Static | ZeroBOX

PE Compile Time

2046-08-20 00:00:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00008994 0x00008a00 5.42887892478
.rsrc 0x0000c000 0x0000bff8 0x0000c000 4.02291680549
.reloc 0x00018000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001748c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000178f4 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001796c 0x000004a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00017e0c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<>c__DisplayClass0_0
<>9__1_0
<PerformSelfDestruct>b__1_0
<ProcessUrls>b__0
<>9__1_1
<PerformSelfDestruct>b__1_1
IEnumerable`1
List`1
Microsoft.Win32
ToInt32
<>9__1_2
<PerformSelfDestruct>b__1_2
g8Ai63
get_UTF8
jTpd39
qF44LE
aauyEF
get_ASCII
System.IO
x0YCiP
zTEYzQ
tEv2GR
qIYrdW
z6TCG_
UploadData
ProtectedData
get_filedata
set_filedata
o4WFCb
vQrvMb
i6gXXb
mscorlib
System.Collections.Generic
Thread
add_DomainUnload
get_IsAttached
System.Collections.Specialized
Synchronized
ProcessCommand
Append
Islagcsnlxjxtmchpwssyd
Replace
CompressionMode
FromImage
get_Message
AddRange
IDisposable
ToDouble
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
DownloadFile
Console
set_WindowStyle
ProcessWindowStyle
get_CPUName
get_GPUName
get_Name
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_FullName
get_UserName
get_name
set_name
get_filename
set_filename
get_Compname
get_Username
DateTime
get_LastWriteTime
get_CreationTime
WriteLine
Combine
Escape
DataProtectionScope
ValueType
SecurityProtocolType
wtfAreYouDoingHere
get_Culture
set_Culture
Capture
ApplicationSettingsBase
Dispose
get_modifiedDate
set_modifiedDate
get_createdDate
set_createdDate
Create
EditorBrowsableState
Delete
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
XmlEnumAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlRootAttribute
XmlArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ToByte
get_Value
set_Value
GetValue
SetValue
Remove
get_Size
get_DiskSize
Serialize
Deserialize
get_filesize
set_filesize
get_Jpeg
System.Threading
get_Encoding
System.Drawing.Imaging
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
FromXmlString
ToString
GetString
System.Drawing
IsMatch
get_LocalPath
GetTempPath
get_Width
get_Length
EndsWith
StartsWith
hC2i3i
lOO2Ei
Impdxecozpztznlyrwhyxk
get_Model
System.ComponentModel
kernel32.dll
System.Xml
set_SecurityProtocol
ProcessUrl
Iudtsrvlqzywjmvgdhqkvl
l1vOOm
GZipStream
MemoryStream
get_Item
OperatingSystem
AsymmetricAlgorithm
TimeSpan
CopyFromScreen
AppDomain
get_CurrentDomain
get_OSVersion
System.IO.Compression
get_Location
get_Information
set_Information
System.Configuration
System.Globalization
System.Xml.Serialization
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
ManagementObjectCollection
IOException
add_UnhandledException
get_ScreenResolution
Iwljpjokuummbberkjgcfo
FileInfo
CultureInfo
FileSystemInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
Bitmap
ToUnixTimestamp
sTxncr
StringReader
TextReader
RSACryptoServiceProvider
RNGCryptoServiceProvider
StringBuilder
Buffer
get_ResourceManager
ServicePointManager
Debugger
ManagementObjectSearcher
UnhandledExceptionEventHandler
System.CodeDom.Compiler
get_Manufacturer
CurrentUser
StringWriter
TextWriter
ToLower
XmlSerializer
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
IntPtr
Graphics
System.Diagnostics
LoadCommands
ProcessCommands
get_commands
set_commands
get_TotalSeconds
GetBounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Minecraft.Properties.Resources.resources
DebuggingModes
Matches
GetDirectories
ExpandEnvironmentVariables
get_Files
set_Files
SearchFiles
GetFiles
ReadFileBytes
ReadAllBytes
GetBytes
UnhandledExceptionEventArgs
get_args
set_args
get_Ticks
Equals
ProcessUrls
System.Windows.Forms
Contains
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
get_Headers
get_Success
Process
get_IPAddress
Compress
set_Arguments
get_Exists
Concat
ImageFormat
Subtract
ManagementBaseObject
ManagementObject
Collect
Unprotect
HandleSelfDestruct
System.Net
get_Height
add_ProcessExit
get_Default
WebClient
System.Management
Environment
get_Current
get_RAMAmount
MakeScreenshot
Encrypt
ThreadStart
Convert
MoveNext
System.Text
ReadFileText
ReadAllText
hIYDIu
Iwerwbxtttuzoxtzdsiceu
get_Now
get_UtcNow
set_CreateNoWindow
zXWltw
nEUpBx
ToArray
get_Key
set_Key
CreateSubKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
BlockCopy
Directory
Registry
op_Equality
op_Inequality
System.Security
IsNullOrEmpty
WrapNonExceptionThrows
3673772352
6602549809
2514488080
7529646457
5682364936
4276273733
$68d5aff3-723f-4739-863f-67b909666c26
66.2.4.5
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.5.0.0
command
Commands
commands
filesize
createdDate
modifiedDate
filename
filedata
information
report
_CorExeMain
mscoree.dll
oecyxd
Q6}H`{{d
2V~.Ih
4P&py
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGX
v@AfI?
fHVfpF#
y'GdBf
zOXqMS
SV"%F\'
@QZJVX
gD9Xuw
YT`eYT`eYT`eYT`eYT`eYT`e
d1Ryi4
igig^
"G4?Py
1A%!D9A#c
M*(85&6.#<
olIfOn
worgQA
a_5v3R
& `$4!
S,5'$!8
% 68,
''e4:*1?
>(2* >
o?=53d$
jU =!a[2>pf9$;
>##!*;
LDykmJB|lhC0
"!),0H{5
EIbC@KeKCL
xQt]uQe
hBsQzMy0*
jAuCt\
jAuCt\
$Q{SeO&
xQwQ{O$
NgAgMy
xQtQ{O$
NgBgMy
xQuQ{O$
{YkzLy\6
xQtQ{O$
NgBgMy
NgBgMy
NgCgMy
5, ),)
NgCgMy
xQuQ{O$
xQuQ{O$
NgCgMy
NgCgMy
{Y6HzLzLzLzLzLzLzLzL
NgCgMy
{YkzLy\6
xQuQ{O$
NgCgMy
NgCgMy
{YkzLy\6
xQuQ{O$
NgCgMy
NgCgMy
NgCgMy
xQvQ{O$
Ng@gMy
Ng@gMy
xQvQ{O$
Ng@gMy
!MeSy\&
p3K_nN
iI7xLt
sM5xqu
yKdMC_
sIy4k8
jbfIO4
xK7ihU
r86,E`0
aBHsYy
K,5e&P-kw.z,55
pkPTBl
nIN8ua
wG9rZI
:u%u*dI
vDj8Qe
hKAqPr
4.Rtg\
?&t(z)&c*
get0bR
e1HiI6
^:f>T 2
xuEaPo
j3ibH9
<INQ@kAKZJ
vBFoYB
HELL YEAH:
FUCK ESET:
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
c5f5db9864b95a21f790ac067329730b16ce8
CompanyName
uc1bd37cb05f34d6e4eaa6318
FileDescription
R03506410ba4d2633f221
FileVersion
7.82.1.58
InternalName
Be4b622b98618b84af2e238f7a59bb057.exe
LegalCopyright
X4d2b409f0ebfa7fb420ed9e9913b89
LegalTrademarks
qf3f7ad0e932d48006ae4da67554867
OriginalFilename
f234b3777c46dccf88f250a.exe
ProductName
ce9868ed79ad76f69bf4a292a177658142fbaca
ProductVersion
26.93.100.65
Assembly Version
75.60.8.9
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Zilla.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan IL:Trojan.MSILZilla.25609
ClamAV Clean
FireEye Generic.mg.cb1ca4cee1049ab3
CAT-QuickHeal Clean
McAfee Artemis!CB1CA4CEE104
Malwarebytes Generic.Malware/Suspicious
VIPRE IL:Trojan.MSILZilla.25609
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.25609
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36344.fm0@aiG!mgh
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stelega.gen
Alibaba Trojan:MSIL/Generic.84c3eb66
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
TACHYON Clean
Emsisoft IL:Trojan.MSILZilla.25609 (B)
Baidu Clean
F-Secure Trojan.TR/Redcap.effgf
DrWeb Trojan.PWS.Steam.35316
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Win32.Outbreak
GData IL:Trojan.MSILZilla.25609
Jiangmin Clean
Webroot Clean
Avira TR/Redcap.effgf
Antiy-AVL Trojan/Win32.Sabsik
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6409
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stelega.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Trojan/Win.Injector.C5404040
Acronis Clean
ALYac IL:Trojan.MSILZilla.25609
MAX malware (ai score=86)
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09D123
Rising Spyware.WhiteSnake!8.17C86 (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/WhiteSnake.A!tr.spy
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
No IRMA results available.