Static | ZeroBOX

PE Compile Time

2023-03-26 18:16:02

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00032d1f 0x00032e00 7.93453419884
.rsrc 0x00036000 0x000168c2 0x00016a00 2.06475405006
.reloc 0x0004e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003b828 0x00010828 None SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003b828 0x00010828 None SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003b828 0x00010828 None SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0003b828 0x00010828 None SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0004c09e 0x0000003e None SUBLANG_NEUTRAL data
RT_VERSION 0x0004c118 0x00000584 None SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004c6d8 0x000001ea None SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+S+Xri
91-(*
+g+h+mo6
+(+)+*
+&+++0(V
p+"+#+(
v4.0.30319
#Strings
mhpi.exe
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
PoweredByAttribute
SmartAssembly.Attributes
Attribute
WebClient
System.Net
value__
ParameterInfo
System.Reflection
.cctor
object
method
Invoke
nhffskdgsfkdfdddadfrfffdfdhffscffdf
hkgfffgsfddffffdhhddrfdahddsshcf
chfdgeffdfkffdafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hfsdkffddgfgfhsefffdfaffffdchd
fghhfgsfffrffddffdfffdcdshhfdasdfh
cfffhddffdgfadfdfrsfsshdkfffgh
hjfdfffhfgfadsfgdfdcrdfffffskhj
fsfghrgfddffdffdfdfffkhsjd
fsfdfdcdfffddshdffgfefdfkfghj
sddddfffhfedgddjffgfffffgjfsfkdgsfacsafp
sgfhjffkffffgfdhjsrfhddfhffaddsfsfhssfcfgdb
ddffrdjfffsffhgdffafcfdssfkfhgj
ffchkffgdafhffdsffrdsfsfj
jffgadffcffdggffsddefhfsgkffj
jcfsaffdfgddhffrfddsdgkfff
fdfcfhkfhrfffdgfdfdfgsfssffj
jffaffgffdfdrfdgffhfcsdsgkffj
jcffdhfdfsfrfgfdsadfsdgkffff
gdddffdsffdhfssfdgh
fhfsdsdsffsdfhfddfhhs
hsfffdfsd
ffdfffsh
shsdasffadsd
sdffsdffsfh
sdhffdffssf
sfsaddfsfgfs
affdgsffdshs
gsfasffdsd
gssfdffadss
gsfshadfsfs
gfsafdffsdg
gasdfffdfshsg
gdsfdaffag
hsdffdfdafs
adsfsdsffdds
jdddffsdsf
gdfgffsssdfh
jfsdsaffdffhg
jffdffdfdsgfdgs
jsfsffdffdf
jdffffaf
gdfddssffddj
kfdssffdfsagfh
fssffjffsffdfg
sjffadfsffaf
fdfhfsfssfsfs
jsffssfffdssd
jdsfdfffaffssk
wssffffssdv
gsfffffssds
gffssfffddsx
startupInfo
bSmkFI
jdfhfdfdffdfffssdkfj
hdfffdffshffsassdkfsh
hdffhdfsdhdffdfkdf
affdssdfffhhfhh
sdfffdsdshffafdhf
hffdsffddfsfshfsdhs
hhhgfdfffffffdfsfh
fsfdffsffhfffdhs
fddsfffhss
ffdhfdfff
hfhfdhsdffsf
jhffsdffdfdh
fsffgfgfafad
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
CompilerGeneratedAttribute
mhpi.resources
System.Windows.Forms
Application
get_ExecutablePath
AssemblyName
AppDomain
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
IEnumerable`1
System.Collections.Generic
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
System.Runtime.InteropServices
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_CurrentDomain
get_ParameterType
TimeZoneInfo
FindSystemTimeZoneById
Equals
Console
WriteLine
get_Local
String
get_Chars
get_Length
IsNullOrWhiteSpace
Concat
System.Management
ManagementObjectSearcher
ManagementObjectCollection
GetEnumerator
ManagementObjectEnumerator
get_Current
ManagementBaseObject
ManagementObject
get_Item
ToString
MoveNext
IDisposable
Dispose
op_Equality
Directory
System.IO
Assembly
GetExecutingAssembly
get_Location
GetDirectoryName
Exists
EnumerateDirectories
ResourceManager
System.Resources
GetObject
get_Assembly
ReadLine
Convert
ToInt32
Encoding
System.Text
GetBytes
Resize
get_UTF8
Marshal
SizeOf
ToUInt32
IsNullOrEmpty
IntPtr
Exception
BitConverter
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
SortedList
System.Collections
IDictionaryEnumerator
IEnumerator
DictionaryEntry
get_Key
get_Value
RemoveAt
TimeSpan
get_TotalHours
Double
WebRequest
set_Timeout
set_Method
GetResponse
WebResponse
Create
GetHostName
Contains
IPGlobalProperties
System.Net.NetworkInformation
GetIPGlobalProperties
get_DomainName
ProcessStartInfo
System.Diagnostics
set_CreateNoWindow
Process
set_StartInfo
FromBase64String
MD5CryptoServiceProvider
System.Security.Cryptography
HashAlgorithm
ComputeHash
TripleDESCryptoServiceProvider
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
GetString
Replace
get_Message
WrapNonExceptionThrows
"Powered by SmartAssembly 6.9.0.114
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
q4\,E(
E5\1Y)@-E5\1Y)@-E5\1Y)@-E5\1Y)@m
mrMjM
S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"O'W>S;K"!
HuQ"@`
O*G/_6
oF*A0X
SRA*[#
Z:U9R"K
RWA2\j
KK$J#S:
h(C/H8Q
ZNK{C8
jF K<V";
fC-^8>
5DET9I
f4Y1A(
8C5^4]
N*B1X5
xA1Y5^
jN%O@*D<=
M[j"="yO8C
585kL4O
Se>-~dq
C6/AAQ
bMh_F_
1p}utE
TJk.Af0
_^4l+,
FE]'Te
D?4Ew#
48OG#C
I]<#lY
<t [-%|
=o6YV
T*P^jov
Wdz8;6
Dy49m+K_
^(5?.W
VZC|A2
ildXCq
y)&_4?
UwYIX5
G27JwT
6II .!
ne|iAI
@X5y+
}M:bL&"
L--U2Z
QI?.\C
R`l(Qz
O0UL(2cH
^{5B|9
D`a~jccT
xC=@H&>
t)d@2M]
Kj_2z"
z06`,T
NdFi;z
0Th/~q&
~[",M2
wOax*[r/u
6|cPsKX
gx6K-<3
;9Hn`='
(mVNZ89?G|
-WoXmg
{00oU2
)}ik{T=
k6GS^~
NHN6](A
|7jf"f
-"ClB;lL
R2y.|7
w#!cK|
z});mSo
te4V#g
P~xc}[b
1x2Dhs
gbt*}O
i!O2yYx8f
.+%u9C
wE7gl
[cM5<!k
m3230&
17xLR#
f{n)QS
5GjVe/L
)bPgp#
X5K9wd1
W#w!~"O
=@:+j'
{)Q9J5
T.5PIjtft
>w51s,
Pv[9=e
FPf6g1
4>>u~{
J#.6fK;
I1,Mj9
-jD,fz7Zc
G10+k/5
rJLI+^%
PX/A!<e
aq.`uX3x
~4<}rGz
@z-{2'
%UY_?;
a<F{rN'
DEfLDBn
lW02($
,rp*S7
s3?b 2p
Twu%*u/
MX4L_X'
ax\\+GvcU7
Be,$dr
%j7P>fI04
$>XW|bY
Rh9G+_
,{|1Po}
_vy,_`
.1&pB9d
V9uI=%
:y2M!]
j7nC~?F
E*ce/<
$PS"i
U:bq2@5
<t{.I4
(@;4aG;|yJ
-I:N>q
RI+#N,U
Id3 .5
\Uah
i8v{8j"[F
m=X-^S
Y~\*p8
&v(\o2jH
kRzRHc
RlwEAfw
Tt<>us
n\bJy#\
9",N5
_<?NM^
HQKhu<
AlC:9
{- 8rR{U
g1Bng
S3mD@U<
=h[WCj:Y
;mYpA7,
k@'R$>
tfK5V&
|sO$w9
r4,[@8
UcB=^1
]GT"OkF0
%7;vkn
!%XBN9lU%
LB6h.SQ
uJ|7M<r
CDNDh<
}8$dLD
p$e3@W
8=].*/
oA3H{}
+mBgu(T
N|uq r
?U{b:
G^yuweu
|Moa.#
Yc &Ft
LSM=|&
A\i/.0s
F0x@`:F
[C_TUO
j6NaLN
W&0-OS7
-wg)l
cls`Ax
O:\c[Ma
,8xPR]
C`e(!=
yhQ`[Sz
M^;)@i$7
8Xn~'
Lu*`~*
e%W)sw
R8b0)aeS
")835d
Zx'Fw\
)vY(A+
1~R^X-
2w{=+uF
Us\~pz
y=oU;_
vXrDg`gT
J;DT9_
QA_VE2
<$YYn~
-YfYN~
1Gw^9tp
b[:}C=
^kUz A;4
3=#q#K
o}0[RT
WIEo_b
s2,?B|V
cS*uCxy
6w=lzV{
.H@s\e
Y5^otX'."
7P|Ilz
Zu>W@5DQBR
~^Eh:K'
wP/TMfX
bq.+f}
J}hPJf
1~6*&N
:]{&86_
~@:mq!
<0T|u
] Qa&0
0yP)&Y.
SWVYK>
M$>JB.
p&rWI}?7
&h<TbH
%x615.
C>l>ed
.B6jrv
xdSJ]$ "f
.$GK<_
\T22@p
CJ&Zxa
en:y{d
n*Y6n.
cFXTP|
B]z(TnJ
5k)$xb
z\[kOA
R5(|sk
o`2yR-
36CN"b?
m'-Z8J8
'*Q\K#
xT,BI!
RLzO.G
!-B7FK
#!6E5*:nXWZ
I`)$t)~Q
WZ1(h<
x-8xSU
3_h*X?
ewaMED
",;p^w
Ld3aUb
Pc\T&c
>%j[Lu
C G|gtd
NRE]T&y
bV"`);y
L(> d=
sg"}6+
Su1\Xy
Tz~^l)]
[aIWR<
RO,Hi|
yl7Bh;wy
"(~nm;
afljeio
BA1J3
T?]OEa4i
Uz6p%KDw!
=Zp_k@
@}:oO,
ff?s~UTW
@`JkyO
~bDtNM
8i'vtQ
pyqWU$Ysl
.D6v&Xk
SvOqb\k
9R8#f~5tA
V.|ti!
]yk>bX
tXR.Yh
NU|)4N
2./=|>
L|->v&c
)bD49N=
9|hb,|#
U]A59RW=
`Z9ZC_;z1B
\L+JZk
0U m4-;
rL/ rQ
Byc.AA
?<-G)Wuc
A&TcL9P
cOp(5-U
a!~,q/
"|CJwb
i"`3kU
37.K E
tLjf<4
i4]g65i
^DTWq0d
Yu7iB93
QydV{G6Pz
fnYvlW
sXpax|
uEP()z
=7'J&'8
1;=7#R4
!()n\L
Ngfc
A_G7{
Tw?E$5.,T
|~m'~{
a,rj4b
qZ<p''
mmNdZ,
<K8uj$u
/ZpO=4
Z.$Y/S6o
L[$l&'
6ZQoXI7B(
U(E0({
L5am{'
@Cb!t/
T32~Rt
=y139(f
g~vXGH
{+/"<
^VBj>v
NfQk{"u
;ERcA3W\P
qK{:fe
S{^Ih$
$01NUs
R@G52]Ws
>$#H U+L
xL"`xr
oO=}a8`
AHJ&1.}
M>`ya_
^N >}_?
=J!4M
hWX|.W
^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+F.^7Z2B+
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
R80KlFF2Ovm27OReE4mckRpstvWRbTf5
R80KlFF2OvkmhiQJL+Rj/BpstvWRbTf5
DynamicDllInvokeType
BQ0NQc3FxfA=
jzBNdS+q3JWrCsEttfDOfw==
Cn0ATuBOWFUfvn+n5DCM52JOERxPgKZ/
w3zXHbTt9/w+MBMSOK9MehpstvWRbTf5
iSer44ERQIk1Xc26uVgQBWljlPxYMWET
wdKV9woTk9aIAjxbvmdhaw==
LevgDj7QSezMkMg7FJChuyV1nFQs0fkC
SetW8bllXm8fvn+n5DCM52JOERxPgKZ/
DT08bHyEE/A+MBMSOK9MehpstvWRbTf5
K8d0KEHaKXaGxOpUBEIr0A==
ojn7Qy76bdarCsEttfDOfw==
mliAtLpVyAoeYWqzg08Wae9rl5qtXVsP
Central Standard Time
Eastern Standard Time
Both are equal
Both are not equal
<html><head>
<meta content='IE=Edge' http-equiv='X-UA-Compatible'/>
<iframe id='video' src= 'https://www.youtube.com/embed/{0}' width='560' height='271' frameborder='0' allowfullscreen></iframe>
</body></html>
Select ProcessorId From Win32_processor
ProcessorId
dddddddddd
Enter Value of N :
America
Australia
Africa
Canada
List before RemoveAt:
{0} : {1}
List after RemoveAt:
Created TimeSpan values:
Hours in TimeSpan:
sdfafd
/csafsf
https://subf.domaffaifn.comd/objecsts.json?api_key=123
{"objeact":{"ffndaf":"Naddfme"}}
https:/f/susb.dofmafin.com/obadjdects.json?api_key=123
{"obfject":{"nfafme":"dNaafme"}}
https:/f/sub.domfain.com/objecadts.json?api_key=123
{"obfject":{"nfafcme":"Naafme"}}
MAINICON
VS_VERSION_INFO
StringFileInfo
000004b0
Comments
This installation was built with Inno Setup.
CompanyName
NordVPN
FileDescription
NordVPN Web Installer
FileVersion
0.0.7.0
LegalCopyright
OriginalFileName
ProductName
NordVPN
ProductVersion
0.0.7.0
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Barys.15006
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Generic
ALYac Gen:Variant.Barys.15006
Malwarebytes Trojan.Crypt.MSIL
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Barys.15006
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AGWQ
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Trojan:MSIL/Kryptik.7bc0a7f3
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.Generic.Qwhl
TACHYON Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Barys.15006
TrendMicro TROJ_GEN.R06FC0WCQ23
Trapmine malicious.moderate.ml.score
Sophos ML/PE-A
Ikarus Trojan.MSIL.Inject
GData Gen:Variant.Barys.15006
Jiangmin Clean
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1305736
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Barys.D3A9E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:Win32/Leonem
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!4EF3BFE67588
MAX malware (ai score=80)
VBA32 Clean
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06FC0WCQ23
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:93uEqFpNURVO90XTKVzW0A)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AEBO!tr
BitDefenderTheta Gen:NN.ZemsilF.36344.sm0@a8d4WhaG
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
No IRMA results available.