Static | ZeroBOX

PE Compile Time

2023-02-07 21:16:20

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001addd4 0x001ade00 3.67053916414
.rsrc 0x001b0000 0x0000f76f 0x0000f800 7.52170992233
.reloc 0x001c0000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001b4768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001b4768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001b4768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x001b4768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x001bf16f 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x001bf1e9 0x00000396 LANG_NEUTRAL SUBLANG_NEUTRAL big endian ispell hash file (?),
RT_MANIFEST 0x001bf5bb 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-9&&8l
*4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C010300CE16E2630000000000000000E0000E210B01060000600D000006000000000000DA7F0D000020000000800D000000400000200000000200000400000000000000040000000000000000C00D000002000000000000030040850000100000100000000010000010000000000000100000000000000000000000807F0D005700000000800D00640300000000000000000000000000000000000000A00D000C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E74657874000000E05F0D000020000000600D0000020000000000000000000000000000200000602E727372630000006403000000800D000004000000620D00000000000000000000000000400000402E72656C6F6300000C00000000A00D000002000000660D00000000000000000000000000400000420000000000000000000000000000000
v4.0.30319
#Strings
Rdvbt.exe
<Module>
mscorlib
ValueType
System
Object
PoweredByAttribute
SmartAssembly.Attributes
Attribute
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
String
Substring
Convert
ToByte
Encoding
System.Text
get_ASCII
GetString
get_Length
Assembly
GetType
GetMethod
MethodInfo
Collect
Action
GetTypeFromHandle
RuntimeTypeHandle
MemberInfo
get_DeclaringType
get_Name
Delegate
CreateDelegate
Invoke
WrapNonExceptionThrows
Opera Installer
Opera Software
Copyright Opera Software 2023
$75a1b900-1789-44fc-b6cf-628a376228a8
95.0.4635.25
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6(
#Powered by SmartAssembly 8.1.2.4975
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
_CorExeMain
mscoree.dll
B0E&L?<
bN@5'a
4iaL3/
PynNu3
hvZrjZ6
T%|t+-9
;;pG 
&x5eaG
=n-?fG
?>Ri,Q
C?<T.~
u;,fM\M
g{jr=
vAI)U[?
Jorze}Xv!3
WqeZv/}
E>).r8
l$4q,L
+3i\Ytmg
Uq|?\[
CY>dG@
KVZp#*X
aC[uXw
dZL1#1
JKFqGP
=t|ht;
"lG}NB
s/.sF7ZBB
~:>^Lm
(c6FwC
y5Q"aD
8>&lM~
rCN^n(
&7]}R9
dIA6UUiaP
!q`+E;
A7b%%N
iGK^a)g
=@/tQ^8
'SNoiY$0
\`xaS#
'.6n:!rY9
4'Gs[M
-]70#)C
Al^P4F
Q~x9 x
E$&>-N
)mIDAT
!jE.s
[O?,h
8Q~,v+;
$`P!hl
SH%O~Pp
ASA)#n6
2^[cZn
0dx(.v
D}V/&S
@9(p\\
tn^i5_3z
X"G#we
fdh,-]^
DQ!XeJ
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
9}%A}%I}%Q}%Y}%a}%i}%q}
=.#\.+\.3q.;w.C\.K
.Sq.[q.c
Mvwngiwvpieneloqxped.Rimpthwicyfkwjzzpjxt
Dxarqzhajkahwmnjghd
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Opera Installer
CompanyName
Opera Software
FileDescription
Opera Installer
FileVersion
95.0.4635.25
InternalName
Rdvbt.exe
LegalCopyright
Copyright Opera Software 2023
LegalTrademarks
OriginalFilename
Rdvbt.exe
ProductName
Opera Installer
ProductVersion
95.0.4635.25
Assembly Version
95.0.4635.25
Antivirus Signature
Lionic Clean
tehtris Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.64479
ClamAV Clean
FireEye Generic.mg.135ec341e42d2905
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.64479
K7GW Clean
Cybereason malicious.205d78
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.GFLX
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.MSIL.Injuke.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.93 (RDM.MSIL2:PMk/O7RcB+WHjbL7Pf7NBA)
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.64479
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.64479 (B)
Ikarus Trojan-Dropper.MSIL.Agent
GData Gen:Variant.MSILHeracles.64479
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.MSILHeracles.DFBDF
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!135EC341E42D
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/RnkBend.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36252.Vn0@aKzPj3
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
No IRMA results available.