Static | ZeroBOX

PE Compile Time

2023-04-17 17:59:35

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x001f5c04 0x001f5e00 5.92098650329
.rsrc 0x001f8000 0x00005048 0x00005200 4.53329561229
.reloc 0x001fe000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x001fc6a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x001fcb10 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x001fcbc0 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x001fce94 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
}.+a
I0YjX
I0YjX
-"&&&&
&&&+Y(
\.M+{
ZXI$3C
ZXIt36
ZXIy3)
ZXIp3
ZXIe3
ZXIs3
ZXI"3
ZXI.3
N.C+^
n.7+R
aYjX
AYjX
ZXI/3l
ZXI*3v
ZXI/3
].D8b
ZXIi.
ZXII3
ZXIi.
ZXII3
ZXIa@f
ZXIl@Q
ZXIs@<
ZXIe@'
ZXIr@
ZXIu@
ZXIe@
ZXIu3>
ZXIl3,
ZXIl3
ZXIa35
ZXIn.
ZXIN3
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPQ
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADjQAAAADAAW8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADAALgAwAC4AMAAuADEAAABuAG8AaQBzAHIAZQBWACAAeQBsAGIAbQBlAHMAcwBBAAEACAA4AAAAMAAuADAALgAwAC4AMQAAAG4AbwBpAHMAcgBlAFYAdABj
v4.0.30319
#Strings
Gqufkob
Gqufkob.exe
mscorlib
System.Core
System.Data
System
System.Xml
System.Runtime.Serialization
WindowsFormsApp24.Properties.Resources.resources
Action
AppDomain
AsyncCallback
Attribute
Base64FormattingOptions
BitConverter
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
DictionaryEntry
System.Collections
Dictionary`2
System.Collections.Generic
Enumerator
KeyCollection
ICollection`1
IDictionary`2
IEnumerable`1
IEnumerator`1
IEqualityComparer`1
KeyValuePair`2
List`1
Hashtable
ICollection
IDictionary
IDictionaryEnumerator
IEnumerable
IEnumerator
IEqualityComparer
NameObjectCollectionBase
System.Collections.Specialized
NameValueCollection
StringDictionary
Convert
DBNull
DataColumn
DataColumnCollection
DataRow
DataRowCollection
DataSet
DataTable
DataTableCollection
InternalDataCollectionBase
DateTime
DateTimeKind
DateTimeOffset
Decimal
Delegate
DebuggerHiddenAttribute
System.Diagnostics
DebuggerNonUserCodeAttribute
Double
DynamicObject
System.Dynamic
GetIndexBinder
GetMemberBinder
Exception
Func`2
Func`4
CultureInfo
System.Globalization
NumberFormatInfo
IAsyncResult
IConvertible
IDisposable
IFormatProvider
StringReader
System.IO
StringWriter
TextReader
TextWriter
IntPtr
Enumerable
System.Linq
MulticastDelegate
NonSerializedAttribute
NotImplementedException
NotSupportedException
Nullable`1
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
BindingFlags
ConstructorInfo
DefaultMemberAttribute
DynamicMethod
System.Reflection.Emit
ILGenerator
LocalBuilder
OpCode
OpCodeType
OpCodes
OperandType
FieldInfo
MemberInfo
MethodBase
MethodBody
MethodInfo
Module
ParameterInfo
PropertyInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
DynamicAttribute
RuntimeCompatibilityAttribute
RuntimeHelpers
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
Marshal
DataMemberAttribute
FormatterServices
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
Single
String
StringComparison
Encoding
System.Text
StringBuilder
UTF8Encoding
Monitor
System.Threading
TimeSpan
UInt16
UInt32
UInt64
ValueType
XmlIgnoreAttribute
System.Xml.Serialization
<Module>
.cctor
Equals
GetHashCode
Invoke
BeginInvoke
EndInvoke
value__
GetDynamicMemberNames
TryGetIndex
TryGetMember
MoveNext
GetEnumerator
Dispose
get_Current
Reverse
ToArray
FromBase64String
get_ASCII
GetString
Append
get_Length
ToCharArray
AppendLine
IsWhiteSpace
ToString
GetTypeFromHandle
GetFields
get_FieldType
IsAssignableFrom
GetValue
get_OpCodeType
get_Value
GetBytes
get_OffsetToStringData
op_Inequality
GetGenericTypeDefinition
GetGenericArguments
GetProperties
GetIndexParameters
get_PropertyType
get_Name
GetCustomAttributes
ToLowerInvariant
get_IsLiteral
get_IsInitOnly
op_Equality
get_IsEnum
get_IsArray
GetElementType
Contains
get_IsValueType
get_IsPrimitive
get_IsInterface
get_IsClass
get_IsGenericType
get_AssemblyQualifiedName
StartsWith
Concat
GetType
GetConstructor
GetILGenerator
Ldarg_0
Newobj
CreateDelegate
get_FullName
Format
EmptyTypes
DeclareLocal
Ldloca_S
Initobj
Ldloc_0
Unbox_Any
Stloc_0
Ldarg_1
Castclass
GetGetMethod
IsDefined
GetMethodBody
GetILAsByteArray
get_OperandType
get_Module
ToInt32
get_DeclaringType
ResolveMember
GetSetMethod
EmitCall
get_IsStatic
Callvirt
get_CanWrite
get_CurrentDomain
GetAssemblies
FirstOrDefault
get_Assembly
GetObject
FromTicks
op_Addition
ToInt64
get_Key
get_Chars
IsDigit
MinValue
ToLocalTime
TryGetValue
get_Count
get_Item
set_Item
ContainsKey
GetMethod
set_TableName
get_TableName
DynamicInvoke
CreateInstance
get_InvariantCulture
ChangeType
MakeGenericType
CopyTo
GetUninitializedObject
SetValue
set_EnforceConstraints
BeginInit
ReadXmlSchema
set_DataSetName
get_Tables
get_Columns
EndInit
BeginLoadData
get_DataType
get_Ordinal
get_Rows
EndLoadData
Insert
get_InvariantInfo
IsInfinity
get_Ticks
get_DateTime
get_UtcDateTime
get_Offset
get_Hours
get_Minutes
ToByteArray
ToBase64String
ToUniversalTime
get_Millisecond
get_Year
get_Month
get_Day
get_Hour
get_Minute
get_Second
get_ColumnName
get_DataSetName
WriteXmlSchema
GetXmlSchema
get_Rank
get_Keys
ToList
get_IsAbstract
IndexOf
set_Length
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
WrapNonExceptionThrows
$425b038f-3861-466d-a9e8-97800a35ec53
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwx
n~~~~~
dgfvgv
Cd4vvvww~w
wwwwwwwww
wwwwwww
wwwwww
NNNNNNNNNNNNNNNNNNNNNNNNNNN
.//4899[`````fsw
*+-248[``ffkkssw
+,137[[`gfnnv
)==<<>DDERRTW
!!$O(%CW
#&GBYVPZ
r||zzz||
_llllllmzplz
]^^^^^^^^^^^hu
!!!!!!!!!!!!!!!!!!
''**2;EJR
$PXO]Wg~
>Ah|upw
|uw|wz
woieluw||j
^oobVVKMeuto`T
6B<77:7Hao|aIJ
-//0333Hlw|[DF
&)))---6F^cZZS
lllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllllll
S>JJJNNNT]ee
'769;Igj
*@akkkfkkc
H9WkYYaYYaf\
]YaUMC?PYaUE
</3,,%3DaU54
.GaP02
#=MFBB
lllllllllllllllllllllllllllllllllllllllllll
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
FFFFFFFFFFFF
 "')(F
&9CC@@F;F
1F@>@?>@8F
F<CC=54:>@2F
F#4,,%/>F6$F
!.2+*F
FFFFFFFFFFFF
GGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGGG
z_G4z_G
z_G4z_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_G4
z_G4z_G
z_G4z_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_G4
z_G4z_G
z_G4z_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_GYz_G4
z_G3z_G
z_G3z_GXz_GXz_GXz_GXz_GXz_GXz_GXz_GXz_GXz_GXz_GXz_GXz_G3
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
Wiwzokfshcoozngypst
system.configuration.install.assemblyinstaller
system.activities.presentation.workflowdesigner
system.windows.resourcedictionary
system.windows.data.objectdataprovider
system.windows.forms.bindingsource
microsoft.exchange.management.systemmanager.winforms.exchangesettingsprovider
Dictionary
Black list type encountered, possible attack vector when using $type :
Failed to fast create instance for type '{0}' from assembly '{1}'
Unknown IL code detected.
WindowsFormsApp24.Properties.Resources
Wiwzokfshcoozngypst
AutoConvertStringToNumbers is disabled for converting string :
Wiwzokfshcoozngypst.Ubulaevuii
Tncgqsciodsy
$types
Cannot determine type :
$schema
"$types":{
0000000
{"$i":
Serializer encountered maximum depth of
,"$map":
\u0000
System.
Expected colon at index
Unrecognized token at index
Unable to read key
Reached end of string unexpectedly
Could not find token at index
got '
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Gqufkob.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Gqufkob.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.loK7
Elastic malicious (high confidence)
DrWeb Trojan.Inject4.30942
MicroWorld-eScan Gen:Heur.MSIL.Krypt.11
FireEye Generic.mg.e8ab54ff681e5009
CAT-QuickHeal TrojanDownloader.MSIL
McAfee Artemis!E8AB54FF681E
Malwarebytes Trojan.Crypt.MSIL.Generic
VIPRE Gen:Heur.MSIL.Krypt.11
Sangfor Downloader.Msil.Agent.Vche
K7AntiVirus Trojan-Downloader ( 005a3c1a1 )
BitDefender Gen:Heur.MSIL.Krypt.11
K7GW Trojan-Downloader ( 005a3c1a1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36164.!n0@au!psgd
VirIT Trojan.Win32.GenusT.EGLK
Cyren W32/ABRisk.QEZM-7219
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.PCF
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Seraph.d305a421
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Msil.Trojan-Downloader.Seraph.Fplw
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1323344
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0WDI23
McAfee-GW-Edition BehavesLike.Win32.Dropper.tm
Trapmine Clean
CMC Clean
Emsisoft Gen:Heur.MSIL.Krypt.11 (B)
Ikarus Trojan-Spy.AgentTesla
GData Gen:Heur.MSIL.Krypt.11
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1323344
Antiy-AVL Trojan/Win32.Wacatac
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Trojan.MSIL.Krypt.11
ViRobot Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/Malgent!MSR
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Gen:Heur.MSIL.Krypt.11
MAX malware (ai score=80)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WDI23
Rising Malware.Obfus/MSIL@AI.91 (RDM.MSIL2:HAJpShPGx1piBSrbDxv6Zw)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.PCF!tr.dldr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.