Static | ZeroBOX

PE Compile Time

2022-12-07 08:37:32

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000012a4 0x00001400 5.36214185291
.rsrc 0x00004000 0x00000a60 0x00000c00 3.66928054729
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004720 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00004720 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00004848 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00004160 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00004870 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
Xdgmbc.exe
Program
WindowsFormsApp14
mscorlib
System
Object
EventArgs
Program_Playing
EventHandler
Playing
add_Playing
remove_Playing
LiveTV
sender
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Security.Permissions
SecurityPermissionAttribute
SecurityAction
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Xdgmbc
MemberInfo
MethodInfo
Action
RuntimeTypeHandle
GetTypeFromHandle
Delegate
CreateDelegate
DynamicInvoke
Combine
System.Threading
Interlocked
CompareExchange
Remove
<LiveTV>b__0
Func`2
CS$<>9__CachedAnonymousMethodDelegate2
CompilerGeneratedAttribute
<LiveTV>b__1
CS$<>9__CachedAnonymousMethodDelegate3
get_FullName
String
op_Equality
get_Name
Assembly
GetTypes
System.Core
System.Linq
Enumerable
System.Collections.Generic
IEnumerable`1
GetMembers
op_Inequality
Invoke
System.Net
WebRequest
Create
HttpWebRequest
set_Method
WebResponse
GetResponse
System.IO
MemoryStream
Stream
GetResponseStream
CopyTo
ToArray
List`1
get_Item
System.Text
Encoding
get_UTF8
GetBytes
System.Security
UnverifiableCodeAttribute
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
KFCLEANER
Copyright
2014
$b65a6083-69fc-42e9-ac79-71e7490dcef4
1.0.0.0
WrapNonExceptionThrows
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLN
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGO
DDDDDD
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Hbmqvgrbizxwsrrqlwcjj.Emoseqbbcaau
Kwhvrxyrayfv
http://eisnt.com/documentos/Vdphcbtfoys.png
Horptkyvodayqzboisbptos
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
KFCLEANER
FileDescription
KFCLEANER
FileVersion
1.0.0.0
InternalName
Xdgmbc.exe
LegalCopyright
Copyright
2014
OriginalFilename
Xdgmbc.exe
ProductName
KFCLEANER
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Seraph.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.MSILHeracles.54634
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!1E063B3D9CC7
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Msil.Agent.Aune
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.54634
K7GW Clean
Cybereason malicious.081237
Baidu Clean
VirIT Clean
Cyren Clean
Symantec MSIL.Downloader!gen8
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OGH
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Seraph.cbf7afd4
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Ad-Aware Gen:Variant.MSILHeracles.54634
TACHYON Clean
Emsisoft Trojan-Downloader.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoaderNET.507
VIPRE Gen:Variant.MSILHeracles.54634
TrendMicro Clean
Trapmine Clean
FireEye Gen:Variant.MSILHeracles.54634
Sophos Mal/Generic-S
Ikarus Clean
GData MSIL.Trojan-Downloader.Agent.BJU
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1253931
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Wacatac.dd!n
Arcabit Trojan.MSILHeracles.DD56A
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36106.am0@a0Cs74i
ALYac Clean
MAX malware (ai score=85)
VBA32 Downloader.MSIL.gen.rexp
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-Downloader.Ader.Dnhl
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.