Static | ZeroBOX

PE Compile Time

2023-06-06 19:18:28

PDB Path

NBB872.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00079803 0x00079a00 7.96682956288
.rsrc 0x0007c000 0x00000596 0x00000600 4.07763658499

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0007c0a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0007c3ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
Z ^q%Xa8
P=%&8+
L7~+8
'9."Z
crmH%&8
_}<7Z 2
Z `zK'a8
[mu!%+
kp5>%+
v %6J}a%
J%jqZa8
_bj/
_bY*
*=%&8s
:cpxZ
~Z @Bn
JjAUZ
Y+bZ ?
YZ q~A$a+
VP\k 7B9Ha%
),%&8k
Z q.g}a87
E<%&8d
Z N}t"a8
nVaLZa8
Z O)<_a8
Z_bX
q]Z 1>
Y_cX*
.[ xqT\
f HL.Qa%
Z ;l*ca8
\\rZ P
@S4Z `
thiZa8-
pZ q=c
1k-Z E
!l1Z hu]Xa8l
4]%&80
Z _wmDa8/
"4b5%+
lLqe8
Z ^urZa8
t8e<8
1C9M:}iq
Vrr3CE&
BBeH-Q
[x-cD{
{gcjxo
.^]6/o
Gbi#F>O6UyG
L{z}Ct
(__}<o
h%!73"
c$?S7w
'|r<4UHc
;_@ a>
r|>]\Ej
>gNwWU
0I/M3M
?N<0?+zv
#F_Y!!{
NF;@@t
%@j&~&
:PG;*1
h3SnzF
i~I%U+1
-4q{=3
@'%1=M
RryX1"j
%A;<Wbu
@G+{Wt
BV5S2[
>g_*1s
_ l8^<
I^`FS{
chJl"z
D"9-%g
l\G0c1
Hns2:o+B
PL(2D-
rY*6`#
h\1je|
S*ZGU7
D/pgTUs
1r6bXC
%r[P{c
%~`,f(
4nF@LCC
j#K,!l
tP}q(]i
H%TBkC/
oVy`a&d
BgEvRG
plJ#me
4-V\)W
#q8iSA
s,,(x}mf
1dl]74
R,[9P"
-wA(5C
e=J=H-
DGPO9X
R6XnOm
Q7WXqz}
YlEZvZ
N9Uggk
HrvZB<
6b&kJm
Q_eaQn
m&X-SL
Fc&lBGm!
!rADv4
%br7A[
3K4C U
gl>hQF`
>;.<aZbI
0W@o[c
?nDV!2
u_tazH?df
`Pb/;e
1kk5.'
7KB$%8
{D?SKhv
h_&}C$
"!srgw
cV(7$/
:.4ye2N
FZeoZl
h3jUJs
Rd/W|>8
0kQHXp
9Fq^dTf
jYJ)qK
|8gOo+
L..O]sD
I\|DsY
P#KT"F
6v~b&2
~0qm&+X
wy\e\I
}q"gW3
5O:!^
{qXH=/
@yGe?D
5X2'~$W
3bM"X|
wc <-K
2L_\4N
I.b^nq
+Of:r`+
:j[O'8
lpT1cR
()${"p
nl>?TA
LSjuS;
`Jf;e
7R:\NK
@ b\wQ
-5S^m J
2,t6UE
^d_CAr(V
5K?bzz>ff
qN(FY*
lTYE"L
YN`|-/
o;Bu+b{
3"C0T~
aO_4h<
_8"5V)
&LSk%QD`d
I0(hg*9
O&r]j
%N8DMM
CE)pM]
(UDKe9
;~SoJ0
M,GMw%<g
&dt9i%
<X&kP&
9a,|`fP2
c/l;2yb
#f8iH!
b*sI+Vm
D"7Lw~NuN
"[SSN"=
djI2eqz
*/i:za
N?LF32
3t:gjC
TWi|Q 9
1$PqpY
eYTxUy
Z!5YG~
=Wg'EP
OAz!gl
'CT*CZ
@_3OU2H
KOCVf
1@$h(Q4
zg9o|o2
S_~{41
chKfe+
X_{{[J
@mO;PI(a
%~xX+:
@Ugu<E-K
UMH6";
:UP`C{
eSXV#0X
/(zS`w
aI*xK~
MM`XAI
Ssi!V'X
)=Ve-S
:H3!{j
af\jR04
n`vS!W
]?<]=j
[lK/kFU
W@u(GJ?u2]]|
y*+mM?
%y~"6*
0B@F3C
{BS5mo=o
t?NGX
%@hjg}K\
$0d&Y\=,
*^]+qx
A!:ty;@z
h]<E'`[z\
q8aj%m
91vLa)
r!IR5)QR
2CpVS9`
X]O &M
+?IwA2
U.Lg%'
s%oS-0
8rj8bw
B!`3NA"
-RLx/PR
!$ -:1
5<[+E4
}BxnVa
;5>n$c7S
;Nb=Lm
!j#;tc
DXj.Qg
k}n6 $1
y<t"rs
sHCGx)
k(8(!2u
ic*ULSr
3pD4w@K
rvbv23
>(A~%R
*i<&?(
>F-0y^
&]K=r1
e\%#`~:
s27llV
ioGfzn-
,#EI,'
~P5R^"CZ
hmT8W
R{6_^%
{Rl(Xb
>U-(ON
_c.Qzs
BaU]AU
le:]2,CR
xm`0@f
{62.:Jl
Ko}V|Ks
_au*vH|
`a6~\q
[':pre
+,I!fa
s#}cS2
tH;L('
^m_Yzm=
DV!1a2
YL7s,d
Kl=7;J>
tH^q#8vm/
^H'N/#L
#+)73U
W&:hHZ
R.HcP'
0~;3EZ
mrjESI
*z\6q.
!eK9'l0?
c,:y9+9y
+ dXan
=oCm5#
lwwpjeG
.z#he8
T n}x!l
PkuBso
1G2|sVG
jxTE^s:Ua!HBYeo
Nl[kSd
1~W\=n.
GR$hM~v
PV/3&XPS
2?{8)~
w':ch4
C)KYYe
?dF(Kw
|-MpHu
<Z[ZvD
V}C795
ES1:!!
d1h[@%h
c~@$&Wo
SM Em`
f@-o,k
2+ra;S
d~ZNXv
Jk4Mr
K=}[+|{
o#=geGO
ZV;P3Z
>%Sf5Dp8
sz/hs5
-vZLi_
ho!hn)
~LJ,m*
Zf{yX)e
M}oH)/~EhxC
17q~u0
zCcX"
4DD ;n{f
m_0ujR
p.&Id87
J;wxmri
D$5+-8
GKiIrd(
b"02oS
]LTX!4
11m*o)
I8<jU/y
<:!x/%
.t=p']b4
I,KBTn
_,YVkt
2G%|pU
zLn#RBc
N5`\I-
LZ8`(lND
LUnHtqdl)
%_I.FP
{VNIL^
*9l>Q
bs_uaY+
^j91cA
+rt]kMv
\Qd;8CU~
%SsBzWe(}*
<ULM7,
#h,.m/*
/N70'k
`M&y@n
]Ws_q*
tm\\"2
K9^QsO
b-NEi2-a
L:#D$&
v}VUJEI
[UrYZx
b#pG/s
_m^LOQc
:\o9d\P
N=$x,
T=AQ3
$I)Tey
$FZ+hCV
&udC)7l$
}-ut)U
vgv/^x|
Q.7ESv.
M $VVT
g<TS[b
N2|/g=0'
I&"Wd
u/J|z=
o7*`|
6w2T7Ym
c@XE`Ct
f[C$8m
!mF<6g
Ep2v;a$
A{KaK{
}vnqEf
0bBT?Y
FFb[[3c
ARQ/@D2
Co%JPk)
o{3:NmV
g$y7(c:
m({aAre
7;Smr-wN;
F^BYW"
w-)t|+
~3>@-{K*!]^
Hr^)$-
P g@[=
3~<!Ay
0AJnpt
'\~*Gg
,VKR0A
:k@/gT
]kp=CAF
M'O+g@
F=Ky'\
[nwXrX
S_y5$i3
UiI0n$
.x)ma#
C<gZ!`
g@n62"@J
,bKoq"
n)"kM)
GS$/-F
B}:z#<
}xL$!6A\2
L,0-Na
V'+\0QE#
L~&vz.
j[T@=b
?A)_p9g
3VovaH
OH'01L
H?8gl2s
Gh5tt=/
eORI7b
MGzYr&4
\EXw'|^
vQ+F8j
uI"X?7
2K5.'n
TIvH-6E0
Kpma@c
@oqb>{VL
M#:?f*R%
,~bzr`
PQY;Ieiq/8Q
'uZcq/
Xo66|8
,^*bB+'F
s?!~dX
O_q`CG
/eWve$
{~$Ft,
G0'Kf
D%Z>X<
rc6"rV
'_XM>F}
ZN>DUxd
Au-,GQ
tbyFoe
7V=84dN
wMyGdFw
TO*uS2
W5y^lNT<M
~V"=Q
}+"DlO
GTIK^Z"
lX+#P<+_YH
qa8GYB
ts~[dR
D)C;8f
6|@zwg
ur^Br!
%n,R@J4
b,VQ<l
!E_M!r
+9*'1)
<{oExt
(yMZD.
`gj&]ay
bO(Zdl
rV1?AEd
65`zF[
wtV3tY
OQ`K1y
wtN1}^
tav?i6
\QOP(w
qz3M@K}W'6d
y#J)E9
u_warLw
/O)EhB'2
TRALl_
nfpF>(
8nD2p_Z
JwW(9
8KFH:g
)WWV@,
A)~m;Mw
$l83K50
&$eig"kq
c+eejP
9GXGiGK
}lYe_g
_nwI4jH
zL5597
'})UnK
5//1,>+
`!/{Fq^
2Zm]\6
$h^2n
AEiz0B
ihDOdh
1I}^LO
c|B%:Ye
yx39L9/c
>eiLHS
"zOMR/
x\#)/g
l%GD9a
1(>Nce
OwXten
pqnA9E
QhX-FW
e@_8w+
D37Zk2
2-3`+,
v@f|H2
z6"6qA
;@Fnofn,
'wCaa*5WfAZ
"tj#x<'
$@*SpO4N
ZotL E.
/FXJuf
A^kL:&"K?c
e1Hpq]
qNE0z+
V%k2f
|,ree
W(f9$|
?rM\?Ur
r{X4Xl
?}/eTG^?
0t8!6`Y
'M&5g$
)O$IU`:
:b{#|D
HI;L^H
c~4qnx
vRd~WA
*NGCE<
K2Aqc{
v$E982J
:4E%d/
[hdm/p
n(J6>x
-#X)ry
^2=Xp97C
JX:<Mz>l
+:3q)O
q\OVJM n
IsDG2O
>,_)S:;M
eJLH"=
wY&qd^
hw>'NcZ
D0pYnj
:3U9)w
~dZy[ )i
C2|\qF
PkjVs
7F%|f:
t+Qh5Wt
,EnDrj
*0loa
,,BJ0v
eMUr#x
).X51A_
IGm/b
"K*jv6
oYkc`o
.`B\jV
8bB";s
F.]*\?(1
SDpOyr
d~t0`$
l&50e>
LI|.T5
NOSLep
b%AP"!
>)wcBm
E-yOis
Eivi}6
TauL6r
m@r37&DV
0i&6Ri
v>4"jq
9%]nG5:
t]FFk~
2iSOD6
Z;bjEm
zQ3/ J
|Js'#U
Cf!=@*7
g+=vGO
+9xrE3
Q*LFT&X
mVX-R!E
YU$M-/
h) r~eL
QW2qB)V!O@
-$d|;h
Jj_)!w
p0vEfU[7P
Y'% ]z
_w@Mts\
e&kmApq
S?Mq@<
"0(tR|
bva=LU
lh'J5`
O&7va:/H
ycA{a[
*4-HMC
<R&Ng2
qF#%J^2
QTH,8^
Y4'Y1b
;hV8JBS
AFm4M
kVCrD5>->
KLD2kh
w?_5k9
7|Ut<B
u$Wl}~^D
?[ ^~l
k</o.v
rcdl_ua
+4'In%{
J:*mv*
3 M:tOJ
"ZB[2>
.K<jV]
P('.3SXgFH)
N}slN:
nWmX`Ec
P:xGak
``SA'b
5lVYL'
R%pBl.
f-0\a]
(n=_S$
NAm2A
n`zI|=
3Lg43.0I
xsnc?H
_'uzz"
>+>Th'5
y>OsR#S
(.Q_qU
gy-nd\
8jDa~d
Ce\G},6
:/Q]4K8g0
,,y=FTQ
BR/Y#H
b7}G/Z
27/'#yg
Rv4A%r
aZmj7W{
=uVAWl&m
z^h3:^w
8VL,:vS^
.|({bs|x"
eB$jZK7
M]lWlr
]5(e^
0V%:L#i
l*>U*//#,
hR]zSq
3{tJC-%
k%8|PK8
v<gR+H
kKOrjK
Tb=:bws
t9Ck(^
'f13bZ
zlm?.E
QSwPpw
Q"J@#
j^_)$R
]t_d^h
8C@X\:
^4oTxCg
S:3xTj
Th dts7{
8A%X9.
SgHM(,
u@2[yY
%WY(z4Hwd
6<YaH:q
rBa~s'B
0^o_c
+&ppY}j
M'j7Q=
4CiL&Q
bD4\tU
evs=r]p
-yvf3L
d\2MQe
&3^B Z
qTC\8E
G9`$t8
[CWfn'!
df1cfs
OL`QB]
RYT\,}u
3 pJZ8ZN$
7y<wD^
_3CFD@4
}&&ORY
M.N_eh
[]\*e~
(TX{-d>
mP;qSv
R0&*{/
. ~q;
`2|T,xV7'
LdLQm j
Iei8h*
\j>"W',
T0,?0-
-%7/!
RT@m0A
b%K@$n
9`~PO?
Cu2!1D;
m[*8JR
^qsg:ah
NO\0Hif
1S)\!}&>[
V|[?_
eVmk~JV
]a'0vDb
et|3Dv
<).Ci!
Ln9k.su
(v6wiy|<
:~t0meg/
"KqzAS
Es3w-7L
L&XPeT
,SJi?&{
0ZY4le
|B3L#[
^b5[Ik
#>=;~/
S=Pxc*
LEV<A^
:YKN?Rg
~\S7^D
&(%D4s
gRnV%
n%3&o$eAA
VA1=?}
Vsju|21~
lG;(WM
CX*p8~H
bUAS~[c[
uUUv["p
bbvbZT
ZwP{bP
$oaqE9
ufd^ N
vtu]tJN
cP 2c,
E4B(W?
teqdB(
\R'/Hh
udqz$_
e~^yP\
XA_!x&{3
Nr146
v;=-]1
zsy?{/
?|"a~vA$
u:m&\L
*`#T#k
as%Sk6
7m9Cvb
[#bE%4
6\cA^ogl,
ex&{0~
9{6>`h
5.-FL #d
]O]>Q9
%b27"5
L$EcuCs
$ft]c\~
] xKE8
{wi)ITURB
#<<Y_3
=n/0>Y
d8L:%^
T~?5qL/#/
l-U%Bb2
rTAg_y0a]
[c*Z|X[
Us$,[K
b-N1H$
F{IsN
[?j!T:
4D|4-O^
e%%f\h5
T"<r91
+q@]''_
v4.0.30319
#Strings
NBB872$
NBB872%
c4534db413c199bc8f9dea693c8d34c40
cac9453cafd1497d25ec861d2bb51cf50
c5fcaefb1cf840e0e1139f9082b586260
c62dbefc691ddb84aede0a70a53008011
cf595c41e34fae9d34a62be861bbebf51
c825baf6786fec1189a0eae76559b1d91
cd10e3c0d34c2b19ad03c9df67c843bb1
ccb1e615ad13dcc4f769fbbaa71c8be32
UInt32
ToInt32
c37aed41589f9a3459f4a1cfc3b22c562
NBB872
c87d39d03d7a0fa83bad0e9f48cf52c03
ccaba5d20028d921b02b79ed0c7013063
c37cbd04ff7807644e9e0bca031436ba3
c6e4be313f6a14cfad1a74bdaa7f289f3
c8870bc13af2770de926d16fc75f3a824
ToInt64
ce0c350783b499067538710b5021fe965
c678aee7c43a634ab14b4e38901cbe1e5
c1d20b5b7d0b8f23ca38645692dd223e5
c718da5d0865f0c15f557c373644b8f16
cfe605753591ecefb0de5afddfaa74037
ca7e8b056ae5b4203a039346f2f8d53f7
get_UTF8
c2135129d04cbdf3a825d2cb3976c0bc8
cc043f03d6d2410e9f39b28a9263f33d8
c3bafb76ede496e426f66e14e37129e39
<Module>
System.IO
set_IV
c7b1b6bb6facafa48992dace8c830c53a
c552e967316b60651cc41ae2097c59a7a
c1692e0dec345c6bdfc756ed39a9d601b
c92b8f3af304556f07caf6257ea1a2d6b
mscorlib
cc5c8984fa43fe4fc7bdcfd24dbfb2e2c
c4f434da2f5676ec647ec4091af3a5e2c
c3580da6fc10cb20bbe1b350fa582663c
c73a2cd4c1bf356c5300f7f17a8b1a96c
c7c635231cd9b7e6b4bfe69697df67d0d
c248fdb8a044a5f50e405976e03871c8e
c15aefe5c4575b92e215cc6da6fdb439e
c3add3bb3ab294cf37c338e41abedd9ce
Replace
distance
CreateInstance
CompressionMode
get_Unicode
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
ToSingle
get_FullName
ValueType
GetType
GetElementType
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyInfoAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
NBB872.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
windowSize
dictionarySize
c1675bf00bf077c2c9cbaa9d027c7d40f
c9eec0ca9f66ddc8b9406b87240b5fa8f
cbc5b1df9eb318f700a67e0123907799f
IndexOf
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
GetManifestResourceStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
System.IO.Compression
System.Globalization
System.Reflection
get_Position
set_Position
Intern
InvokeMember
DESCryptoServiceProvider
Binder
rangeDecoder
Buffer
BitConverter
.cctor
Monitor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
numTotalBits
numPosBits
numPrevBits
Object
Convert
System.Text
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
Confuser.Core 1.6.0+447341964f
Copyright
2023
$acec886d-89a8-4153-9706-c2bdec389144
.NETFramework,Version=v4.5.2
FrameworkDisplayName
.NET Framework 4.5.2
1.0.0.0
NBB872
WrapNonExceptionThrows
NBB872.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
NBB872
FileVersion
1.0.0.0
InternalName
NBB872.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
NBB872.exe
ProductName
NBB872
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Agensla.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67410429
ClamAV Clean
FireEye Trojan.GenericKD.67410429
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Crypt
VIPRE Trojan.GenericKD.67410429
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005944cf1 )
BitDefender Trojan.GenericKD.67410429
K7GW Trojan ( 005944cf1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AFAK
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/Agensla.dcc9b46b
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.98 (RDM.MSIL2:Xvlm0nsmSHgGW3sw84vf2w)
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1326434
DrWeb Trojan.DownloaderNET.345
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.gc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.67410429 (B)
Ikarus Trojan.Inject
GData Win32.Backdoor.Remcos.8VU6XK
Jiangmin Clean
Webroot W32.Trojan.MSIL.AGensla
Avira HEUR/AGEN.1326434
MAX malware (ai score=80)
Antiy-AVL Clean
Gridinsoft Trojan.Win64.Remcos.bot
Xcitium Clean
Arcabit Trojan.Generic.D40499FD
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.PWSX-gen.C5438140
Acronis Clean
McAfee Artemis!66108176E22E
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DF623
Tencent Win32.Trojan.Agen.Nsmw
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AGEK!tr
BitDefenderTheta Clean
AVG Win64:PWSX-gen [Trj]
Cybereason Clean
Avast Win64:PWSX-gen [Trj]
No IRMA results available.