Static | ZeroBOX

PE Compile Time

2072-10-20 01:21:26

PDB Path

Cinoshi.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x0bE\x1b< ]^\x1b 0x00002000 0x00027730 0x00027800 7.99890604818
.text 0x0002a000 0x0006de58 0x0006e000 4.24440014463
.rsrc 0x00098000 0x0000032c 0x00000400 2.51288504428
0x0009a000 0x00000010 0x00000200 0.142635768149
.reloc 0x0009c000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00098058 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x49a000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
&C5>v(S
BHLdB1xu
n"[Z;tI
".QQF.$
6(zt_hOm
o&5@ <
DA@teb.
[;"/$'
h\H$Y0#
+yfX[<
E5t1\]
w&`N:N
`M2fcp+k
.Enxf&
;kW$?\
&fmW!2
;%[1^G
3W9Iyz2
"T-H/+
W15HpsGi
a#xvd|
{T!_AU
`U)4u~
=&^C=4
oYKt)l
-$k{*~hVp+<
zw_L0V
._z></
A6:;pZX
W0d(/'
GqEXk_0Da
}F[I1rR
J{-5a@k
8al+P0B&*#w
xEKX=pg
Lr"I\br
Mb=~s5
MOQmy[
^,$/SGGu2
/iQ>4N?
5JO2<C)No
R/T]<\aV0db
hv/x8#
Kgm|`,
<UIsrq)
W6AAoz
j(YWb]W
z+g~GN
W2vOD3`
mX_AL0
(/C"/]G
Y |\!|
6nQ(=D$s
/Azrpu\
s1q+7N
OP5Gk
[>yT=6
N@Mm5\8
:01(eE
Ud*:z%
yUZ8X
Br,m`P
YU^Rw4
4G1ch
_7O6:r
b_)oB8w
)3ncH9
[QSHl6
|('X=A
|h@h7j
.]:Y[L
V`yF@#V
kO-/?p
Wq#}n:
[$P/o[#
ohA#$-
;VFJ]o
)DO[Or
{zCL&KuA
je8}4v
CX$gsT
1x'%=\1
u2,QRJ
epslK@[Y
Xb P26.+^
b4!j4u
e.e#Zo
\KQ}E8
+)&|"c:
&h]w8l
+[V-|7
puRDHl
&HWGu
(v=YYY
.[b~{&i
i6B/i'
w=,X@g
otFks)
`7]>~&6
j(hvbs
]6"0Tji
st;R/Tb2TyS
wi|KXO#r
bfLAmU
EO~J3%
bV=KhXB
S[{I8z`
(^v|>j|
@TO?.2
Rp+Nl0%^|
U|1=z0
R}a\L]
Ci{NZX
"65f|O
#AuMjs
B\v+97|d
1?VJG/
wNf78V0
HT[?mN-
BtA$Gm
G[9w^9u_
{~|^C;
9B.JT
;|=VWu
+0^^`A'
a_g<G(I
(o}G/pH
=yu&J|
~[He:{
0 jZo
D 8jCCYG8
mTx>w;E
aD>@pt{
7{Tv+Y
#(.~<R-
'k~^~L
9"~6~;
/aI;%ta
0%uuREY.IBW
t=S}]+
VE\ZLd
lIeDnC
,C}9u)\M
b:Y?5I
75_)}v
jt}_cfC
QPLOnjE
*ZYk4Q
u*kutw
a{Cq06?
}e*?G
,.)Avr
6""M_04
TI!yPC
AnWAA3EF
ynle$F
<i<CD+
B]s1Bh1
z*ce$R
.Q`/4:
1zzfdY
)"GSj*`
i':j"
bM`h~V
H>SC.j
[]1p=mk
^v._BJ
curY*R
($Gy!*r
i&WC%.
{=EVm;o
Z|K}]^~v
)@]Bp=
jQ2~^n
~Ydt*jd
MPD@!`
P$%HF&"W[
\*djIv
kHqdA//
GUIkl
_|My}*
7.(##6
VTWS'|
iDs{D%
KQ[0O{ta
5J.,Ze
>l(#n/
)dW9@P
ip3ID%o
7dQ#gA
Qfr[~]
w=CmE#
iAsL];W61
=|]CRc
VoQ%)~
:?Lt!;
m-/>H'
41sOE6
qck3p)Op
<(/o!>G?
~$}XN>^J
t9lu&
S9@W(@h
{V3]Z,
g^ilf{?
HbeLwpie
]d!3XD
R#:Q+Du-
dX)J65
(g^\9(
AKkzrt
GQ`&sQ
(o4\ENa
pjv#e*
=3Ov7#>
skG|Pm
iS6]}4
zM;N>$
YS?]i]nu
rB[=fSi
N0\ J6
oaV5?YG
12'/`+
jUfxg.
7%qeCt
iDmXI|
@y0y)v
KPv|2
Oafo;aR\
,KA"E
!@}j@U
c'm7~b
VmzrP[]
t/o]ZG
]nlP|F
?x6#)$
NY/d4l
u(z/~U?H
AzZ-]2
2x++V`~_
J>Vpqh
x9W:BO
^o+%Y\y
K,+Qy?
.ACy2V
qR5B0yH11C
|z$cu`
^]:pK?
~8X(ffB7E$Ll
h}qqV0
g,hGE'%
uP0FbV
Z5Po#I
C~EaaN<
&FBAJ -<L
s#sC6a9
yN$8]Si5d
X[MqU
@w2k)YK"{
l#8d?n
Q#z@=q
[5J$:[[
,&I\L,
!@%QA#i"
"LBEft
RuZ )W
+Z ?f)
6V[YZ
VHryZ
/+a8I
S2K8Z
wd=a8#
v7+>Z
Cinoshi.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
'M'W'b'
(((:(@(G(R(`(g(q(y(
*7*?*a*k*
+%+,+4+D+J+Q+`+f+m+
,!,1,8,H,O,_,f,v,},
-C-P-\-j-q-x-
0>0E0L0
1V1]1d1k1r1y1
$>%Y%b%
&J&S&m&v&
) )Z)g)o)v)
,(,?,V,m,
..2.@.\.n.{.
.=/N/Z/l/
/b0r0}0
7LG7Z'@UlR@bueQ-,,2CpOSn)
;UbZfe=C+FFt$GR|8<OwA3r+*
<>9__2_0
<>9__3_0
<>9__4_0
<>9__5_0
<>9__6_0
<>9__7_0
<>9__38_0
<>9__8_0
<>9__2_1
IEnumerable`1
CallSite`1
Stack`1
Action`1
ReadOnlyCollection`1
IEnumerator`1
IList`1
85332E00AFFFDBE44E7421AA4236274F9495AC6C2204C59B9ADFC872D4215E12
Microsoft.Win32
UInt32
ToInt32
GetInt32
C2D8E5EED6CBEBD8625FC18F81486A7733C04F9B0129FFBE974C68B90308B4F2
Func`2
KeyValuePair`2
IDictionary`2
Func`3
Action`3
UInt64
GetInt64
_VtblGap1_4
Func`4
_VtblGap2_5
GetInt16
0C9B53D0417CF5539EA98A771F400E930B4B4F55363A296A9E5A5F941AB71C86
7C97C06F982D2F598F71BCF85A27244685EC039BC414EB391EC3EC449A619F37
get_UTF8
_VtblGap1_9
<Module>
93631B0726F6FE6629DAA743EE51B49F4477ED07391B68EEEA0672A4A90018AA
GetTypeFromCLSID
GetHINSTANCE
formSubmitURL
System.IO
value__
System.Data
tsData
CryptUnprotectData
embedder_download_data
form_data
Ionic.Zlib
mscorlib
DinersClub
System.Dynamic
System.Collections.Generic
creation_utc
expires_utc
last_access_utc
Thread
Nss3CouldNotBeLoaded
dateAdded
date_added
timePasswordChanged
NoArgumentsSpecified
Unspecified
timeLastModified
lastModified
date_password_modified
date_modified
last_modified
opened
timesUsed
timeLastUsed
lastUsed
firstUsed
lastAccessed
times_used
date_last_used
timeCreated
date_created
cc_number_encrypted
card_number_encrypted
keyword_id
place_id
anno_attribute_id
origin_id
billing_address_id
by_ext_id
NewGuid
passwordField
usernameField
set_ParallelDeflateThreshold
TrimEnd
ReadToEnd
DbCommand
CreateCommand
SQLiteCommand
Append
DateTimeKind
Nss3NotFound
LocalStateNotFound
MozGlueNotFound
FunctionNotFound
DownloadsNotFound
CreditCardsNotFound
CookiesNotFound
ProfilesNotFound
BookmarksNotFound
LoginsNotFound
AddressNotFound
FormHistoryNotFound
http_method
MasterCard
name_on_card
Clipboard
encryptedPassword
Replace
distance
CreateInstance
XmlNode
FromImage
AddRange
EndInvoke
BeginInvoke
GetEnvironmentVariable
IEnumerable
IDisposable
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
DownloadFile
UploadFile
ZipFile
CouldNotSetProfile
Console
get_Module
get_Name
get_FullyQualifiedName
GetFileName
get_MachineName
GetElementsByTagName
get_FullName
get_UserName
cc_name
site_name
cc_additional_name
cc_given_name
by_ext_name
display_name
cc_family_name
fieldname
nickname
encryptedUsername
hostname
source_scheme
DateTime
ToLocalTime
creationTime
end_time
last_access_time
last_visit_time
start_time
WriteLine
Combine
LocalMachine
encType
ValueType
ExpressionType
GetElementType
cc_type
password_type
original_mime_type
folder_type
danger_type
CarteBancaire
System.Core
isSecure
is_secure
Capture
Dispose
Reverse
use_date
last_visit_date
Create
MulticastDelegate
posState
SetApartmentState
Delete
System.Data.SQLite
rawSameSite
sameSite
CallSite
samesite
DispIdAttribute
CompilerGeneratedAttribute
GuidAttribute
NeutralResourcesLanguageAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
TypeIdentifierAttribute
UnmanagedFunctionPointerAttribute
CompilationRelaxationsAttribute
CoClassAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
ToByte
prevByte
get_Value
MinValue
TryGetValue
encrypted_value
password_value
username_value
RegistryHive
add_AssemblyResolve
Remove
Cinoshi.exe
get_Size
inSize
outSize
dwSize
windowSize
dictionarySize
Serialize
Deserialize
SizeOf
get_ItemOf
LastIndexOf
get_Png
System.Threading
set_Encoding
GetEncoding
System.Drawing.Imaging
System.Runtime.Versioning
FromBase64String
DownloadString
ToString
GetString
Substring
set_UseZip64WhenSaving
System.Drawing
ForEach
url_hash
GetTempPath
GetFolderPath
target_path
current_path
get_Width
get_Length
EndsWith
StartsWith
expiration_month
cc_exp_month
Cinoshi
AsyncCallback
callback
skip_zero_click
AllocHGlobal
FreeHGlobal
Marshal
System.Collections.ObjectModel
Parallel
set_CompressionLevel
kernel32.dll
crypt32.dll
DBNull
System.Xml
LoadXml
tab_url
preview_image_url
site_url
origin_url
icon_url
federation_url
action_url
tab_referrer_url
inStream
outStream
MemoryStream
stream
get_Item
get_Is64BitOperatingSystem
httpRealm
signon_realm
Random
GetBoolean
IsLittleEndian
TimeSpan
hidden
CopyFromScreen
get_PrimaryScreen
AppDomain
get_CurrentDomain
origin
GetExtension
version
get_Location
UnaryOperation
BinaryOperation
expiration
System.Web.Script.Serialization
System.Reflection
MatchCollection
GroupCollection
ManagementObjectCollection
DbConnection
SQLiteConnection
position
CallingConvention
Zip64Option
NotImplementedException
KeyNotFoundException
DirectoryNotFoundException
ArgumentOutOfRangeException
IndexOutOfRangeException
PathTooLongException
ArgumentNullException
InvalidOperationException
UnauthorizedAccessException
ArgumentException
description
System.Data.Common
interrupt_reason
Intern
Unknown
FileInfo
FileSystemInfo
CSharpArgumentInfo
DirectoryInfo
schemeMap
Bitmap
Ionic.Zip
Microsoft.CSharp
cc_exp
System.Linq
expiration_year
cc_exp_year
ExecuteScalar
InvokeMember
TryGetMember
cc_number
DbDataReader
SQLiteDataReader
ExecuteReader
StreamReader
TextReader
StringBuilder
SpecialFolder
sender
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
GetMemberBinder
GetIndexBinder
rangeDecoder
Buffer
ManagementObjectSearcher
ResolveEventHandler
referrer
CurrentUser
blacklisted_by_user
GetDelegateForFunctionPointer
syncChangeCounter
BitConverter
JavaScriptConverter
Discover
ToLower
value_lower
JavaScriptSerializer
moving_blocked_for
UnknownError
IEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
IntPtr
Graphics
System.Diagnostics
AddSeconds
FromUnixTimeSeconds
ToUnixTimeSeconds
FromUnixTimeMilliseconds
get_Bounds
GetBounds
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
Matches
EnumerateDirectories
GetDirectories
properties
EnumerateFiles
GetFiles
GetSubKeyNames
ReadAllLines
get_SupportedTypes
has_expires
numPosStates
get_Attributes
set_Attributes
FileAttributes
originAttributes
SetAttributes
GetBytes
received_bytes
total_bytes
CSharpArgumentInfoFlags
CSharpBinderFlags
ResolveEventArgs
System.Threading.Tasks
Equals
Models
NumBitLevels
numBitLevels
System.Windows.Forms
Contains
System.Web.Extensions
System.Linq.Expressions
System.Text.RegularExpressions
System.Collections
get_Groups
get_Chars
RuntimeHelpers
RegisterConverters
possible_username_pairs
get_Success
get_Is64BitProcess
GetProcAddress
lpAddress
AmericanExpress
numTotalBits
numPosBits
numPrevBits
get_Exists
syncStatus
generation_upload_status
Concat
ImageFormat
DynamicObject
ManagementBaseObject
ManagementObject
object
Select
lpflOldProtect
VirtualProtect
flNewProtect
Strict
System.Net
Target
DateTimeOffset
get_Height
ProcessIsNot64Bit
op_Implicit
op_Explicit
get_Default
IAsyncResult
ParallelLoopResult
tsResult
result
WebClient
transient
System.Management
inBrowserElement
password_element
username_element
submit_element
Environment
XmlDocument
parent
get_Current
iContent
content
is_persistent
get_Count
typed_count
use_count
foreign_count
visit_count
ThreadStart
TrimStart
Convert
source_port
XmlNodeList
ToList
ArrayList
rev_host
MoveNext
System.Text
set_CommandText
ReadAllText
AppendAllText
WriteAllText
OpenText
get_InnerText
GetText
SetText
RegistryView
get_Now
TryGetIndex
startIndex
UnionPay
InitializeArray
ToArray
frecency
get_Key
OpenSubKey
OpenBaseKey
RegistryKey
top_frame_site_key
host_key
GetCallingAssembly
GetExecutingAssembly
isHttpOnly
is_httponly
BlockCopy
LoadLibrary
FreeLibrary
expiry
AddDirectory
CreateDirectory
sDirectory
ZipEntry
Registry
op_Equality
op_Inequality
priority
IsNullOrEmpty
is_same_party
WrapNonExceptionThrows
$4b568f36-1d92-4937-a8a0-f9960b1f14ba
0.0.0.0
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
$F935DC21-1CF0-11D0-ADB9-00C04FD58A0B
$24BE5A30-EDFE-11D2-B933-00104B365C9F
$41904400-BE18-11D3-A28B-00104BD35090
FullName
$F935DC23-1CF0-11D0-ADB9-00C04FD58A0B
ZSystem.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
'1*D,].c1j4{6
! "!# $#% &%' (')'* +*, -,. /.102131405460768690:9;0<;=0>=?0@?DCFEQPRQXWYW\[][^[_[wvxvyvzv{v|v}v~v
InstallPath
SourceModInstallPath
\mozglue.dll
\nss3.dll
SELECT creation_utc,top_frame_site_key,host_key,name,value,encrypted_value,path,expires_utc,is_secure,is_httponly,last_access_utc,has_expires,is_persistent,priority,samesite,source_scheme,source_port,is_same_party FROM cookies
SELECT origin_url,action_url,username_element,username_value,password_element,password_value,submit_element,signon_realm,date_created,blacklisted_by_user,scheme,password_type,times_used,form_data,display_name,icon_url,federation_url,skip_zero_click,generation_upload_status,possible_username_pairs,id,date_last_used,moving_blocked_for,date_password_modified FROM logins
SELECT id,url,title,visit_count,typed_count,last_visit_time,hidden FROM urls
SELECT id,guid,current_path,target_path,start_time,received_bytes,total_bytes,state,danger_type,interrupt_reason,hash,end_time,opened,last_access_time,transient,referrer,site_url,tab_url,tab_referrer_url,http_method,by_ext_id,by_ext_name,etag,last_modified,mime_type,original_mime_type,embedder_download_data FROM downloads
SELECT name,value,value_lower,date_created,date_last_used,count FROM autofill
SELECT guid,name_on_card,expiration_month,expiration_year,card_number_encrypted,date_modified,origin,use_count,use_date,billing_address_id,nickname FROM credit_cards
SELECT id,originAttributes,name,value,host,path,expiry,lastAccessed,creationTime,isSecure,isHttpOnly,inBrowserElement,sameSite,rawSameSite,schemeMap FROM moz_cookies
SELECT id,url,title,rev_host,visit_count,hidden,typed,frecency,last_visit_date,guid,foreign_count,url_hash,description,preview_image_url,origin_id,site_name FROM moz_places
SELECT id,type,fk,parent,position,title,keyword_id,folder_type,dateAdded,lastModified,guid,syncStatus,syncChangeCounter FROM moz_bookmarks
SELECT id,place_id,anno_attribute_id,content,flags,expiration,type,dateAdded,lastModified FROM moz_annos
SELECT id,fieldname,value,timesUsed,firstUsed,lastUsed,guid FROM moz_formhistory
\cookies.sqlite
\logins.json
\places.sqlite
\formhistory.sqlite
\autofill-profiles.json
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
0.0.0.0
InternalName
Cinoshi.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Cinoshi.exe
ProductName
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Seraph.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Cerbu.165427
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
ALYac Gen:Variant.Cerbu.165427
Malwarebytes Spyware.FormBook
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Cerbu.165427
K7GW Clean
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.JAN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Spy.Agent.DXY
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Seraph.16894d24
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.87 (RDM.MSIL2:oYMgC6D2XfGtcGTJN2c0fA)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1311394
DrWeb Clean
VIPRE Gen:Variant.Cerbu.165427
TrendMicro TrojanSpy.MSIL.CINOSHI.SMTH
McAfee-GW-Edition BehavesLike.Win32.Generic.jm
Trapmine Clean
FireEye Generic.mg.6bd02e751b2b2033
Emsisoft Gen:Variant.Cerbu.165427 (B)
SentinelOne Static AI - Malicious PE
GData MSIL.Trojan-Stealer.Cinoshi.FHZXD9
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1311394
Antiy-AVL Trojan[Downloader]/MSIL.Seraph
Gridinsoft Trojan.Heur!.03013281
Xcitium Clean
Arcabit Trojan.Cerbu.D28633
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/CinoshiStealer.A!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R561300
Acronis Clean
McAfee Artemis!6BD02E751B2B
MAX malware (ai score=86)
DeepInstinct MALICIOUS
VBA32 CIL.HeapOverride.Heur
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-Downloader.Seraph.Mqil
Yandex Clean
Ikarus Trojan.MSIL.PSW
MaxSecure Trojan.Malware.121218.susgen
Fortinet MSIL/Agent.DXY!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36132.Lu0@a87Mt8k
AVG Win32:SpywareX-gen [Trj]
Avast Win32:SpywareX-gen [Trj]
No IRMA results available.