Static | ZeroBOX

PE Compile Time

2087-01-26 15:42:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000a54 0x00000c00 4.72071793988
.rsrc 0x00004000 0x000138cc 0x00013a00 6.15329613217
.reloc 0x00018000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00016d7c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000171e4 0x000000ae LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00017294 0x0000044c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000176e0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Build1
<Module>
System.IO
mscorlib
Thread
get_IsAttached
DownloadFile
Console
set_FileName
ReadLine
ValueType
SecurityProtocolType
UnverifiableCodeAttribute
DebuggableAttribute
TargetFrameworkAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Build1.exe
Config
System.Threading
System.Runtime.Versioning
String
Mdsdddddddddddddfsh
GetTempPath
user32.dll
set_SecurityProtocol
Program
System
Application
System.Security.Authentication
get_StartInfo
ProcessStartInfo
Tfgfgfg_mp
ServicePointManager
Debugger
.cctor
System.Diagnostics
System.Runtime.CompilerServices
DebuggingModes
EnableVisualStyles
SslProtocols
System.Windows.Forms
GetCursorPos
SetCursorPos
Process
Concat
Object
System.Net
SetCompatibleTextRenderingDefault
SystemDefault
WebClient
lpPoint
Hdffffdddddddddsaiy
System.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
_CorExeMain
mscoree.dll
=jcbyI{|by
'Sl/<{
=DbVY#
MeGa/o
miZ|ea
>3>>n<
}mK/$-
/;gyw?v
0x9*ANCT
\6\B!p#
)HZeH5
O^0swh
K/[|Q
=WZn?B
;'CEE
En~a$9
]sNFK7
l1W1|I
ZSMMSZ
SSQPPMMMMMMP
^VSSSQPPPMMMMMMZ
fVXVVSSQQPPMV
\XXVVVSSSQPP
^\\XXVVSSSQQ
^^\\XXVVVSSSQ
a^^^\XXXVVSSSQPPMM
aa^^^^\XXXXXVXVVVS
daaa^^\\^
hdaaa^^^\\XVVVVSRRPPPMMS
hhhaaa^^^\\\XVVVSSSQPPMMMZ
hhhhhaaa^^^\XXXVVSSQQQPPMM
hhhhhhaaa^^^^\XXVVVSSQQPPMV
hhhhhhhdaaa^^\\XXXVVSSQQPPP
hhhhhhhhhaaa^^^\\XXVVVSSQQP
hhhhhhhhhaaa^^^\\XXVVVSSQQa
(,((((
hhhhhhhhhhdaa^^^\XXXVVSSSV
.(,(( (
da^^^^\XXVVVSS
00(,((
^^^\\XXXVVS
0./((((((
^^^^\\XXVZ
000.,((("(
a^^^\\XXd
A0.,,(((("(
daa^^^\X
~000.0.(((
hdaa^^^^
900.,(0((((
hdaa^^^
<90000(((((
hhddd^i
#############
9000.0,((((
hhhddd
##############
<000.,,(((((
}GGGGGEEB@@@@8
,(/((((
//,(,(((
######################
J,((((
######################
,(((("
900//,(((((
I00/.0,((( ,
##############
##############
\QQNNNNQf
dWUSQQNNNRWQ
WWWUUSQNW
\\WWUUSQ\
_^\WWUUUQ]dNN
__^\WWWURRQNN
c___^\
ecc__^^\\WWWUQQQQ\
hcc_c^^\W\WUURQQNNQ
hdee_c__^\WWUUSQQNN
hhehe_c__^\\WWUUSQQR
heeehhcc__^^\WWUUSQQ
ehehchccc_^^\WWWUUS
c^^^\WWUU
4505##
?~~~~~{{~
_^^\WWU
745##&&
i__^\WW
D4444&&
c___^\
y74445#&#
ccc___
9944&4&&
'''''''''(
x98445&&&#
C94445&#
''''''''''''''''
9@H45##
D744000
lpppprpm
''''''''''
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!,A)-A-+,,
!!!!!!!!!!!!!!!!!!!! !! !! !!!!!!!!!A!A,
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!-A-,),
dG525Gd
_55432?@_
>=;543{|2
B>==55;:2
DB>>_gdaa
iKDBB>>;;5433`
iKKHHB>>;;5432x
YKKKHHBB>=5554I
0eKKKHHBB>>=54;
QsxxwxweK>>=;5
jH>>=>
OS((
hm\\XXWW+
PZ,$
f7322B~
v::53jkh
u=::7:6d
{[Tt?=<fhfhjj~
_A?==::732B
^CAA==;:753~
/lfaaa?<::7x
..,,Fc=::x
EYWTQPN
GZVVZH
K0-55U
G20+(%(S
F320/((N
@@<E0(M
UUUhooG{{;
&e`===
@kC5.\<
"Mss3n
M7e5uZ(
{qdx\!NI
]]]hkkCKK
Y}(t^%
^!`jkkQ[[
P n^y3f
-OWe/'
wMGED:
.M^'-~H
9]zuZl
vpuZz#
F6A-Pd
OM1ki
!2<l|.
[2M%P1_
@rlKU
c~UE9V
F!~+]%~
_/t_,d
1|LCu8
HieU@Y-0q
j 1j.g~Bo
eeeHeee
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
http://94.142.138.111/software/Build-1S.exe
dtsmsys.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
Python
FileVersion
3.11.3150.1013
InternalName
Python Console
LegalCopyright
Copyright
2001-2023 Python Software Foundation. Copyright
2000 BeOpen.com. Copyright
1995-2001 CNRI. Copyright
1991-1995 SMC.
OriginalFilename
Python Console
ProductVersion
3.11.3150.1013
Assembly Version
3.11.3150.1013
ProductName
Python
CompanyName
Python Software Foundation
LegalTrademarks
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Reline.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.80322
ClamAV Clean
FireEye Generic.mg.bfaa027a645e5678
CAT-QuickHeal Clean
ALYac Gen:Variant.MSILHeracles.80322
Cylance unsafe
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.80322
K7GW Clean
Cybereason malicious.b1cc10
Baidu Clean
VirIT Trojan.Win32.Genus.QAO
Cyren Clean
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Generik.IFPKTNY
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba TrojanPSW:MSIL/Reline.da49d503
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Undefined!8.1327C (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.80322
McAfee-GW-Edition BehavesLike.Win32.Infected.ct
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.80322 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Trojan[PSW]/MSIL.Reline
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Clean
Arcabit Trojan.MSILHeracles.D139C2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Reline.gen
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36196.hm3@aCVXQnl
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.PasswordStealer.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CE523
Tencent Msil.Trojan-QQPass.QQRob.Azlw
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.95853585.susgen
Fortinet PossibleThreat
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.