Static | ZeroBOX

PE Compile Time

2046-08-20 00:00:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000089c4 0x00008a00 5.44724609836
.rsrc 0x0000c000 0x00000728 0x00000800 4.59457574393
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000c0a0 0x0000049c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000c53c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
<>c__DisplayClass0_0
<>9__1_0
<PerformSelfDestruct>b__1_0
<ProcessUrls>b__0
<>9__1_1
<PerformSelfDestruct>b__1_1
IEnumerable`1
List`1
pHrB12
Microsoft.Win32
ToInt32
<>9__1_2
<PerformSelfDestruct>b__1_2
get_UTF8
wN_4f9
azG8yD
get_ASCII
pSGP3M
lluwqM
ssN12N
System.IO
lwRbqO
jM3WUT
izP3yW
enY6kY
crSPPa
UploadData
ProtectedData
get_filedata
set_filedata
Ipiaopebuixuwkimbreqwa
mscorlib
System.Collections.Generic
gFFrBd
Thread
add_DomainUnload
get_IsAttached
System.Collections.Specialized
Synchronized
ProcessCommand
Append
Replace
CompressionMode
FromImage
get_Message
AddRange
IDisposable
ToDouble
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
DownloadFile
Console
set_WindowStyle
ProcessWindowStyle
get_CPUName
get_GPUName
get_Name
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_FullName
get_UserName
get_name
set_name
get_filename
set_filename
get_Compname
get_Username
DateTime
get_LastWriteTime
get_CreationTime
WriteLine
Combine
Escape
DataProtectionScope
ValueType
SecurityProtocolType
wtfAreYouDoingHere
get_Culture
set_Culture
Capture
ApplicationSettingsBase
Dispose
get_modifiedDate
set_modifiedDate
get_createdDate
set_createdDate
Create
EditorBrowsableState
Delete
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
XmlEnumAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlRootAttribute
XmlArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ToByte
get_Value
set_Value
GetValue
SetValue
Remove
get_Size
get_DiskSize
Serialize
Deserialize
get_filesize
set_filesize
get_Jpeg
System.Threading
get_Encoding
System.Drawing.Imaging
IsLogging
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
FromXmlString
ToString
GetString
System.Drawing
IsMatch
get_LocalPath
GetTempPath
get_Width
get_Length
EndsWith
StartsWith
Ixuqqlgbllvxeguqeugitj
get_Model
System.ComponentModel
kernel32.dll
System.Xml
set_SecurityProtocol
ProcessUrl
GZipStream
MemoryStream
get_Item
OperatingSystem
AsymmetricAlgorithm
TimeSpan
CopyFromScreen
AppDomain
get_CurrentDomain
get_OSVersion
System.IO.Compression
get_Location
get_Information
set_Information
System.Configuration
System.Globalization
System.Xml.Serialization
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
ManagementObjectCollection
IOException
add_UnhandledException
get_ScreenResolution
FileInfo
CultureInfo
FileSystemInfo
set_StartInfo
ProcessStartInfo
DirectoryInfo
Bitmap
ToUnixTimestamp
Inrznwjnwejvizimqbvcar
StringReader
TextReader
RSACryptoServiceProvider
RNGCryptoServiceProvider
StringBuilder
Buffer
get_ResourceManager
ServicePointManager
Debugger
ManagementObjectSearcher
UnhandledExceptionEventHandler
System.CodeDom.Compiler
get_Manufacturer
CurrentUser
StringWriter
TextWriter
ToLower
XmlSerializer
IEnumerator
ManagementObjectEnumerator
GetEnumerator
RandomNumberGenerator
.cctor
IntPtr
Graphics
System.Diagnostics
LoadCommands
ProcessCommands
get_commands
set_commands
get_TotalSeconds
GetBounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Minecraft.Properties.Resources.resources
DebuggingModes
Matches
GetDirectories
ExpandEnvironmentVariables
get_Files
set_Files
SearchFiles
GetFiles
ReadFileBytes
ReadAllBytes
GetBytes
UnhandledExceptionEventArgs
get_args
set_args
get_Ticks
Equals
ProcessUrls
System.Windows.Forms
Contains
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
get_Headers
get_Success
Process
get_IPAddress
Compress
set_Arguments
get_Exists
vI0NBt
Concat
ImageFormat
Subtract
ManagementBaseObject
ManagementObject
Collect
Unprotect
HandleSelfDestruct
System.Net
get_Height
add_ProcessExit
get_Default
WebClient
System.Management
Environment
get_Current
get_RAMAmount
MakeScreenshot
Encrypt
ThreadStart
Convert
MoveNext
System.Text
ReadFileText
ReadAllText
Ieqfxjtwazdqtcqykxbxbu
qClYsu
get_Now
get_UtcNow
set_CreateNoWindow
Ibtvnxdoznkazlqiowijtw
r1ddSx
vPmpmx
ToArray
get_Key
set_Key
CreateSubKey
RegistryKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
BlockCopy
Directory
Registry
op_Equality
op_Inequality
System.Security
IsNullOrEmpty
WrapNonExceptionThrows
3673772352
6602549809
2514488080
7529646457
5682364936
4276273733
$68d5aff3-723f-4739-863f-67b909666c26
66.2.4.5
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.5.0.0
command
Commands
commands
filesize
createdDate
modifiedDate
filename
filedata
information
report
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
rnDbh@r~Wr(
<?QcjF|h_bv@r~Wr
iHD4xq
cTTdhl
4,~34y5&
YWYWYWYWYWYWYWYW
;OfY,Y(
X.b<k@
o6FmkS
;M|6,I4
u4gufy
jh1CVz
eXUbhn
dhL0qR
pYqNca
V$"_.86
R{,,2$
2]'?A'
2!V8#4b]U
V3 7&!
87*%&9
',d40(
=+Ui*($$19
W <3b;0mS]
W]FLwTQ_EO}&$*CA4%
empxGg
Up[~y~Vv]x
dBiNON
DCJM
@S3~<1S
VLMCA
TN^CA
TN^CA
TNGe8v"2b$u9.uNo
TN^CA
TN^CA
&QRU>
@N^CA
O]lA@LMCA
PLMCA
U@LMCA
U@,5Q
TN^CA
]LMCA
VLMCA
U@,%E
ZLMCA
GLMCA
ZLMCA
]LMCA
^LMCA
U@,'H
]LMCA
@N^(\
yoDWwc
b7MZPK
9'LUU$'[
,1ou!<
hqCE36
u8ALXs
G4p!~>
uGbMD7
rDfim9
97&7)&J!
R, %?J%
J%"787J6
t_zuPV
iUliku
xEatQe
vjPEpG
<$EmG|
*9/'L<98%"M
&wUH_NO
$`$$(D<T#
x5WAZd
tqU0Lo
kZHl0C
l4IPVH
GVIRKFTSG
l9BPpc
HELL YEAH:
FUCK ESET:
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
X6cd058df54270276aba903
CompanyName
Xbf8b55e5ea739ec9e46db37ff7
FileDescription
Fa464b7b90ad0d2dda1676b43fe8a5f078e
FileVersion
75.8.29.100
InternalName
D1c6fb07e3584299f2380.exe
LegalCopyright
yb3da610921aa33f48939a20a
LegalTrademarks
L08a8d3bcfdb442a909f69fd7205244b534
OriginalFilename
Z74c863ea58f2b7295063a92fd4a14d.exe
ProductName
a6f07fad4034b61a6df02c39062fc3a330dfcb3
ProductVersion
37.72.37.33
Assembly Version
48.11.88.32
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Stelega.4!c
tehtris Clean
DrWeb Trojan.PWS.Steam.35316
MicroWorld-eScan IL:Trojan.MSILZilla.25609
ClamAV Clean
FireEye Generic.mg.4f0402bf30445ece
CAT-QuickHeal Clean
McAfee Artemis!4F0402BF3044
Malwarebytes Spyware.WhiteSnake
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.25609
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36132.cm0@aek4xUh
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Spy.WhiteSnake.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stelega.gen
Alibaba TrojanPSW:MSIL/Stelega.cb1601c9
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Spyware.WhiteSnake!8.17C86 (CLOUD)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.jgdma
Baidu Clean
VIPRE IL:Trojan.MSILZilla.25609
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.nm
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.25609 (B)
Ikarus Trojan.MSIL.Spy
GData IL:Trojan.MSILZilla.25609
Jiangmin Clean
Webroot W32.Trojan.MSILZilla
Avira TR/Redcap.jgdma
Antiy-AVL Trojan[PSW]/MSIL.Stelega
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6409
ViRobot Trojan.Win.Z.Whitesnake.38400
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stelega.gen
Microsoft Trojan:MSIL/Vigorf.A
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5404257
Acronis Clean
VBA32 Clean
ALYac IL:Trojan.MSILZilla.25609
MAX malware (ai score=84)
DeepInstinct MALICIOUS
Cylance unsafe
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CDA23
Tencent Msil.Trojan-QQPass.QQRob.Ekjl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/WhiteSnake.A!tr.spy
Panda Trj/Chgt.AD
No IRMA results available.