Static | ZeroBOX

PE Compile Time

2023-05-27 18:51:03

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00011ab8 0x00011c00 6.120958291
.rsrc 0x00014000 0x0000d800 0x0000d800 6.34644519436
.reloc 0x00022000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0001c888 0x00004a27 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x000212b0 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0002130c 0x0000033c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00021648 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Yeef .
c E7C"Xee
>`!Xe
Xf 7tF
afee a+
a pu{)X O(
cffe )
y5 }rd
X (U*Y
aef o=~
bef ut
Yf L^R
Yfe t`/
a HF$Xfef
%Xfe &
J*f !vt
ef cmt
Y 3i~$a
f ae pe
ce xr@
ce K%N
Y A>$!a Q?
afefe a
aef 2{
1aef *O
eee a{
e -F)Y
$y)ae(B
<9<" 09<"Y
YX g;;4 O
aea qxV
sC)aea
}&e%af
Z^# =[^#a
{n'a T
{vy'e
1PX*X
$ IYw"Ya
XY /+4
\j=)Y 0
cr Y `
f V4o*a8
Xa {tk* pq
=?m"
#a )mx&Y*
c vQk a
ce* 9+l
X* '{a# ),
Yf* *:v
a* f|$
Ye* 3*
e* 7#$
'8X&
_b`}E
_d}E
4/{Hol
?#2y=}
a?h$=jC
FQqr4u*
B"TFmd
v4.0.30319
#Strings
#Strings
#Schema
Ldc_I4_0
Ldloc_0
Stloc_0
Ldarg_0
Ldc_I4_M1
Ldloc_1
Stloc_1
Ldarg_1
IEnumerable`1
ReadInt32
ToInt32
Ldloc_2
Stloc_2
Ldarg_2
Func`2
KeyValuePair`2
Dictionary`2
Ldloc_3
Stloc_3
Ldarg_3
ReadInt64
Ldc_I4
Conv_I4
Ldc_I4_5
ReadUInt16
get_UTF8
<Module>
GetHINSTANCE
System.IO
Ldloc_S
Stloc_S
Brfalse_S
Ldarg_S
Bne_Un_S
get_IV
set_IV
GenerateIV
GetData
mscorlib
System.Collections.Generic
get_IsStatic
GetProcessById
get_CurrentThread
Interlocked
get_Millisecond
set_IsBackground
DynamicMethod
DefineMethod
GetMethod
Clipboard
Replace
OpCode
CryptoStreamMode
Storage
EndInvoke
BeginInvoke
GetEnvironmentVariable
Enumerable
IDisposable
Hashtable
ReadDouble
get_Handle
RuntimeFieldHandle
ResolveFieldHandle
RuntimeMethodHandle
ResolveMethodHandle
get_ModuleHandle
RuntimeTypeHandle
ResolveTypeHandle
GetFieldFromHandle
GetMethodFromHandle
GetTypeFromHandle
ReadSingle
get_Module
DefineDynamicModule
get_ManifestModule
get_Name
get_FullyQualifiedName
get_MachineName
get_ProcessName
GetName
AssemblyName
DateTime
SetOnline
get_FieldType
DefineType
CreateType
get_IsValueType
MakeByRefType
get_DeclaringType
SecurityProtocolType
get_ReturnType
SetReturnType
get_ParameterType
GetType
System.Core
Capture
MethodBase
Dispose
CreateDelegate
MulticastDelegate
SetApartmentState
SuppressIldasmAttribute
DefaultMemberAttribute
RuntimeCompatibilityAttribute
ReadByte
get_Value
LegalBlockSizesValue
LegalKeySizesValue
SetValue
set_Expect100Continue
add_ResourceResolve
vaultnw_csharp_build_self.exe
set_BlockSize
get_InputBlockSize
get_OutputBlockSize
set_KeySize
Deserialize
SizeOf
IndexOf
vaultnw_csharp_build_self
System.Threading
Encoding
FromBase64String
EscapeDataString
ReadString
DownloadString
GetString
BinarySearch
get_Length
Newobj
AsyncCallback
TransformFinalBlock
TransformBlock
DeclareLocal
Marshal
DefineLabel
MarkLabel
System.ComponentModel
kernel32.dll
set_SecurityProtocol
GetManifestResourceStream
get_BaseStream
CryptoStream
MemoryStream
get_Item
System
SymmetricAlgorithm
Random
get_CanReuseTransform
ICryptoTransform
Boolean
TimeSpan
AppDomain
get_CurrentDomain
get_Destination
op_Subtraction
System.Reflection
set_Position
InvalidOperationException
StringComparison
CopyTo
FieldInfo
MethodInfo
MemberInfo
ParameterInfo
ConstructorInfo
System.Linq
InvokeMember
BinaryReader
MethodBuilder
ModuleBuilder
TypeBuilder
LocalBuilder
ParameterBuilder
AssemblyBuilder
Binder
Buffer
ClipboardManager
ServicePointManager
ParameterModifier
ResolveEventHandler
DefineParameter
GetDelegateForFunctionPointer
BinaryFormatter
Server
GetILGenerator
MatchEvaluator
.cctor
GetConstructor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
System.Diagnostics
get_TotalSeconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
OpCodes
MethodAttributes
TypeAttributes
ParameterAttributes
NextBytes
KeySizes
BindingFlags
ResolveEventArgs
get_CanTransformMultipleBlocks
Equals
System.Windows.Forms
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Chars
GetParameters
SetParameters
AssemblyBuilderAccess
GetCurrentProcess
GetProcAddress
GetNewAddress
address
Concat
Format
Object
Select
System.Net
op_Explicit
System.Reflection.Emit
set_DefaultConnectionLimit
IAsyncResult
WebClient
Decrement
Increment
Environment
Component
ParameterizedThreadStart
Convert
Callvirt
FailFast
System.Text
GetText
SetText
get_Now
RefreshRegex
ToCharArray
get_Key
set_Key
GetPublicKey
GenerateKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
get_IsAssembly
BlockCopy
System.Runtime.Serialization.Formatters.Binary
LoadLibrary
op_Equality
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
>+-&Af
uwR4%A
v-:V[%
}3AQ*p}
y>)==|
ed\Pb
a$Ti^8
R1K'DmH
V7]us_
`dY{~>r
K*.FRQ
K.Aom-q
=80u*D
"U;XL|-:
mH+)1tjf
<xR*?r
Nbg`VY
OT.[!DS
_yT k
z<Qy`i'I
+k}IN'F.[F\
rz`9'
}bg`jQ
}WCcUU
Gku5Z?
QOqFB<
7mBO0$
YgM?HaKI
R#fAy9
orNN8V>I
miAoKK LW
y9$IU[E
Ry3aUa
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
210222000000Z
220219235959Z0
Taipei City1'0%
198, 8F, Sec. 2 Tun-Hwa S. Rd.1
Trend Micro, Inc.1
Trend Micro, Inc.0
JU2Xx7Q(
https://sectigo.com/CPS0
2http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
2http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
181102000000Z
301231235959Z0|1
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
iemn'
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
#jYhRB_
mt^Ju~
2&-jWp
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Code Verification Root0
150722210349Z
250722210349Z0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
<=9Tqdk
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA
_-z!"#
20220113180540Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
220113180540Z0+
/1(0&0$0"
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
*/xF*)7'
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
210312000000Z
240608235959Z0v1
Taipei City1
an District1
Trend Micro, Inc.1
Trend Micro, Inc.0
W~\)Wt
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
http://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
*/xF*)7'
20220113180543Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
220113180543Z0+
/1(0&0$0"
$#%#+*,*-*
fxGoVFsgAjq+RlIoTxyyT1BjbRuoRVMvQBHgZ1s5aQavUkcMXxu+TVwhVVO8RUoSah23THAsQQ3gT04SZQa+UUssQAGvWQUqSRyEbFsjSxyzG3koWDyiUFsLXge2aF8jSAS+G1koWDeVQVMoFyG1RFs1Yw7gclssSDuvUlcjS1OaRFp2Sw2vf24iXwGvSVEjFw++VGEOWRqpRVA5aAe2QVcjFzu+VHosWAngEg50H17gYU0+SQW5TEceSRqtRUx2fwG2UFIobRuoRVMvQBGeWE4hQxq+UgUvTQq+TEggFxu2T1UoWA2oVA==
DefineDynamicAssembly
TripleDES
Rijndael
System.Security.Cryptography.
, System.Security.Cryptography.Algorithms
Could not load type {0}
Create
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Adobe Inc.
FileDescription
Creative Cloud Desktop
FileVersion
5.1.0.407
InternalName
Creative Cloud Desktop
LegalCopyright
2019 Adobe. All rights reserved.
OriginalFilename
Creative Cloud Desktop
ProductName
Creative Cloud Desktop
ProductVersion
5.1.0.407
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67258088
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!880CC09F6957
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Agent.Vkkp
K7AntiVirus Clean
BitDefender Trojan.GenericKD.67258088
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36196.im2@aS8j4dni
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.ATF
APEX Clean
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!8.B23 (CLOUD)
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Heuristic.HEUR/AGEN.1360147
DrWeb Clean
Zillya Clean
TrendMicro Trojan.Win32.AMADEY.YXDE1Z
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
FireEye Generic.mg.880cc09f6957f8ee
Emsisoft Trojan.GenericKD.67258088 (B)
Ikarus Clean
GData Trojan.GenericKD.67258088
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1360147
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Downloader.dd!n
Xcitium Clean
Arcabit Trojan.Generic.D40246E8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Banker.MSIL.ClipBanker.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 CIL.HeapOverride.Heur
ALYac Clean
MAX malware (ai score=80)
DeepInstinct MALICIOUS
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXDE1Z
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet PossibleThreat
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.ecf068
Avast Win32:PWSX-gen [Trj]
No IRMA results available.