Static | ZeroBOX

PE Compile Time

2046-08-20 00:00:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00008734 0x00008800 5.42700216571
.rsrc 0x0000c000 0x00000744 0x00000800 4.57000108743
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000c0a0 0x000004b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS
RT_MANIFEST 0x0000c558 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<>c__DisplayClass0_0
<>9__1_0
<PerformSelfDestruct>b__1_0
<ProcessUrls>b__0
<>9__1_1
<PerformSelfDestruct>b__1_1
IEnumerable`1
List`1
Microsoft.Win32
ToInt32
<>9__1_2
<PerformSelfDestruct>b__1_2
get_UTF8
ncDzF9
fbSYpE
get_ASCII
eK83UK
System.IO
naRu6Q
xT1jmR
UploadData
ProtectedData
get_filedata
set_filedata
mscorlib
System.Collections.Generic
jkwkMd
Thread
add_DomainUnload
System.Collections.Specialized
Synchronized
ProcessCommand
Append
Replace
CompressionMode
FromImage
get_Message
AddRange
IDisposable
ToDouble
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
DownloadFile
Console
set_WindowStyle
ProcessWindowStyle
get_CPUName
get_GPUName
get_Name
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_FullName
get_UserName
get_name
set_name
get_filename
set_filename
get_Compname
get_Username
DateTime
get_LastWriteTime
get_CreationTime
WriteLine
Combine
Escape
DataProtectionScope
ValueType
SecurityProtocolType
wtfAreYouDoingHere
get_Culture
set_Culture
Capture
ApplicationSettingsBase
Dispose
get_modifiedDate
set_modifiedDate
get_createdDate
set_createdDate
Create
EditorBrowsableState
Delete
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
XmlEnumAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlRootAttribute
XmlArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ToByte
get_Value
set_Value
GetValue
SetValue
Remove
get_Size
get_DiskSize
Serialize
Deserialize
get_filesize
set_filesize
msY9Yf
get_Jpeg
System.Threading
get_Encoding
System.Drawing.Imaging
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
FromXmlString
ToString
GetString
System.Drawing
hx2Tug
IsMatch
get_LocalPath
GetTempPath
get_Width
get_Length
EndsWith
StartsWith
mIpIUj
o2aA7l
get_Model
System.ComponentModel
System.Xml
set_SecurityProtocol
ProcessUrl
GZipStream
MemoryStream
get_Item
OperatingSystem
Isfzhpzhchmysnfbkmcjgm
AsymmetricAlgorithm
TimeSpan
CopyFromScreen
AppDomain
get_CurrentDomain
get_OSVersion
System.IO.Compression
get_Location
get_Information
set_Information
System.Configuration
System.Globalization
System.Xml.Serialization
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
ManagementObjectCollection
IOException
add_UnhandledException
get_ScreenResolution
FileInfo
CultureInfo
FileSystemInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
Bitmap
ToUnixTimestamp
yMlC8q
jLDjGq
StringReader
TextReader
RSACryptoServiceProvider
RNGCryptoServiceProvider
StringBuilder
Buffer
get_ResourceManager
ServicePointManager
ManagementObjectSearcher
UnhandledExceptionEventHandler
System.CodeDom.Compiler
get_Manufacturer
CurrentUser
StringWriter
TextWriter
ToLower
XmlSerializer
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
Graphics
System.Diagnostics
LoadCommands
ProcessCommands
get_commands
set_commands
get_TotalSeconds
GetBounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Minecraft.Properties.Resources.resources
DebuggingModes
Matches
GetDirectories
ExpandEnvironmentVariables
get_Files
set_Files
SearchFiles
GetFiles
ReadFileBytes
ReadAllBytes
GetBytes
UnhandledExceptionEventArgs
get_args
set_args
get_Ticks
Equals
ProcessUrls
System.Windows.Forms
Contains
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
get_Headers
get_Success
Process
get_IPAddress
Compress
set_Arguments
get_Exists
Concat
ImageFormat
Subtract
ManagementBaseObject
ManagementObject
Collect
Unprotect
HandleSelfDestruct
System.Net
get_Height
add_ProcessExit
get_Default
WebClient
System.Management
Environment
get_Current
get_RAMAmount
MakeScreenshot
Encrypt
ThreadStart
Convert
MoveNext
System.Text
ReadFileText
ReadAllText
Igsmdlzaqqrhqxzuelnxlv
get_Now
get_UtcNow
set_CreateNoWindow
Iuoblmcmyodghsfgagdolx
ToArray
get_Key
set_Key
CreateSubKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
BlockCopy
Directory
Registry
op_Equality
System.Security
IsNullOrEmpty
Itmtbxmdrhmicvylmmieuy
WrapNonExceptionThrows
3673772352
6602549809
2514488080
7529646457
5682364936
4276273733
$68d5aff3-723f-4739-863f-67b909666c26
66.2.4.5
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.5.0.0
command
Commands
commands
filesize
createdDate
modifiedDate
filename
filedata
information
report
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
yosaqWy
7>f`sQwihaoWy
fYYFQA
lloNFW
sidC0O
h8En2q
S' ]NP<4
f9wj0K
ld6Wm2
pPrROM
"$/>=<
'+'Q&#?&(-
7U+B?45B
P,/((?V5*=U5.8
29/%'
<XPYB(
S$<$/YB
[QJ?6,.
ZsV|_|[r_r
bEPgAV
LxGV`Y]
.^FoWPf)9
.^FoWPf)9
>E_iQH<
,LVmE_u
I}UCwM
\k@Va[
:ZCxSJc
,LVoE_u
aMO%NKcH
\k@Va[
tSE}Y](
tSE}Y](
tSD}Y](
I}WCwM
bEQkOH>
I1IBvB=
,LVoE_u
:ZCySJc
:ZCySJc
O`X^vNK`X^vNK`X^v-^,[N:
:ZCySJc
\kAVa[
tSD}Y](
tSD}Y](
,LVoE_u
:ZCySJc
:ZCySJc
:ZCySJc
bERkOH>
:ZCzSJc
I}TCwM
,LVlE_u
I}TCwM
t_gaIq
islW_E
zhIjm1
ePwU8f
swFRm8
"K78v!g<
qj9lGk
l44t9A
%s:s5bVx
0d9{VaXE
kRtBYG
nGOUQe
i72I91
lswYK7
xrQsOn
iwh8zp
qclMfR
mbliwi
ozh1Aw
uOEXLa
nETfXZ
pBTaMX
m7m2CQ
wcz8wV
f2pCYf
fZ57QK
kl1QjK
mINg]FpZN
dKRM7F
HELL YEAH:
FUCK ESET:
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
zb35ddcdfc3e7a61cb6f3f091f478666f4c1aec
CompanyName
W8c96546bfacf48d56eb9c8574314af7c
FileDescription
h824351cdcc540b95f74b
FileVersion
94.37.63.3
InternalName
M37e144d00dc96b3b6f6205c8fa47da7aef977a.exe
LegalCopyright
Jc5af40615c27a32d1a67ce2dc58e
LegalTrademarks
O768cf5277f4189f5dc18312314636499
OriginalFilename
t5a3fcd1dad0d8964b08f36.exe
ProductName
ode20f490e6cd151b94883ef09e1c996b2a
ProductVersion
6.1.67.43
Assembly Version
80.10.59.25
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Stelega.4!c
tehtris Clean
MicroWorld-eScan IL:Trojan.MSILZilla.25609
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!943D66043301
Malwarebytes Generic.Malware/Suspicious
VIPRE IL:Trojan.MSILZilla.25609
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.25609
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stelega.gen
Alibaba TrojanPSW:MSIL/Stelega.88972aab
NANO-Antivirus Clean
ViRobot Clean
Rising Spyware.WhiteSnake!8.17C86 (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PWS.Steam.35299
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Generic.mg.943d66043301745e
Emsisoft IL:Trojan.MSILZilla.25609 (B)
Ikarus Trojan.MSIL.Spy
GData IL:Trojan.MSILZilla.25609
Jiangmin Clean
Webroot Clean
Avira TR/Redcap.jikds
MAX malware (ai score=80)
Antiy-AVL Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6409
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stelega.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac IL:Trojan.MSILZilla.25609
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CD123
Tencent Msil.Trojan-QQPass.QQRob.Hflw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/WhiteSnake.A!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36344.cm0@aC5Ymsb
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
No IRMA results available.