Static | ZeroBOX

PE Compile Time

2083-02-16 10:09:10

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00007314 0x00007400 5.50627988094
.rsrc 0x0000a000 0x0000072c 0x00000800 4.57779088644
.reloc 0x0000c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000a0a0 0x000004a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a540 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<>9__1_0
<PerformSelfDestruct>b__1_0
<>9__1_1
<PerformSelfDestruct>b__1_1
IEnumerable`1
List`1
Microsoft.Win32
<>9__1_2
<PerformSelfDestruct>b__1_2
KeyValuePair`2
Dictionary`2
hMH7v6
get_UTF8
pKMWIE
get_ASCII
bwDjMK
System.IO
pcFiVO
zNPy4Q
n09yEW
gps9kZ
UploadData
ProtectedData
get_filedata
set_filedata
xvfwwa
xwj1Vb
mscorlib
System.Collections.Generic
hKDYUd
Thread
add_DomainUnload
get_IsAttached
System.Collections.Specialized
Synchronized
ProcessCommand
Append
Replace
CompressionMode
FromImage
get_Message
AddRange
IDisposable
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
Console
set_WindowStyle
ProcessWindowStyle
get_Name
set_FileName
GetTempFileName
get_MachineName
get_FullName
get_UserName
get_name
set_name
get_filename
set_filename
get_Compname
get_Username
DateTime
get_LastWriteTime
get_CreationTime
WriteLine
Combine
Escape
DataProtectionScope
ValueType
SecurityProtocolType
wtfAreYouDoingHere
get_Culture
set_Culture
Capture
ApplicationSettingsBase
Dispose
get_modifiedDate
set_modifiedDate
get_createdDate
set_createdDate
Create
EditorBrowsableState
Delete
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
XmlEnumAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlRootAttribute
XmlArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ToByte
get_Value
set_Value
GetValue
SetValue
Remove
get_Size
Serialize
Deserialize
get_filesize
set_filesize
xiZiLf
os5tBg
get_Jpeg
System.Threading
get_Encoding
System.Drawing.Imaging
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
FromXmlString
ToString
GetString
System.Drawing
qEizng
IsMatch
get_Width
get_Length
EndsWith
Ikycljodybakdylqjxzzok
k2k_xk
System.ComponentModel
kernel32.dll
System.Xml
set_SecurityProtocol
GZipStream
MemoryStream
get_Item
OperatingSystem
AsymmetricAlgorithm
daXKzm
TimeSpan
CopyFromScreen
AppDomain
get_CurrentDomain
Iorsifvpjugpsjifdsppln
get_OSVersion
System.IO.Compression
get_Location
get_Information
set_Information
System.Configuration
System.Globalization
System.Xml.Serialization
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
ManagementObjectCollection
IOException
add_UnhandledException
get_ScreenResolution
FileInfo
CultureInfo
FileSystemInfo
ProcessStartInfo
DirectoryInfo
cl12jo
Bitmap
ToUnixTimestamp
g_wiCr
StringReader
TextReader
RSACryptoServiceProvider
RNGCryptoServiceProvider
StringBuilder
Buffer
get_ResourceManager
ServicePointManager
Debugger
ManagementObjectSearcher
UnhandledExceptionEventHandler
System.CodeDom.Compiler
CurrentUser
StringWriter
TextWriter
ToLower
XmlSerializer
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
IntPtr
Graphics
System.Diagnostics
LoadCommands
ProcessCommands
get_commands
set_commands
get_TotalSeconds
GetBounds
qvt5es
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Software.Properties.Resources.resources
DebuggingModes
Matches
GetDirectories
ExpandEnvironmentVariables
get_Files
set_Files
SearchFiles
GetFiles
ReadFileBytes
ReadAllBytes
GetBytes
UnhandledExceptionEventArgs
get_args
set_args
get_Ticks
Equals
System.Windows.Forms
Contains
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
get_Headers
get_Success
Process
get_IPAddress
Compress
set_Arguments
get_Exists
woPXvs
nvxRVt
Concat
ImageFormat
Subtract
ManagementBaseObject
ManagementObject
Collect
Unprotect
HandleSelfDestruct
System.Net
get_Height
add_ProcessExit
get_Default
WebClient
System.Management
Environment
get_Current
MakeScreenshot
Encrypt
Convert
MoveNext
System.Text
ReadFileText
ReadAllText
Ikkwwrvutglbirvyaptvwu
get_Now
get_UtcNow
set_CreateNoWindow
ToArray
get_Key
set_Key
CreateSubKey
RegistryKey
Inaqqjmjigflwhuoseqney
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
BlockCopy
Directory
Registry
op_Equality
op_Inequality
System.Security
Igxcadkatwzukojjzpxhvy
WrapNonExceptionThrows
3673772352
6602549809
2514488080
7529646457
5682364936
4276273733
$68d5aff3-723f-4739-863f-67b909666c26
66.2.4.5
.NETFramework,Version=v4.7
FrameworkDisplayName
.NET Framework 4.7
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.2.0.0
command
Commands
commands
filesize
createdDate
modifiedDate
filename
filedata
information
report
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
h8Q3ny
y4nxpR
OBOBOBOBOBOBOBOBOBOBOBOB
Q\'[)]A#
ZFqMMR[?
U_6KOO
.T`>q<
Q\'[9MB6LMO
.{g98(E
pwFvXC
dYoFpU
ay1gYq
<*5'0PV
8g8a
\>~)4f
(?& !?
\ )k`1
?)&?*&d
"V<'`g8-9
(!$Y3:m:
/~=5-],
%-liA8
<*5'0P
njKYRU
PFAwPFC{X76
{+9%>Q
PDuHWCsAPC
r@[aRHo
G~THp\V
.@ToBV,
*_H}@Ts
WmPHq^
WmSHq^
*_H~@Ts
qHD#]UsM
WmSHq^
r@[m\V.
r@[m\V.
r@Zm\V.
WmRHq^
r@Zm\V.
B7Z\fG6
Qp]Up]Up]Up]Up]Up>
r@Zm\V.
WmRHq^
WmRHq^
WmRHq^
WmRHq^
a2CgUl
wTNUNL
u5Bbsh
2F[Vi_
hax2Wi
dPmuDn
w:NOqr<!(qc
yUq96D
g0qRUx
uzaXa5
pzduKP
jdvEft
*7 &.&A
$5 [_P
xeR499
cN_yPs
erbeL9
NTNFBDSGN
nrY56W
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
k9be187d291aa8219fbd6
CompanyName
F89bd1d5ab8742427a0e205
FileDescription
j4d2edb9a23d5882138f6e4e181
FileVersion
2.21.84.32
InternalName
X8c2b8046c962ecd94f2d276acb.exe
LegalCopyright
Sf8f12fd0ca53dcd1eb270d9cb80b56
LegalTrademarks
Y83331c3e771c2f444e5a8bc52d6cb21432a152
OriginalFilename
if3a7b3382beb2f37d3531e28bfb0f5fb84e4ad.exe
ProductName
yc63877414a781062513bcde4e02d04
ProductVersion
53.48.68.72
Assembly Version
10.50.26.63
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
DrWeb Trojan.PWS.Steam.35197
MicroWorld-eScan IL:Trojan.MSILZilla.25609
FireEye Generic.mg.495ce8bc963f4b0d
CAT-QuickHeal Clean
McAfee Artemis!495CE8BC963F
Malwarebytes Spyware.Stealer.MSIL
VIPRE IL:Trojan.MSILZilla.25609
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender IL:Trojan.MSILZilla.25609
K7GW Spyware ( 005a12bd1 )
K7AntiVirus Spyware ( 005a12bd1 )
Arcabit IL:Trojan.MSILZilla.D6409
BitDefenderTheta Gen:NN.ZemsilF.36344.cm0@aqGxNyc
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.A
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/Stealer.d3bcb07e
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Stealer.32768
Rising Spyware.WhiteSnake!8.17C86 (CLOUD)
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.25609 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Trojan.MSILZilla
Google Detected
Avira TR/Redcap.teokj
MAX malware (ai score=88)
Antiy-AVL Trojan[PSW]/MSIL.Stealer
Gridinsoft Malware.Win32.Sabsik.cc
Xcitium Malware@#1uu2vohnahrv7
Microsoft Trojan:Win32/Casdet!rfn
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
GData IL:Trojan.MSILZilla.25609
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MSILZilla.C5397965
Acronis Clean
VBA32 TScope.Trojan.MSIL
TACHYON Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DCK23
Tencent Msil.Trojan-QQPass.QQRob.Sgil
Yandex Clean
Ikarus Trojan.MSIL.Spy
MaxSecure Clean
Fortinet MSIL/WhiteSnake.A!tr.spy
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
No IRMA results available.