Static | ZeroBOX

PE Compile Time

2023-05-29 15:20:43

PDB Path

BVGg87636.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00021992 0x00021a00 7.64045569013
.rsrc 0x00024000 0x000005a6 0x00000600 4.13424218768

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000240a0 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000243bc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
<9WU@]
xW4L o
*TSnZa8>
r*s u??Oa%
lLJj%+
%-Z /S6Ea8
UahZ 2
!{M4%&+
Z {;Pa
WW(rZ
yN2M8
mH{&%&
t|w;Z
//Z PZ
_bj2
%N%&8y
_bY*
Z @BBTa+
'Hg\%&+
Z =<h
d .Z =G5Ma8
ybZ as
]9&Z G
4E%&8!
xiZ N*
wuV{%+
mH"A%&
~1Z g2
RpZa8|
Z I@a{a8n
Z_bX
3&%&8w
=Z |2
A`oC%+
Y_cX*
MEg\%&
AmS.8
Lli%&8R
JRna82
#j<z
5YZ d}
9V~Z |
R1LZa8I
acvrZ
;!Z D]h
UPfZa8m
]YZZ >%
ZhZ ,
0 ] *WU
!x.TJe
<=&ya<
WIbq-9]M.
XP=bQd_
qwP?f?(
y3+BNS[
!nauh#6WY
9OE_'b
EuYj($8
m^C~uh
8?gHm@
F7}v>c
-nmRQ&q
X~7`v3
;H2NAI
U\z6h_
72|p[J
=L&;ZT
h*kljY
cORW0x
zlT4y>
7vB*I*U
(VH7)9
usRZ^%
J?=+kj8
&h|PiAe
`S*fzA
v1RzNVx
8sUQ{-
8CJ&r#2=
G}]K!>
;9T@yi
W7yl4 d
y=34fy
UY6Koa
{WL?#m
.2Ybgv
*'R>_m
qt;iT=
qXeHj%
Lp=^l0Z
!Q:/-
C=B~M
w{!*6r
J30.$rHA
v?H 4g
i9ajZo
cq@{#)
GfYcm+ea
}|SGlH
}sTe/dh-
X-(x.
|(G%GgBn?
c/n6>J
c1f*^QW
li9c[T
(4| 7|
[FvgY,
X!0xNC
]e?c$6$N
^YD26J{
oza+@i
SyNDgnBc+
Q~zMce
!2eZcE
1R^@< j(
]hMlSy
p(uD&B
5bS<85)S
s~S'fG
"e@kGj
/$b(&S
F_<E*#
Z8JC7Gk
8IYm$Y
Xe\O>.
50e Ds
Ww?j0L
!#M!j#
ZKJVI6
p/bW<i
-:>Bs=
K[z&.*
=.i9z|
\J6M^C
`>,LoJ
d,Mq9h4
8 Ju4]d
Vg o]X
.4u(SA
d2CwHKP
y6?nI65
g^8RqnN
UN04U*
V$MQaCFw<o
4-8lNN
TQ/PgH7
M4k??'
8ip6`4
9"'*[b
[/y,Jop
"QJ[ R
]azcPGz
Zp?H^l"
w&Pfor
Xt_-"[_
+Gt*c/
14*EZwAE
>j5].e"
v<|;-
E60%w{X
`~i_3S;
5h{24]
XAPa (
h6p0Jq
idD%VM
1_^[nH
{[@:p(`
PuD4(Q>l
tW+#*EY:Z
9VCh?<
'cqM0]7
\eGB38
@@wohw
kT:hPOybQ
oi{gUhDF
biR8rW
+^lv_Mz
\eR[s'
BPivK_
4F+1`9
"S:mv/|T
HY^A8y
3=mwYt
]Ih)w[
/({3f]
|YFjHv
eYcjKq~
U)F>]5
ut?##$
JU;N7
7WyU+~
zmMr~$
h2~#'}h
a#@Z8R
clx/$v
j&<z'!
9a!jNz
s`,#r
^Px}Zd
v4.0.30319
#Strings
BVGg87636$
%/d432UBN:&L5!6tf6X1c3#V$
BVGg87636%
UInt32
ToInt32
c4b327cbfd2fef0794b968a01bf0e9f54
ToInt64
BVGg87636
c197c5a70473dd9f7934ae503cfc9dd96
c966b4882d2b282368d738412ced68f97
c85d038d38acf8426170e4bc9449b03d7
get_UTF8
c641c1c9d143583b247a5336b3d019789
<Module>
System.IO
set_IV
mscorlib
c0c4adab8d98835245666a68547c97ffc
get_CurrentThread
thread
get_IsAttached
set_IsBackground
GetMethod
c5677dadc7ef6dad73a8240897c89785e
Replace
distance
CreateInstance
CompressionMode
get_Unicode
Invoke
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
ToSingle
get_FullName
ValueType
GetType
GetElementType
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
BVGg87636.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
windowSize
dictionarySize
c05ab28bf4344137cd0fc9ad1f89cf69f
IndexOf
c350642b14790e7c68e86b1efb01943ef
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
GetManifestResourceStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
System.IO.Compression
System.Globalization
System.Reflection
get_Position
set_Position
Intern
MethodInfo
InvokeMember
DESCryptoServiceProvider
Binder
rangeDecoder
Buffer
Debugger
BitConverter
.cctor
Monitor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
numTotalBits
numPosBits
numPrevBits
Object
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
Confuser.Core 1.6.0+447341964f
Copyright
2023
$72b1916b-7378-4cec-af80-5dd07febe9e0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
1.0.0.0
BVGg87636
WrapNonExceptionThrows
BVGg87636.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
211213000000Z
250108235959Z0
Baden-W
rttemberg1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
Yd?O_{
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
$Ck&Hm
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230328144258Z0/
8q`je\
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
211213000000Z
250108235959Z0
Baden-W
rttemberg1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
Yd?O_{
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
$Ck&Hm
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
J7G[*A
K(W{,w
20230328144259Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
230328144259Z0/
/1(0&0$0"
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
BVGg87636
FileVersion
1.0.0.0
InternalName
BVGg87636.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
BVGg87636.exe
ProductName
BVGg87636
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan IL:Trojan.MSILZilla.22611
ClamAV Clean
FireEye Generic.mg.cd7722e668bab873
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Trojan.Crypt
VIPRE IL:Trojan.MSILZilla.22611
Sangfor Clean
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.22611
K7GW Clean
Cybereason malicious.599cb3
Baidu Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren W64/MSIL_Kryptik.IYE.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AFAK
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.87 (RDM.MSIL2:KrRGmNM0j5ouQxunDRyPfA)
Sophos Clean
F-Secure Clean
DrWeb Trojan.DownloaderNET.345
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.22611 (B)
SentinelOne Static AI - Suspicious PE
GData IL:Trojan.MSILZilla.22611
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D5853
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Clean
Google Detected
AhnLab-V3 Trojan/Win.AgentTesla.C5434824
Acronis Clean
BitDefenderTheta Clean
ALYac IL:Trojan.MSILZilla.22611
TACHYON Clean
DeepInstinct Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Inject
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AGEK!tr
AVG Win64:PWSX-gen [Trj]
Avast Win64:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.