Static | ZeroBOX

PE Compile Time

2023-05-03 11:27:09

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000e9c 0x00001000 5.13611331529
.rsrc 0x00004000 0x00019f7c 0x0001a000 1.51398393444
.reloc 0x0001e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_ICON 0x0001967e 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0001d8e2 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001d978 0x000003de LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001dd92 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+"+'*s
+++0+1+6u
v4.0.30319
#Strings
Uvhfirgpxy.exe
Uvhfirgpxy
<Module>
mscorlib
Object
System
PoweredByAttribute
SmartAssembly.Attributes
Attribute
Rejqcj
Egtudph
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
Assembly
GetTypeFromHandle
RuntimeTypeHandle
String
Concat
GetMethod
MethodInfo
MethodBase
Invoke
Convert
Thread
System.Threading
GetDomain
AppDomain
System.Core
Enumerable
System.Linq
IEnumerable`1
System.Collections.Generic
System.Net.Http
HttpClient
GetAsync
Task`1
System.Threading.Tasks
HttpResponseMessage
get_Result
get_Content
HttpContent
ReadAsByteArrayAsync
Action
Delegate
CreateDelegate
get_Method
Reverse
Encoding
System.Text
get_ASCII
GetString
WrapNonExceptionThrows
Opera Internet Browser
Opera Software
Copyright Opera Software 2022
$47b98fc2-e246-45ee-a985-052863f3f076
92.0.4561.33
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
#Powered by SmartAssembly 8.1.2.4975
_CorExeMain
mscoree.dll
9_;8Ozd>
H;4O&H
<[N=2%
%tEXtdate:create
2015-04-15T16:48:56-05:00q4
%tEXtdate:modify
2015-04-15T16:28:54-05:00
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
)w`9w*Aw*Iw*Qw*Yw*aw*iw*qw*yw*
f.#o.+o.3
GetExp
ortedTypes
FromBa
se64String
https://toraxgold.com/module/Fjwzjb.bmp
Ckvuheqwfp
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Opera Internet Browser
CompanyName
Opera Software
FileDescription
Opera Internet Browser
FileVersion
92.0.4561.33
InternalName
Uvhfirgpxy.exe
LegalCopyright
Copyright Opera Software 2022
LegalTrademarks
OriginalFilename
Uvhfirgpxy.exe
ProductName
Opera Internet Browser
ProductVersion
92.0.4561.33
Assembly Version
92.0.4561.33
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Seraph.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.66823962
FireEye Generic.mg.9fe535a2512484cb
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Msil.Agent.Vc2l
K7AntiVirus Clean
BitDefender Trojan.GenericKD.66823962
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36196.gm0@aSnfctl
VirIT Trojan.Win32.GenusT.DGNH
Cyren W32/MSIL_Agent.FGQ.gen!Eldorado
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AISZ
Cynet Malicious (score: 100)
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Disco.gen
Alibaba TrojanPSW:MSIL/Disco.16dc4940
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:f0YcH+I6ni01eGEklXhafA)
Sophos Mal/Generic-S
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.cz
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.66823962 (B)
SentinelOne Static AI - Suspicious PE
GData Win32.Trojan.Agent.C4I6LW
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Generic.D3FBA803
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Disco.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!9FE535A25124
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Downloader.MSIL.gen.rexp
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DE323
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Small.R!tr.dldr
AVG Win32:DropperX-gen [Drp]
Cybereason Clean
Avast Win32:DropperX-gen [Drp]
No IRMA results available.