Static | ZeroBOX

PE Compile Time

2022-12-09 02:31:29

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000804c4 0x00080600 7.99159154642
.rsrc 0x00084000 0x000002a4 0x00000400 2.18353017492
.reloc 0x00086000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00084058 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
j1D^K`
`5{J-w9Qc
SzB-f4
wFL1%p
^bR.vc
6[Jgr~*
C])Djhm
E6B4^Z
{EpAl\
S5!-M1/O
uXXPz&n
81N8f"\y
}o{}C|1\G
08^;';
hAwTH-
P_Ff|q
G?kCb4
)ElU{J?!@+M
scZJ6C
M#X"q+
uPmfq{
L|k0|U
\?>a>
{wN^u|?
fJ|3sN
ek<n?)
F[|cnZ
27Qs5^
W? 71S
uTlZ;{=
_AwaXS
8YUm<9A
4\OAUo
5J/f%L>,2,r
j>S$'U
8s`!/
WdTy#`]
qBWu?<Zo
"(=sI[7
|YD/2x
cTTt-a
hca4]yUH
/mvJ</A
uPD)&\
^SGZGr0
{@zHL-
.oL'mW
)\'I!v
N>w8z{0
`ojjOo
T$&ebA
|jKBwM
o:|;0):
B[.K,8
4<r`ZN
:Bv1eR
5X.Oi;V
9Nl!^
c1 C0
2{]Y z
_c.Ddx
}-|G^{
@FZC0
3#^<cw
hPE:S1VP:
Vr.-5D
DnMzjB1hO
#([q3g
ZT}8K%
BTH40G
Z53M`z
N(o^d@
4ABe?*L
cc;{UR]
1G[Q-s
[gM$ha{
B'v!ib
F;4Kty
]E6FrNM'
66`Gc'K
3SPV68
*Z.p.p
7L|}r{y
3chd?]
luV3T,
7p1"Bh
hC]z9i
%jH`qe
tL!T-(
$]@{nuN
<pm.`_
HKb6VRB$JLlcg&H
*:C`$Di
Ji+FhA
;ukuk}
>[f/MO
q[SZX3
Axf[/1
'C*i7^
Cm%Mhd
\`/,2`
UoaP{H
BK"HA\Iq(?
YYnYvxFK
M{UD?C
f~QGzo
q=#1?|
Mc]EM3Tf
ks)g(h
Djf|H?J
eUtmHX
]O!d`2)
yZmH|S
UOWw|C
cEm.wB
&JDppt
PIa}iE
MK3Hkp
tHF3\+S
\l2{=9
N~rnJ.z
SOEKE_
2;NC#x
~<%(z:
1qruXO
8Ad*T)7
Fu2Y7boG
H+9RJ
`oC1O*
s-.^c
YJcv1h7
NsKDpd
EanMxy
QT+k G
^)D_tI
cFVO<'
Z':eFf
2W@o~6F
gWb5*(r
p7unVeI
}SO[cq
G&rKE@X(B
e{Usn]
\$p%N3
-+Yy[hO
LBr@vj
W\Te.4X
\&4aW(
'NDh;
=7CUJ~
\:q76} ue
.NZM$6
}jvb^v
>f=R8t
6,`is*
wLVl[(15I[
Vs*)Ywq1$
zpyiwk
D;Kko%K
2|ik9Nr
:w`WSx
Jo;sDW<
[g=*r()S
O.)#ak
f";ecM
IIF#p
oZS2 %
]2yW_K
u"L7{*@
W3;|QE
!3mD{*
ASCgl*8
!Oq%TU
yEw|^S
fogW$p
;+"Jcgo
T T)oR_
^]M%Ow
=ke\~v#
T`-.1n
Z#,IRE\
\OD*_|
=mEgeD
N]]@~
Qn8C:4
*{A.Lv
2)V6j(
!F0>'v
#P`%8wT
W(K+P&
hX[Kt
jYUD\oe
0IzY`
0~X3?]j}
D%_Am6
8')J#{
=0R^b4s)
a`j:OT8
,n(>@7
Dr @lA
f`D+EM
3ebt$!
11S`_ce!
K\39e.
C#n<WC
G#SRmig;
2:r~A^!
{,NEHu
B|jb6[
WR=)vh
;nEY S
go>DqV2s
Qc3P@W
R/Z]aa
3pkDfD
uwp.,Z
`Wi0:P
@ktBI4
6Aqn'&
eN8d0&|
G9}5'BB|OV
_lzO^,
2w`_]<Nq
$xB9aZT
*AH(WA
rho9zl
0K%>HM%yWP
tvPN_B
afx@Xn
H/tB"S%
6[>x~|-wD
Tvgn0=
xOd4%X
Su6=D9T
h6;mntI
mQe|VR
([v!Pi
(: _yn
.2VO,&
^xOA:yl
-xLD![
v[-Ix|p
nsh/UV
>6 &.]
&3b$A<
{1ZNgs
RY3Vb6
6*b}ri
1QL@V&
67I& oz
C8B8JV
nwm\HC
I{.cL[
m0"+A&
l}wHc<
3o\X8
<;/Jw
}Eo?
{MNr}X
h(7G{&
1h_dhQ
%Loo(rI
Hqd8^Y
f6r_-b
,&g^2H3
(H*6=`V
vITn)R
1Mu>z^
Jl4"zA
~Ol&)*/)
<6/!,)Q\
EG^86v^dM
,e}Q#2
jNX{d}
;00{.#
LTf<^N
eCp39:6
T\%Xg2
$0jJfM
#[?U`7
ZBs:QT
%LQ;k?
}Vcvv]C
Yf,%CZ
Wzud|H
5(izCh
]Dvkl
HAOO]e
WxVzk%2
}?|zKS?M"
}0^d81
2|Lie+>
>6m44xy
LsN|mL
kUP1_m
R~K7fT9
<2bUPj
N4<5\b
{vD8:0
&qM,P
QOa&GJ
}j ^Cc
G;("IB_
@g;e=a
">r|uU
VElUL
Rr!V(4QN*f
qjVUX;
3Wi**$0
G_H[V
xgs6gW
6of$9
b;4;Kg&%
7O6JTU
kewlEZ
;bB,]7
HhT#%A
]UI>!N
V:]Ga6xT
{|%Vc
ub|eek
G?d J!j%'
S=wKLtEk
'#l[K
DpyOZi
rY$(\x
_aST|@
:ETrQW
Vd+L*o
?Y@ }/S
G@U|6;
^,-B1j
}+bA<&
]@!sD
bXMJZip
uYwp<$
<mZ=Bn
`/t.>2z
Xd."^9
zppyM|
=AM"#eP
Mf]<c;
hd-cG^
xqnj7}G=m7
j@,VPY[
pV\Tf?
|t<mx?
{8K>}5
/?kFdH
`moy|;
*3-^3"
W0@~,-
OqbSnR
@zq.gT<
K]o?2n
Cv51SO
RL)!Zj
;1H}4DM
z?U#@f{
bL~]TP
68Cv_|
T<g<!<
L#a\l6Pr
{xp$=9#gG
U~wcpts
:!J?9%
2jSWox
X)v)2S9V;
3/Gt&0w
Uqj:mK.?MQ
:LAap<:
e/#v`D
6emhU(
fH>BA9
kNG4eb
{4G\c*Y`
+Q5}u>
JwV;5n
ZlRvcrM
:LmW|x$
BYb=GC
GdM-vm07
?e#%$OI6n
BJ(Y]0F*
0$KTw+
m%''@xZZG
5Tog2X
"J8\@G
T[='k{7RX
ZZ'60>
$9D6S.
~s`buA2
z*"2!Q
B$\Ry{.
W4;n1TuX
+[};ew
J]0eAl
Xxl" 1
OhVp-m
eXAI<?c
pl0Wy-
q0f:&.JY
+p?<z3
I]/m\f
aI8X6,(Pv
" L}PR{
<XC"%r_
x'Y8CX
]PJ3b@
.KWxIj
#xx/8Y#2(0^(
/u2d3o
*bCApH
Ke/JM(
II|RPz
2,$|'G
4rXA]~
t/Ohv'I
9b\ Ob
aolNhB
kVbSNw)
0c%Boe
dmG4802
z_=ABWp
_/zUI!
:K[`#KZ&
#$.w:E:
R(o5d)
rdo%[N
7O-|g.C4
fLy@9r
Y6+"%>yPS
g&@V89|
p"~y)E`
`%E|$n
7O<W,*
goJ8H@p
%\kC4@
\dyKq(
D%dMs->i
X (Kpt
j-aTor
KZ>9F
9o2V2GW
]*r>SIt^4
{P$&YP
Fz74zzuK
r8YN/!
r!mFQR
\qmHI1lU
V>ebsQ
)SM?<+
C:"#~E
Z;pzem
9!a/-q0?
b+m4);
BJoml9p6
+2,$/k5
0>4^d}
Dv>nf4*
Z 5sIp
;'M3Uk
+?yvWJy
\nVnYS
wp0A8&
6n9sx7
e@df1|
_KgCA\
!JS_g>
f[E]~6"
bMxTO<
AjzoE
|r]5:B
)3FM4C
+Y=$j$
tlXaoo$P
}!H\9'
p?|P2{
V|UA_N
@.iO&Ox
"1t|oS!
9~I&8++mW
2.9QH
nhgufG
!D3i3*
;l\PL0
g{j~0z&
\CWJvyh
%a(2(dpg+A[
9sfm-S
PbFn 7
XGer:0
b]dRk-u;
=F{ >e&?
PhMyt2,B
{3Iz%9Dx
a\vw.Bk
?FW<5:'[
ba>snS
\yj^[J
-Z`mK_
s]Z>:l
`aoaL7
xOX*U`
zW4?(9J
7LToU8a*
@(pZ&>
U`@=ay
J1?*!.
Hn,W~I5
,0_vv$
m`PC$)
otc)EKN1
L=sTY@l
fSy\p'
C#d^L[
f=z&Ch
-t8FQR-o<x
IVS3wJN
RjBdEA
r4[N:w
yj8g]?
"e#XdB
YWm&cZ
{Czp(&
c<2PIG
s~Q~*_\
DYADf
q`1=uhe
vUC0d%
/+l%~\
S&<Qxa
r/fLP]
f,!Z&/m
OWyHcr
bKcgT8
rJ#^`"-
VR0UYQV
+}4J}p
Wv!V5n
.cI!Np
92|42M
JzPR}h
uu6l.e
h"!N>;
g$&m, &
sjP:-|
wJ4H?~b
g'gPBY
I.Qzq7
Z3"dr)
JKX\o$
&@O1RU
nBl'g!
:(_5/6
U1Kc5,
tCN:@u7
HXtK~_
u04'r :,
k)(M$B
x7EM~?))
l]$%$#
uUo+?4BzdP,
!s1I6*
E"3@#h
Rl4/LMh
I2Kf21
|Rg'])
;H1 aVI4!
I:"wdl
#Bt~o9LD
CM- L/
^#a}m#
xyDRK>K
VPCP$P
h%\)&D
E^0|
D})x}%>cW
H4VyX\
sV&,:7
uR%NA8
"!zPvD
!BSIx<s
H<Q/BKL
o )Z@e
N"_+z@
d?E9-=g
)W6mE#
G6\VnB3
Aiw meQ
ouu_3I
7^% }u
r6^/Zc
8g?"ny
K76R?s
CMJG5S
L[<#4I
~zVN@.h
@PXwy[
3P6`vJh
tS*jc'O8
={,,]U
Tz)^M{
mbx4d3
-[.SiU
+C|NA~
'CPh.}
A$JI+dM}
kq)4koW
9TyNBG
c<+\%7*
nocM.1
GpgEkv
jcXO|8
K|)lq@M-.D
jN,_1:
w1,SdAKhmc6f+~JA
Nv5bCgE
>=W99J
Wh/y,xt
`D*"wM
7*Dh5c{R/
dQu'(+
jk9n\.
|ECgxP
V?DN+$
.bB6G@
j9EkVB
W(sGGQa\%
H22hJqwO$z?
/%C+E`.o
C,i{aK
Mnw<GQ
K?PtL7b
\&1KG_
+N7da@
l=Y#<b
1\hfue=k~
Sb$630
L(RL%N
aq9j)h6UX[
Q FN:XU
_aTo#4
F;7Z/M
\>rmk[
]xeetIk
1MtFE(~
p!iAT
i3fOQmn
bbLU`W
g&_$\
|=U[P>=a
%ux a|
;="89Y
O9DV6kU>
N|9kl_
VH'KKS
eGiC/?
ASB\~*?
p7.]`,9
5z>B60X
WG-QqH
g~Co#gl%
,OY 5a
7X5A@r
MlV^6<
z{o3Wv
hW!2O2u.
usm3~|{
.U){,"3
]a73"qt
-9hsV#
7,q~S1
nSX=!t#)
GpEyX#q
~o] iB
GWw&0,L
OE.qF@
dFS~kR
J2gPb)F7
Rg2TbiX
q};9k
uY<)81
m,\6(ci
8]vI1g
j;Op)Zf
ln.,jP
((U\oT
`v^nM'
`s%wo8
:"<x9a
>roJWz
fCgIuS<v
KSlu/b2
>4kLO|
|xt6ZU8[
W5?L6Z
<h^:`6
o?w!Gf,&
h9z!I_
1uW4;h
An?B~mJv
u8rzyFD;
wP>.D33
YC f+
dA-z;/
r/<|{;
a"f#xT"oB
cjI}LDsP<
;l6~0Q
jY>ch7
,'@D#6"
G + !9Tk(
zHOJy5
7g;QWY
53,k*B
9E#8f`
isI^:p
w1QO5v.
SYHj(,
`,eUGG
_A7@IF
'yH&zB
imWyBt
R!FZ2:
J60lTWycP
oqyo2]
0|Tr-g
#H"m0#
6J1w5('/Z
=z4X/J
N?OTX.
NSj/"-
p+))k4
h/4H%a
*~Myl;
]b.]8V
nG*{h:
i,E^l\a
A-)^5N
4^*yIMR
YL:|J5
yNRd!~
["g;XS{
cI"8C:
JWog")cJ
YQD$+m
VPM!$`
KMfX"w
x68WV3
?'P0)PMm)
PTol59#.
1Ef~O
.Us+Qn
wAq!Q6
<E6$)T
jGrq8a
Q\s\]^H
=pSd@$
Nc1Ug>
_p6z6GC
w*-7ad
;`TO.P
Db:0)Z
Go7' NG
+~}$u~'
.8!?,E
way7FL
~ktlf|
}-`yBc
w{h_mLPd
;B+AYz=
k:#{;_
]jKCy<(klW
J%_T.H
toL!BbL
>mit5wr
xlmKwK
akvx2Evi.
&R0%w.
D7)&C|
@;-bQ~
o[<T[&)>
|Q*PX]
Rm0NXR1@
y#h"7~
n"5"gs
p]>^2u
2?/:Z|
f_"6M[
R\bfo"
+tx\0L
D4dmO5
,"!LXi
1BX{<U
}QXg:
wAnLm.
1qjQWSUZ
}hiGdj
b_kx\u
Nd++73
D1zb2m
DwuViY
M}u-w8!8W
[e?d)x
wiH^%kgR
/+`*~Q
7aiA{u
QTg03a
xj5H0~
].waWf
Ys&QLL
E7!P4V
jThe,<%
p}{,>w
yj4U!]
cxJ*RF
-#>\t0
FFa)p7
g@9)eX
6PzoO|
4Gdv~~
]irmg{
xTx2|K%_D
yTOTph
?f%AIf
L;iG3k
9oKWn~
xJn<\W
C5T7Xd
[S"jug@x
W2aJ<_
#EgTmUi
;WF\@u
;v<Yp>
G4{S)T
rir[T1T
MYN7r^
'XT}0w#
c[vYZ*
JbVP==3
dJA[v.
o5I@EF
vsSxeh
a\;!u%vCk<
chd8 <
=r|I/%
*=3=F
ZCTYPK
|7+Oj-
1c98I(]
-M&8YL
w@IZso<G){g
h|,?=
Jk53Ek
^3(O1`D
u:L9^DY
{P%};_iSc
FP;Tf[s+1n
Z1M_+&
Md9Gb!
yN4qVS
d@G-3y
zir?1i
ud9$RA
\JfYdd
^UR_e<
P=JE9L
+#Gw)x
OMyn0k
Rc>,5;
DhFN%VH
aGc0}T`
5zqxgK9
qEM0)j4Kj'7Esz
>4a-+n
U@XI;C
*/QdA-{m
PwL3Oj6
g>=[Hsb
A_m4ZSX>!N|_
h"RMo~
4?C*_`
2"=jx>
6fpN)%
DGl7(&
@( {8M
M 'el'
^[)hDk
J=:>sD
W\G&G/d
gLd/,qE
#0fv\kA
(F>6|/
k=7\JD
A>?8_&
k$U[4|
_FWCn@
JE/* w
D.P8M>
4@N&S"
zV\.qFj-h
oUZ?Gn
=t&lJg
/'Np|[kH
L/wMc$
pIT31<
|~!m:}
TL7LF$p
+XS&IT
DiA>J+i
url5$s
P8?uyo`
??Q,Ie
"R*T"d
/(//:&
Cv<5a7
>|K=a59C
Y_cX*j
VMDj^m
_bj2
_bY*
Z_bX
v4.0.30319
#Strings
UInt32
ToInt32
m_Choice2
Decoder2
get_UTF8
<Module>
System.IO
mscorlib
_solid
DataField
ResolveMethod
m_Choice
distance
ReverseDecode
Invoke
GCHandle
RuntimeFieldHandle
LoadModule
get_ManifestModule
get_Name
get_FullName
AssemblyName
DataType
GCHandleType
ValueType
System.Core
ResolveSignature
MethodBase
Reverse
Create
IsCharState
GetLenToPosState
posState
GetState
STAThreadAttribute
DebuggableAttribute
TargetFrameworkAttribute
ExtensionAttribute
CompilationRelaxationsAttribute
ConfusedByAttribute
RuntimeCompatibilityAttribute
ReadByte
DecodeWithMatchByte
matchByte
GetByte
PutByte
prevByte
add_AssemblyResolve
Overskirt.exe
inSize
outSize
_windowSize
m_DictionarySize
SetDictionarySize
dictionarySize
Normalize
Encoding
System.Runtime.Versioning
ToBase64String
UpdateMatch
get_Length
m_DictionarySizeCheck
CopyBlock
m_PosStateMask
m_PosMask
DecodeNormal
GetManifestResourceStream
ReleaseStream
inStream
outStream
MemoryStream
_stream
System
IsLittleEndian
AppDomain
get_CurrentDomain
System.Reflection
ParameterInfo
UpdateRep
UpdateShortRep
UpdateChar
sender
m_MidCoder
m_HighCoder
m_LowCoder
LzmaDecoder
BitTreeDecoder
m_RangeDecoder
rangeDecoder
m_LiteralDecoder
m_LenDecoder
m_RepLenDecoder
m_PosAlignDecoder
BitDecoder
m_PosSlotDecoder
Buffer
_buffer
ResolveEventHandler
BitConverter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
SetLiteralProperties
SetDecoderProperties
SetPosBitsProperties
properties
GetTypes
m_NumPosStates
numPosStates
GetBytes
ResolveEventArgs
Models
NumBitLevels
numBitLevels
_streamPos
m_Coders
m_IsRepG0Decoders
m_IsRepG1Decoders
m_IsRepG2Decoders
m_Decoders
m_IsRep0LongDecoders
m_IsMatchDecoders
m_IsRepDecoders
m_PosDecoders
RuntimeHelpers
GetParameters
Decompress
numTotalBits
m_NumPosBits
numPosBits
DecodeDirectBits
m_NumPrevBits
numPrevBits
Object
get_Target
ToUpperInvariant
Decrypt
Convert
Overskirt
System.Text
m_OutWindow
startIndex
InitializeArray
GetExecutingAssembly
GetEntryAssembly
BlockCopy
Confuser.Core 1.6.0+447341964f
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Overskirt.exe
LegalCopyright
OriginalFilename
Overskirt.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Variant.Marsilia.1985
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Generic.TRFH518
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Marsilia.1985
K7GW Clean
Cybereason malicious.26f4c5
Baidu Clean
VirIT Clean
Cyren W32/Trojan.IQQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.RZS
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Marsilia.1985
TACHYON Clean
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Clean
VIPRE Gen:Variant.Marsilia.1985
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.hc
Trapmine malicious.high.ml.score
FireEye Generic.mg.a5c8a40f7c15619d
Emsisoft Gen:Variant.Marsilia.1985 (B)
Ikarus Trojan.MSIL.Crypt
GData Gen:Variant.Marsilia.1985
Jiangmin TrojanSpy.MSIL.bjiu
Webroot Clean
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Marsilia.D7C1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/Redline.NEL!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5218829
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Marsilia.1985
MAX malware (ai score=84)
Malwarebytes Trojan.Injector
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36106.Gm0@aOpCZqe
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.