Static | ZeroBOX

PE Compile Time

2023-03-30 13:38:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003a864 0x0003aa00 7.7565722566
.rsrc 0x0003e000 0x00011053 0x00011200 4.99107297824
.reloc 0x00050000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003e144 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x0004e96c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004e980 0x000002ec LANG_TSONGA SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004ec6c 0x000003e7 LANG_TSONGA SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-_&&&&&&~
,;&&&~
,"&&&~
-g&&&~
,[&&&~
,O&&&~
,C&&&~
--&&&sX
,(&&&~
-L&+.~
-V&+(~A
_b`}h
_d}h
__d}h
_b`}h
-d&&&&&
-b&&&&&
Y_bX
Y_cX
Y_bY
Y_bX
Y_bX
-&&&&&
Y_bX
Y_bY
_b`}
,F&&&&&
,&&&&&&
Qkkbal
v4.0.30319
#Strings
fFimSmcakkpAe.exe
fFimSmcakkpAe
<Module>
mscorlib
Object
System
Samfple
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
MemoryStream
System.IO
PoweredByAttribute
SmartAssembly.Attributes
value__
YELLOW
WebClient
System.Net
Dictionary`2
System.Collections.Generic
Assembly
System.Reflection
Version
ModuleHandle
BitArray
System.Collections
set_Item
Console
WriteLine
String
Concat
get_Length
ReadLine
GetHostName
GetTypeFromHandle
RuntimeTypeHandle
GetName
Enqueue
IDisposable
Dispose
Stream
Convert
ToInt32
IPGlobalProperties
System.Net.NetworkInformation
GetIPGlobalProperties
get_DomainName
get_Location
ToString
Exception
get_Message
Contains
ProcessStartInfo
System.Diagnostics
set_CreateNoWindow
Process
set_StartInfo
WebRequest
Create
set_Timeout
set_Method
GetResponse
WebResponse
GetExecutingAssembly
GetDirectoryName
Intern
op_Equality
Directory
get_Chars
Exists
IsNullOrEmpty
EnumerateDirectories
IEnumerable`1
OpenRead
GetManifestResourceStream
Thread
System.Threading
ResourceManager
System.Resources
GetObject
Replace
FromBase64String
Encoding
System.Text
get_UTF8
GetBytes
HashAlgorithm
System.Security.Cryptography
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
Marshal
System.Runtime.InteropServices
SizeOf
ToUInt32
BitConverter
IntPtr
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
.cctor
object
method
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
ParameterInfo
nhffskdsffkdddfdhdafffdddhgfsdscffdf
hkgfsfdffdhfhddfdrfahghddsfshcf
chfddgefffghkdffsfhdddhdshdghf
hfsdkfdhdgfhshsfefdfafffhfdch
fhhfgsfffrfffdkddffcdhghhfashdfh
fchhfgfdghffdadfdfrsfsshdkfffgh
nhffskdsfkhdfdhfrffdhgfscfffdf
hkgfsfffdffddhfhdfhrfahghddsshcf
chfdgehfgfhffdafsfhdddhfdshdghf
hfsdkfdhghffshsfefgfdfaffffdch
fhhfgsdffrfffdkdfcfadhfghfdasdfh
chfrffhfgdgdfadfdfrsfsshdkfffgh
hjafgdfffdgadsfhrfdfffffskhj
fsgfhrgfafddddhdffffkhsjd
fjshdfcadfrgdshfdffgfedfkfghj
sddddffsfheghdfdjfffffgjhskdggsfaafcsafp
sfhjffkfhgfdjsrfhhdfdfhfffadsgfasfhsscffgdb
ddafdrhjfsffffghgdffafcfdssfkfhgj
ffchkfffgahffahfgfrddsfsfj
jffadsfffacgfdgfsdfehfsgkffj
jgacfssafafdghhffffrfdsdgkfff
gdghdfddsffhssfdgh
fhfssdssdfhhffddfhhs
hsfdghsd
fsgdfhsh
shsdsfhdsd
sfsgfhsfh
sdhfdghssf
sddgsffgfs
afgfshgdshs
gfssghfdss
gsafhdsfhs
gfgadffsdg
gsdshffshsg
gdsdhffag
hsghdfdfs
adsghfdfds
jddhgsff
gfhsssfdfh
jfsdsafhg
jffdgshfdgs
jsfsdgf
gdffddj
kfdsjfdggfh
fsfgffdlfg
sfdjdfff
ffsfldgfs
jssldsdsd
jdsdldfssk
gsfffdsds
dfssfddsx
startupInfo
jdfhdfjlddfsgsdkfj
hdfffhfllsassdkfsh
hdffhdffgjldhddfkdf
affdssdhfhh
sdffsfffdhf
hffdhs
hhfffgsfhh
jffsfdfdh
MoveFileEx
kernel32
ResolveEventArgs
assemblyFullName
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
codeLengths
pending
minCodes
maxLength
buffer
IsWebApplication
AvailableBits
AvailableBytes
IsNeedingInput
TotalOut
IsFinished
BitCount
IsFlushed
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
{369592d9-2176-446a-8dd6-f96896f51ed5}
{a4bd9aab-a80e-4433-aedb-e3a6117765ad}
Boolean
TimeSpan
get_TotalHours
Double
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
Resize
RuntimeEnvironment
GetRuntimeDirectory
Combine
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_ParameterType
GetCurrentProcess
get_MainModule
ProcessModule
get_ModuleName
ToLower
ResolveEventHandler
add_AssemblyResolve
get_Name
ToBase64String
IndexOf
Substring
Monitor
ContainsKey
get_Item
GetTempPath
Format
CreateDirectory
DirectoryInfo
OpenWrite
FileStream
LoadFile
FileLoadException
BadImageFormatException
StringBuilder
Append
op_Inequality
StartsWith
ResolveTypeHandle
GetFields
FieldInfo
BindingFlags
MemberInfo
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetModules
Module
get_ModuleHandle
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
add_ResourceResolve
GetManifestResourceNames
StackTrace
GetFrames
StackFrame
get_Assembly
TryGetValue
GetPublicKey
RijndaelManaged
CreateEncryptor
DESCryptoServiceProvider
GetCallingAssembly
FormatException
get_Position
DateTime
get_Now
get_Year
get_Month
get_Day
get_Hour
get_Minute
get_Second
UInt32
SeekOrigin
set_Position
InvalidOperationException
ArgumentOutOfRangeException
WriteByte
ReadByte
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
MAmibS
1*Mut#
K2KnT}
fQb{hN
cNW L&
BmWwrt{
D>Nztq
k9@;{y
<r.idt
wcYuF
VAo}kL
K8az9-r
m_2ZfS
Xd!,%gRd8
CGc:$.
Y]x]0P7
8J?YvZ
~|7*PV
{m0Z33F
XXQ$<x
r8,vY[
die#C~
dihw2MP
s%3U_0
)fdpW(<`
5-(Qvr
F~Rwz
4BUm\Zc
mJ9HsQ<
s5Q"?z\
aXS"r+X
VB)u#G
\uQ]{Ca
,xLn/]
BjTfBp
u1kx-F
#+akEm
Eop=X~
b#a+qH(
vs-HT(
oLg!y"
'N:hYB"
P3~k5Tk
G2N2{.
-<h?wz$
}nkr<ip
x/r0x_
eH&>>d
<sdyY%
xF&rCZ
5kC,51z
n^wAP>
_!FLy$
C?7FNw
`"Zz=GU` pF
a[pyW3l
|>Nu/qJV
IKsM/5?
n@Ayu=
B=O`fQ
$?!@ o
Ms0a&d
T-(7_Q
\6?bqc(V
SaG=)-
_oMhGg
*yp/E{
P*RT-M
>h7MC-u
cc-?P'
a@Wk(%2K|C
Z^A6kG
@-A!u<
D#Cj4{
3vDj(c
@QOX.qD&:
M'faGze[
vhNbf,q
;s%+.B
v%)09V+s
WG2cutT
y^~>5f
NQ%eB`
&fL0B^
|>ljI-$
RF5!n3
pKPFuv
$z^QfSU
<<m7UC
8!Ms@j+M'v
Pzv17[
U E5S&
'0_-$e%
YlT"L+
yo`2aO
M7UJ_\
[#bQ7`^
?J8HJ;
f\^,3,
15e,"\
`zO#Y1
<jJ}La}
SOu)`kY
b}95D.
9gq}21
esrTm-tX
aUPSB+G.:
s4z1Wg
CfJxRb
A^$v/'
k5ad+;
W4%-xs
^Z2#oU
ky19t)
i#OJNN
^d$}h.C
O[Ds-F
"GMGo#
9)\Yu/
sjzsS#
sZsmJE
3%mN_*0kr
D{H{K$s
V IR|=
D5/Dyy
.s[;FW8~
vk(UA
6fHG73
BUj#k7
FcE=dj
l8IcKO
B4"ndN
dX)3s@
E\K|E+z*
%e/jtZ
)uI,Dn
pH5!Ku
T5.R`u
YR#Kj1V)
a1L.c#
D19l/\
N6Y_7
RVZq>V
w,Pz#v
#f+ch0
y1sz1^
8D}N{^
LtV;RE6
S{9D~[
.fI<,i
fuxWjS
f#K,J(*
CN=nX[
"7fJ3bM
k+u5-A
c}'/,}
mpY>QF
qpGU"<
v[)z3G
}&rv=.
Dc(LY9)(
wb{p\&K
I0["`Y
.}H_s:I;sS
vP_d{
,gT%c}
9}~T8`
c_]B.F
.D<[(Yj
}~mSY+
_B|&YJ
ZUg6Uy
u8"t,^U.
7Qe3Od
5:{R?yS
mu_]:`
!|1C%I
iV^$%A&T
Em%Fwx
a4)C&T
(#~6JjH
].|u!#|
xseVLg
5%Lc-2P~
xLH.UM
WPYk"M
Yea)SDU
4{BArM
n6R'4
Ek*#="
,TbsHB
/}g@R(8#8
\-lW2a
P$Q<%,
CRHVx?
Ff:V,$
~:T@6,L)
NFM,fW
FK*w.6
*qM~Pt
o~c;1oq\l
pQ~rlj
`P~^=k
iT4b1<
6 }Qinh
}2"ZJU
LR5Q_Pz
w"vW-q
}6C.5?
A!QNK"
@Aid5*d
65K*IOQ
)+Ihnt:
8nG~OQ
8;A+j
65gWZ]
acm,lLfbn
d4eLu{.&
nW~:@sZS
v 5a;T|
p]>Mry
C ($+<
&;4N3Vx
5?T]f#
%hX~XPs
.d%K0O-%
l0M7iK
zgoB[bZ
k.c@?<
ib]1sdf
oyP8QN/i
ED8(ad
W>N+z#
sMg=~\
yjVmA+
1h5}.tP
Z'HU<E)
17_LItO
)[!;+F
Q>wd8v
n7!+;A
7Q?B$h
5+(0L?'
R)M(w%D
hR2]>
4W$w,Vk8`
" Ia26
$Vn:"
@R=pD'
E=oGMr
wiv3w8c
uJ"CK;
fNlRor
/TE<ZV
Gn:4$m
dc}'iR
_PR8*%
|MTP?L-
-j]kbz
;6]0Zh
_E7l;>"=I
6256$-
w-`8.pW
75aR0\
yn6$p.#c
we}#*h
]C}k3]
yNLU7-D
i1?Rh1
<-AUaKo
uqnA}I
Nl.+i`]
LB91)<,
,EJ~)h&#GD
EhE5{^
MciqIj
ethH>s
!;-^YOYwI
ZD5*Zmy$s5
!S{qE2
]<0SrL@
_\N&:j
Vj?3}
cp`M8YM
xP4-'Nt
px]09,
T~<L@y
)_U@WSc1
hDL0!v
/>YtGn
9iD'*w
iN^:n}
QbV"?DE
u151X7
z%B/G&8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
+*76?>@>A>B>C>D>E>FEG>H>I>KJLJMJNJOJPJ
w3wp.exe
aspnet_wp.exe
e2JiNzFjZDYzLTQyYWItNDk4Mi1iYTI0LTVlMmRiZWQwZmE3OH0sIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49M2U1NjM1MDY5M2Y3MzU1ZQ==,[z]{369592d9-2176-446a-8dd6-f96896f51ed5},e2JiNzFjZDYzLTQyYWItNDk4Mi1iYTI0LTVlMmRiZWQwZmE3OH0=,[z]{369592d9-2176-446a-8dd6-f96896f51ed5}
{0}{1}\
, Version=
, Culture=
neutral
, PublicKeyToken=
Version=
Culture=
PublicKeyToken=
{bb71cd63-42ab-4982-ba24-5e2dbed0fa78}, PublicKeyToken=3e56350693f7355e
{a4bd9aab-a80e-4433-aedb-e3a6117765ad}
Wrong Header Signature
Unknown Header
{data}
ERR 2003:
https://subf.domarffaifn.comd/objecsts.json?api_key=123
{"objeact":{"ffndraf":"Naddfme"}}
https:/f/susb.dofmarfin.com/obadjdects.json?api_key=123
{"obfject":{"nfarfme":"dNaafme"}}
https:/f/sub.domfarin.com/objecadts.json?api_key=123
{"obfject":{"nfrafcme":"Naafme"}}
{71461f04-2faa-4bb9-a0dd-28a79101b599}
MAINICON
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Nero AG
FileDescription
NeroInstaller
FileVersion
2.1.1.7
InternalName
NeroInstaller.exe
LegalCopyright
(c) 2015 Nero AG and its affiliates
OriginalFilename
NeroInstaller.exe
ProductName
NeroInstaller
ProductVersion
2.1.1.7
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Heracles.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Marsilia.34054
ClamAV Clean
FireEye Generic.mg.dce62039df2bafb6
CAT-QuickHeal Clean
McAfee Artemis!DCE62039DF2B
Malwarebytes Spyware.RedLineStealer
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 0059df7d1 )
BitDefender Gen:Variant.Marsilia.34054
K7GW Trojan ( 0059df7d1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Stealer.75e87a5e
NANO-Antivirus Trojan.Win32.Stealer.jvhmua
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:JAKixoaBYl/lPImAACZgnA)
Emsisoft Gen:Variant.Marsilia.34054 (B)
F-Secure Trojan.TR/AD.RedLineSteal.jqrxk
DrWeb Trojan.PWS.Steam.35300
VIPRE Gen:Variant.MSILHeracles.74130
TrendMicro TrojanSpy.Win32.REDLINE.YXDDAZ
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Spy.AgentTesla
GData Win32.Trojan-Stealer.Cordimik.4CNB1M
Jiangmin Clean
Webroot Clean
Avira TR/AD.RedLineSteal.jqrxk
MAX malware (ai score=85)
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Trojan.Win32.Kryptik.cl
Xcitium Clean
Arcabit Trojan.Marsilia.D8506
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:MSIL/Redline.R!MTB
Google Detected
AhnLab-V3 Clean
Acronis suspicious
VBA32 TScope.Trojan.MSIL
ALYac Gen:Variant.MSILHeracles.74130
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDDAZ
Tencent Msil.Trojan-Spy.Stealer.Xtjl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ADWG!tr
BitDefenderTheta Gen:NN.ZemsilF.36132.tm0@aSffKTaG
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.