern
MethodInfo
CultureInfo
InvokeMember
StreamReader
TextReader
DESCryptoServiceProvider
sender
Binder
rangeDecoder
Buffer
get_ResourceManager
ServicePointManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
BitConverter
.cctor
Monitor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
A.c49ad79e7f7b9da94586445c9ec726ff8.resources
DebuggingModes
XCXCBBDFDHHD.Properties
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
Settings
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
numTotalBits
numPosBits
numPrevBits
Object
System.Net
Default
Environment
ParameterizedThreadStart
Convert
FailFast
HttpWebRequest
System.Text
IkqWhEUOUipsZErTbrOLHylyIbMu
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
op_Equality
Confuser.Core 1.6.0+447341964f
XCXCBBDFDHHD
Copyright
2022
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
1.0.0.0
$9ce5c0f1-6a66-4692-bc25-818282d7e98e
WrapNonExceptionThrows
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
XCXCBBDFDHHD.pdb
_CorExeMain
mscoree.dll
@wuM{?
Rw@x_te
GoF1#7
(Jv*@q
D'g5Mg
A+@m0LM0B}
TSOm0L$
Kkn^|yQm
'wm%"O
RW-xOW:
-+n `Y
_/xsN7'q
.rQhtx
lWm_2k1
.TCm0Bm0B](
|8io}`
&e(Rw
@te,@vn
1M';4)
Dr3Cq
Cr@CrpDr
Dr!CrNCr
Cr.Cr[Dr
Cr;CrjDr
CrICryCr
Dr)DrVDr
Dr6DreDr
CrDCrsDr
Dr$DrQDr
Dr1Dr_Dr
Dr?DrmDr
Dr*DrYDr
DrDrLDr|Dr
Dr>DrlDr
Dr0Cr^Dr
Cr$CrQDr
DrCDrrDr
Dr6DrdDr
Dr)DrVDr
DrHDrxDr
Cr;CriDr
Cr.DrZDr
Dr!DrNDr~Dr
ACrnDr
Cr2Cr\Cq
Cr;Cr
DrHDryCq
Cr6Cr
*DrSDr
DrnCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
DrwCq
Dr?DrpDr
3DraDr
DrCCr
Dr9DreDr
CrHCr
Dr=DrjCr
Cr6DreCq
DCrsCr
Cr&CrQCr
Dr/Dr`Cr
?CroDr
DrLDr|Cr
.DrZCr
Dr-Cq
Dr1DrcDr
(CrSCr
DrEDruDr
Dr8DrhDr
+CrYCr
DrDrJDr|Dr
CrKCr{Cr
Cr)CrZCr
Dr8CrhCr
CrFCrvDr
Dr$DrUDr
DraDr
Dr2DrbDr
Cr#CrTCr
DrFDrvDr
Dr7DrgDr
Cr)CrZCr
DrKCq
Cr+Cq
HCrxCr
Cr&CrVCr
Dr4Cr
*DrcCr
Dr%CrTCr
Dr8Cr
Dr*DrZCq
CrICrzCp
Cr(CrXCr
Dr6CrfCr
DrVDr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
Dr|Dr
DreDr
Dr%DrUCr
DrGDrwDr
Cr9DrhDr
>DrnCr
#CrUCr
DrGCr
GCrwCr
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
220511000000Z
330810235959Z0j1
Manchester1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #30
/l}.aQ
https://sectigo.com/CPS0
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
210812000000Z
230810235959Z0
Private Organization1
91320192MA1YED3N921
#Aicho Software Technology Co., LTD.1,0*
#Aicho Software Technology Co., LTD.0
-91320192MA1YED3N920
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Ed5Zs*
w3hdQ{
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
fS`A4^
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
220803135605Z0?
-DAKIRBY309-SIMPLY-STYLED-MICROSOFT-EXCEL-2013
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
XCXCBBDFDHHD
FileVersion
1.0.0.0
InternalName
XCXCBBDFDHHD.exe
LegalCopyright
Copyright
2022
LegalTrademarks
OriginalFilename
XCXCBBDFDHHD.exe
ProductName
XCXCBBDFDHHD
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Downloader.Msil.Agent.Vvpn
K7AntiVirus Trojan ( 005944cf1 )
BitDefender Trojan.Generic.32008140
K7GW Trojan ( 005944cf1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.IHD.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.NXZ
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.Generic.32008140
Tencent Win32.Trojan.FalseSign.Hkjl
Ad-Aware Trojan.GenericKD.63303617
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Generic.mg.d7be2aadb342fee7
Emsisoft Trojan.Generic.32008140 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1252470
MAX malware (ai score=99)
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Win32.Trojan.Agent.L9KLZK
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5289838
Acronis Clean
McAfee Artemis!D7BE2AADB342
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CK122
Rising Spyware.Noon!8.E7C9 (CLOUD)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
Fortinet MSIL/Agent.MNN!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34754.om1@aSBoRpk
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
No IRMA results available.