Static | ZeroBOX

PE Compile Time

2091-11-23 23:03:53

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000ed94 0x0000ee00 6.16662250803
.rsrc 0x00012000 0x000006b0 0x00000800 3.87088393713
.reloc 0x00014000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000120a0 0x000003aa LANG_NEUTRAL SUBLANG_NEUTRAL Dyalog APL workspace 32-bit classic big-endian version 52.0
RT_MANIFEST 0x0001244c 0x00000264 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
^&]E@B
34@kksz
y!\4fz
\`JCN]Z?
iri=WO
Rp>M4lK
Srv\'G
/0Xd)0
/0Xd)0
GNI3x
:OHamj
?"Za8M
^6wZ n
Z 8h@Qa8E
Z Z=Eaa8l
,8a8
7a%&8x
.<sjZa8f
uZ c&_
4l_Z (
1?SZ 76
Z >R7ja8
Z z%Z0a8<
XU0:+
Z 5)ina8.
OuZ 7<
_bj2
_bY*
HrG7a%
kxia8u
|l}>Z 1
h#6a8:
0o:9%&8
ue|&%&89
m]=EZa8
0o:9%&8(
@vG%&8
Z_bX
Z Bew;a8.
j`%&8D
"Y['Z
$8`b+
Y_cX*
eMZa8c
a[Z .)\
TZ 93ima8l
/=%l%&+
fZ v=`%a8u
`M`Z !w
,: &H.
)IAsZ
i3rZ+
eJTs8E
,: :{A
& qF2)8
& \5yu8
66Lb HSLRa%
Eo> HSLRa%
-<6?%+
Eo>%&8[
e) HSLRa%
PZ W;H]a+
2 HSLRa%
1;DM%+
s(rKZ .9k
j1R B#!
v4.0.30319
#Strings
yL(L:Ro%n}x1CW!s*\twbWW^,
_)Fc1W!$Xi5N2sLvaPq2Fimg-
IEnumerable`1
List`1
UInt32
ToInt32
get_UTF8
<Module>
System.IO
zKijzSoQJhiygjgBJRLPDcUtzHkR
mscorlib
set_Verb
System.Collections.Generic
DownloadFileAsync
get_CurrentThread
thread
RijndaelManaged
get_IsAttached
Synchronized
set_IsBackground
GetMethod
distance
CreateInstance
set_Mode
set_AutoScaleMode
FileMode
PaddingMode
CryptoStreamMode
CipherMode
Invoke
Enumerable
IDisposable
Double
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
set_WindowStyle
ProcessWindowStyle
get_Name
set_Name
get_FullName
get_ProcessName
WriteLine
ValueType
SecurityProtocolType
GetElementType
System.Core
MethodBase
ApplicationSettingsBase
Dispose
TryParse
Reverse
Create
EditorBrowsableState
posState
Delete
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
Task24Main.exe
set_BlockSize
inSize
set_ClientSize
outSize
windowSize
dictionarySize
System.Threading
set_Padding
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
ToString
GetString
System.Drawing
IsMatch
GetTempPath
GetFolderPath
get_Length
System.ComponentModel
set_SecurityProtocol
ContainerControl
FileStream
inStream
CryptoStream
outStream
MemoryStream
stream
get_Item
System
SymmetricAlgorithm
Random
ICryptoTransform
IsLittleEndian
Task24Main
AppDomain
get_CurrentDomain
set_ShowIcon
Application
System.Configuration
System.Globalization
System.Reflection
ManagementObjectCollection
Intern
MethodInfo
FileInfo
CultureInfo
FileSystemInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
System.Linq
set_ShowInTaskbar
RNGCryptoServiceProvider
SpecialFolder
sender
rangeDecoder
Buffer
ResourceManager
ServicePointManager
Debugger
ManagementObjectSearcher
ResolveEventHandler
System.CodeDom.Compiler
IContainer
StreamWriter
TextWriter
BitConverter
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
yL(L:Ro%n}x1CW!s\*\\twbWW^\,.resources
_)Fc1W!$Xi5N2sLvaPq2Fimg-.resources
DebuggingModes
Task24Main.Properties
properties
EnableVisualStyles
GetProcesses
numPosStates
set_Attributes
FileAttributes
Rfc2898DeriveBytes
GetBytes
Settings
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
System.Windows.Forms
set_AutoScaleDimensions
System.Text.RegularExpressions
RuntimeHelpers
FileAccess
GetCurrentProcess
numTotalBits
numPosBits
numPrevBits
set_Arguments
Exists
Concat
ManagementBaseObject
ManagementObject
System.Net
WaitForExit
SetCompatibleTextRenderingDefault
WebClient
System.Management
Environment
get_Current
ParameterizedThreadStart
Convert
FailFast
SuspendLayout
ResumeLayout
MoveNext
System.Text
set_Text
set_CreateNoWindow
startIndex
InitializeArray
ToArray
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
CreateDirectory
set_Opacity
op_Equality
op_Inequality
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
Programs Engine
Microsoft
Windows
Copyright
2021
$d45ad80b-f521-49c4-8aea-bfca2f21b9bf
10.0.19041.746
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.4.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
</application>
</compatibility>
</assembly>
ZpTjumfXo5+tzpt3M2tIElPV6apngu2OFfAgK8Lnf8/ocdgY/PH35lnQMNwI+WMiHONFWDmIXzwiPMa20mfIzmiWXKqy1DMYdm/pT2HPKiKmYnpndCVdDzcs9ck8jsHgnKCw8fE6vbeLz4txNGUVkQfyUQ9dlBNGNC1pcBZIApg=
gf0+QPM2uOnFJzrXkou5As70Ejpt0H9g4SQnRNQq6QojDlEoCrfbhDcg7GAAHX0fX6voW8En1odN/7FiCFGRf9Pq59Ycf8H2EFUGB8IpcXzigJJTtVU4QDOFuWDBzwxj0DW1bUkk0AVxRrwFduXUXF8ZpMvmW3ziVR5jInFix34=
o4yKaq38xcMvigAZGiFMLT5PqlFEwJhfYshZ8Kep8dIVwYzTlR4XFRbYelFE13MKdBwLrm8w/HcyMP3q4IXyU7Ezelu8dMCL5OXY0+Vy6Y1ikw1+6foAjoOscUWIDsgP
503/8J4CNbeXofXyWeUFsoLhkpa4OnFmp4TBvrl9OFO9hNy38DteHsJs8Vh8/IL0CbvZZaoVT1bhoWVLx7XjnOBdUAXEH3JORAREX+c/SbGV9qnCb10MHoVLRvmst/xi
qVAU+p9WavvMDlo5pTEPs05FmARe4jFJT+AOkrouW06gvQ3/QK9cIpPNtKI1lIMAxdqCW/+qVnKIqC1d7M29ACYte/BzDIBx2yApBwkoIWoHvX+PJnC2CXxdoa3IAP0m
KyAcILKIDZtz31K8Jn70CoWsEBerPNN+MLjZPIpg//1VVaM5AmugvcRiKGwKVJy5mxmcaq7SqRRKWR3+KDXYhAAX++OGGDFQej21DtvbVYdSKVhdvoO5u15lcdrbZOfZshidniZclJsg313SoyvT1G4NjQaAbYkI7FNUGKbQbAr8JTv75SSFDBOf/UoIQBNmzCXAKyLVlngk7iXs5WtFPg==
56NDcn7Pw1BpNiOhQZTETKrVvfzNBE2fh3I7yQaLUOm6TTLX+px6GNtdyIA/umF3AizZUbO08tFZ6ZmMRRt0zekfquvbALa5X2FGZ3PmURedh/VMLQSxleIq1aUmAKkKGMiCSq7XtrnY/vFt7UZWoIIMX+M1O+Y8jQzU2zwp/IcI6FxJKiM8KZekycfFTJqtc9VnABv3VwM0N/gpjKVYJw==
fuBE9m6Kqic9ontaciYGZVYuxjhOuhZSKxoXX+e+dBFb5o0vNBKV3dnJjFIl/I5qyH6+bHVMUluQJswYAuPSBZtWj25yvtNekEFpdb9/eANsS5NBtdZbWq/ETSlmlpOdWEt5HX3LWsVjrR6p3SC04i2xM3oqrjzdpXqopPUiwqdUa7RX+DyL2sqa/YOWCqGiNKlC5ehBwhA685bcuJC9jQ==
gYiUf6o11PSJN2f1Nzl+4UID9PNFP/3xCnhNMR0g5CEYl4xpFXmKEjgBME5B2TF0q7yP4r7I91d+/gbPWfQpBMh2FnDKfSUaf+AytTYA/yZOtjuX00GZjrdqps4widUm
phXrTsnyr3wNVAxiUM9+rDleZq2s2LB9R6oTYrqBXf7NJK6ThGnYn7tJym1OUfIQBrdJGeXsTMW0n9ORA4gBsmYibPgp9ACv+Q3Jr5bhgzejlqo46TK68bt0F5SUEMQh
IeSWvuwD)
task24
dllhost
conhost
C:\ProgramData\SystemFiles\
C:\ProgramData\Dllhost\
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Programs Engine
CompanyName
Microsoft
Windows
FileDescription
Programs Engine
FileVersion
10.0.19041.746
InternalName
Task24Main.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
Task24Main.exe
ProductName
Programs Engine
ProductVersion
10.0.19041.746
Assembly Version
10.0.19041.746
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Evader.4!c
tehtris Clean
DrWeb Trojan.MinerNET.25
MicroWorld-eScan Gen:Variant.Lazy.321759
ClamAV Clean
FireEye Generic.mg.09a29f3b529c5e9a
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
McAfee Artemis!09A29F3B529C
Cylance unsafe
VIPRE Gen:Variant.Lazy.321759
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0058f7721 )
BitDefender Gen:Variant.Lazy.321759
K7GW Trojan ( 0058f7721 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36132.dm0@aCDig9h
VirIT Clean
Cyren W32/MSIL_Kryptik.HRL.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Agent.VFA
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.MSIL.Evader.gen
Alibaba Trojan:MSIL/CrimsonRAT.347c276d
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Agent!8.B1E (CLOUD)
Sophos Mal/ILAgent-B
F-Secure Heuristic.HEUR/AGEN.1310939
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0DCV23
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Lazy.321759 (B)
Ikarus Trojan.MSIL.Agent
GData Gen:Variant.Lazy.321759
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1310939
MAX malware (ai score=85)
Antiy-AVL Trojan/MSIL.Evader
Gridinsoft Trojan.Win32.Agent.cl
Xcitium Clean
Arcabit Trojan.Lazy.D4E8DF
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Evader.gen
Microsoft Trojan:MSIL/CrimsonRAT.MBAT!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5364961
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Lazy.321759
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Trojan.Crypt.MSIL
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DCV23
Tencent Msil.Trojan.Evader.Bdhl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet MSIL/Agent.VFA!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.