Static | ZeroBOX

PE Compile Time

2023-01-21 22:09:29

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00218784 0x00218800 5.85115035156
.rsrc 0x0021c000 0x00013600 0x00013600 7.63250393992
.reloc 0x00230000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00221990 0x0000d646 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0022efe8 0x00000068 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0022f060 0x0000039e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0022f410 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
*AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD5wAAAADAAZIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAwAC4AMAAuADAALgAxAAAAbgBvAGkAcwByAGUAVgAgAHkAbABiAG0AZQBzAHMAQQABAAgAOAAAADAALgAwAC4AMAAuADEAAAB
v4.0.30319
#Strings
IEnumerable`1
Func`2
<Module>
get_ASCII
System.IO
mscorlib
System.Collections.Generic
Thread
add_Load
Interlocked
CompareExchange
Invoke
Enumerable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
GetName
AssemblyName
Combine
ValueType
System.Core
get_CodeBase
WebResponse
GetResponse
Reverse
Create
CreateDelegate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
UnverifiableCodeAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Remove
Wavnss.exe
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
GetString
GetResponseStream
MemoryStream
System
AppDomain
get_CurrentDomain
Application
Action
System.Reflection
CopyTo
System.Linq
EventHandler
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetAssemblies
EnableVisualStyles
GetTypes
EventArgs
System.Windows.Forms
System.Security.Permissions
RuntimeHelpers
Wavnss
Object
System.Net
SetCompatibleTextRenderingDefault
FirstOrDefault
Convert
HttpWebRequest
System.Text
InitializeArray
ToArray
Assembly
op_Equality
System.Security
add_rafz
remove_rafz
WrapNonExceptionThrows
Opera Installer
Opera Software
Copyright Opera Software 2023
$280367a7-0c11-4ae2-83b9-690af914f91e
94.0.4606.54
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
_CorExeMain
mscoree.dll
,,,,,.6..-
-....39330/0330/0333344441
A6AA<OLTSLP<AAAAC6CC=Q
R=CCCCD9DD>N
N>DDDDEEEEBI
JBEEEE
((((()6)))
)))))*9***
*****GGGGG+:;;:+GGGGG
1F6C22222
TTF61111II
w|||{{{X
cgeeuueeeeeeeeeeeeeeeeeeeeeeeeedghij
iiiiiiiiiiiiiiihiiiiiiiiiihfkj}
jjjjjf
djjjjjjjjkf
#######!
!!#$##
HRIFIISJ
KKLLRNSN
'nwwnzzzz'
wRLRSSSQSv
&" vJJJNMNNNv
 "&
XEHEEMEEET
Z8+PP++++++6((((((((6
*+,++-Z>8*QQ******yWWWWUVVVy
+******->@99pp999999
.89999999[];:oo;;;;;;?)0))////?
:;;;;;;;;]b@@ts@@@===U43544445O7<@@@@@@@Zb
``````xMDMGHEOEXY\`````a`a
URSSSJUJw^
BVVVVVSCCCBC
`WWWWVVVSSCVY
f^WWWVVDVVeZ%
%!! &&
&&& &&&&&&&$Y
fX &&&&&&&&&&&&&
   !'  
&'&&&&&'&&&&&&&''& &&&&&&&&&&$'(&&&&&' &
)((()(((((((((()(((()()(((((((()()(((%&(!*++v
vuuuuuuuuvvuvvvvvuuuuuuuuuuuuuuuvvvuuv+v*uyxy
yyyyyyyyyyyyyzyxyxxxxxxxzyyyyyyyyyyyyyyyw{~{{
~}}~~}~}~}}}}}}}}}}||}}}}}}}}
}~}}~~}}{~z
||zzxxxxxxxyyzz|}
|>,,,wwwwww,,,,w,*
'*,,,>,w,w,,,,z>
=""########"##"
"#"####"#>
97777799974442
000034479999
::::::8:2
/0355888::8885:
e_W\E[.
e_\^]\\\^WWZ
:56666666;666221
ZZaZTXYXYWe
22262666656:
MLIIFF
FFFGGII
TXXYXYXXXXXST
dddd```]XX
LQKJ__aGGHHHGGG
FHGGHHHHKMJmmQL
MMMMMMKKIG
`_]]\\WW\W\e
FHIKKMMMMMMPQPmmRQ
PPPQPPPNMIH
bb`__]]W\WUe
FIMLPPPQPPPQQhRpmmR
QhhhhhhgPKH
cdd``_^\]\W
HKLQRghRhhhhRijippmk
jjjjjjjiggO
c`___\Y^
JINgijjjjjjjjjkkk
lllllllkjgg
Jgggkkoolllllosss
sssssosongg
Jggnoosossssssstr
_]#)!)A
;(jX.hbK/
_e|%b8
8Ud>G|
>uSnf
'nzdqK
zp%HoRK
&K266"
-nG`><
d@g#J/k
f%1F @
y/LBV=
l4{?qm
h4@Y[~
?:H39G`
ebRy.:+
`,"6M"
]TBk@Z
82LdLJ
icl@Hxb
JGU:bc
E]^?)y
b\k`{+
8XDaVZ
I=]wI(
>,Y,Ld
uBrp|d
hcRA$!
U}@YN6
3DzTS>6
,UWR%&
huLf9qH
I8"!o|
8ck1Hr
v{']OZ
||Y0+\
DT;T<m
503O{V
3)Kzq$M
+`V@B&
0[o:nQdS
g8@]W+
G;{VQF4
IDATDA
KFfefe
m. a
kRWt=%YG
c`[VmrB(IK
h)lC4v
WHohow@
>\SRAH
|_}?|lK\tD
>uwuV
){< h>
k=ujt z
Vma/4H
.hG[FV
k8x`qKH
j@JdmfA
bK|dcv
0y/(W/
/-xi|B
Xsog[]
{?A E`
t_@mgl
.&Hi<E
#{D+8e
myW=!/
u%q^2J
L m`_.Q,
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Suvlobdgdvfiwnyvz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Opera Installer
CompanyName
Opera Software
FileDescription
Opera Installer
FileVersion
94.0.4606.54
InternalName
Wavnss.exe
LegalCopyright
Copyright Opera Software 2023
LegalTrademarks
OriginalFilename
Wavnss.exe
ProductName
Opera Installer
ProductVersion
94.0.4606.54
Assembly Version
94.0.4606.54
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
FireEye Generic.mg.994218a84ef481fc
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.c25b54
Arcabit IL:Trojan.MSILZilla.D5FA2
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.MSIL.Injuke.gen
BitDefender IL:Trojan.MSILZilla.24482
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan IL:Trojan.MSILZilla.24482
Avast Clean
Tencent Clean
TACHYON Clean
Emsisoft IL:Trojan.MSILZilla.24482 (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1232149
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Clean
ViRobot Clean
ZoneAlarm Clean
GData IL:Trojan.MSILZilla.24482
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36212.lo0@aiAea!h
ALYac Clean
MAX malware (ai score=87)
VBA32 Clean
Malwarebytes Malware.AI.2087340352
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:3i1jxFUjh0UJWEZJ2GJjqw)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Clean
Panda Clean
No IRMA results available.