Static | ZeroBOX

PE Compile Time

2023-06-07 20:28:05

PDB Path

BHNh772.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0007f60c 0x0007f800 7.93496105924
.rsrc 0x00082000 0x00000596 0x00000600 4.08356573382

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000820a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000823ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
HN=,7M
RNz('KPi0S
$'3lI<
:6v3H\~
J.EP bk
EAwSai
9531ds
Gei>H5
J{t?"pEx8
_&GuX7
^pJIv!
4feBR!
"m?T@p
qt=^Z
&Cj^(z-
Dks;zw
%>^ewK
)*5`Q]`
Yzj|GWRo
Obpft$p
P6KB1a
%p+b|(
$jbR7]
Y(<O:g=o
SoD^+D
80a~L*7nY
M2f)kO
o:H\1jl
~qmhd.+
[z@BZm}-O
E;G/jIK[
9'QdsP
?|2_CL@3
_9A{;>
JoN~3;W$
Pi?i;Y
?d|pVE
KKQjPlj]^O
h(Sy:@
D\RDT
?e%v9n
*":^+\
hOPK;O
C\PzWSU
UnWdJo]
TU\uE*
(>0['o
{2m =)+
'lD;?
90j{T
pB!8b+
'))qBt
j.v$|Q).
T(iJBBF<
1.'|%<
`sN2!4
R\(|c884&
LRP?>.
t~b7|0
54J`kx
]`'dt;
OcX]$T
y@sLSo~
5305M
vX0>J8
W&}R]*
GDe:RR
C12Zn
M'CSjz/
6FUXM !hu
~>4*BpO{
Kwh=n,
eJM"{I
E$- :D&
Tgv~%P
g9ezM aq
43lpD(
Hnn1,
Z~Oko[R{
4S~1?m
r>00Dk g
DoB'[O
.{CM5W
uHL$S_
WYe6"
S/D~rpj
I{zW11l
vWJ!@Y`
r*39<9
P{CfHK
\7:GX$
EQI<+ktp
i`{]ym
_`CJc[
<3Y$eH#X
w&u?/m
_3o!v4
'p}i@0
iA.m+'
9Yho&M,
xW^+L<
g_cuZ,
5_Op20R(
"HfX)^
tjX#ps49e
fj"a 8
C4)HG/
v<!{9OW.
6ksVF>
+~RDR|
*vk =p
&<6n#8
rtQiz}/
@qL82A<
P>q|jQ
5zVP[V
)8Cgj62 V
q7w'UJ%
"\gtH
``)l1$k
8X5jPn|
<Lr7D|m@x'
[V85w~
=H%CY
(V:A\w
4PKkF(
=?0YI[
^ydWFJs{
2FUtGYU
%30hE7
g=HL^$
wETUXt
Lr$!U.
0y3-uM
JrZiID
8Ag.aw
_8t7DP
%HEFd"
`1\x\^
&nT?m>
:xDU+*
e@\Yp&
;hf,4J
!<?yA|nvK6
W;:;4*-
k`h}#A[iUSk
;JUx2q Rc-
e=iGPoT
Hzk4Ly
G*|mCte
\3q{z@
qY#IHV{
a7%KHla
D =r9)h4*pU
+#O'(#
XQ,{+RF
Na@Qg3
~_Aws-
T$UB.h
q1Am#!~9\(
3u~ Bv
J`'e6X
SP0BpWa
lZBn.T
c;F'k;i
+;"8&j
B5/_S*
>D eE'
GK'Nq
'hZU>g
17>W=VeI%
/PA *!I
aulAz5
e/A\Aq
+HO4g>
6e5Esw
CQ.-}n
Q81:<G
Wj <"V
I~6c7T
=n96ri
w,&$r1
[9Vjdrn
8lPos1
@]g29@W
SZC|,l
~/NBc>]
\(|rqj
%qK@PY
k7J,nu
?>d@&B"
yz~P5M~
F !CZMw
}-Zg%ah
:<{S&(
iZ'=#J
LvXl"b
Bxvf/.\h
hR~@=
L<?bAS
!u]?f
\lEijo
wPRLT;
ofcU]-
Ys0"t!
Rt}cM0
{TI>6d3+
PO(_Wve
P\v/:E
73#sh3
SlvPw&
%?U-Rr
y6Am}tX
-*:8*r
],Me;{
.;YVr3
(q!S48IdL
`?9!D_B
R`6.ZzP
^R~+S
<NiwP'
,zqWto
*/XD6&
,\7`"~
4\g8Mz8
XLcn|C
;z~S{=f
(s@.qF
.%'Wz
+aob;>
\#}Qq0
pMEG wU
%Qqbu!7
<Un4)5
9G'N.m
<0P6&
+ 0-Z2
q083\i
)=usk~
pn'.|t
Na8_kcj
,^R*QU
/_e*'OlL
cQZ?93
jdbhz[4
#;,f4c
6[de`
g:i%0->#.
`t!|'L
Pe$u)L
puG@^x"8v
g)n!]i
[!qke
rkc>t_l
N3y:U'
iB2lg;E
& Gq;-
ysk_#?
:x\O%!
bfh?v2
sMhSVW
bUC8[j{
{UMUG7v
[86kSn@
jo@e4N
GT5p\Yf
H')f^>
3tJ#:ww
_T^Zc&
k]Y':0~
k! ^0m
-S.5IZQf`
H2E.X1Y
X*{T d
*f,`=7'J
n}PJy%
I)'Pln
qHYS<^
~]IAO|
L@Zuju
AL:M*f
xqVFR,
='lsts
^gF4o?
Wxaq*KI
>Nf8@N
*>eAuT
Q6[."B
iZ2Q}D
yo;=DH3
'/NkzO
,V^1.94
rLqr#X
&ZEwC+
'blwZRB9
s{=RCI
m%4vD.
g#z|lQ
c4xZc@
op>Q)?
>]pZ@wF
W;\(h^k
w5Pu!@
9v9I9`
^'e?`q
HI56(e
G9z17k
# 'VCm
@s!~!DW'
,twr+m@
ARLS6vcO
|u`f:}
jY9{M
#65;S-c
/jr=rr
!j^&P6i
qbyy6)
O@%ME.
<hdKH113
B.=5Na
gZ#btG
Vnm_XJ
`,mwFK
Enm7c,
7@>5*=
Qe~W@
hIAx7r
f0A9KFR
?#?=fK
(XkF]_d
:CISW`
j9cHOa=
8vow4."
,/!E)aH
<snXq-`
ALFy?][
{:w5Z.
siW9J^
v#l#n-
X5_74[E;
sj0.H>
cE'Z.^
.GQMa&}C
.;P[~r
zpryu^
O[*wp>d
d.)mB|
E2~:P`
P;WBA$b
Y**i=w\
'N"$!s
!mpvzCM
+lZF_#
sejX?DoQ
dJAuW2
b'm]I[
J4qczf
Xu5ZiX
\1m17>?
lC>&zy.
8K{a[Z,I
}9 Eq&
sW)1(&K3V$j
wo.rwUfB
QxKwi$.r%
4qRIy
3\6l+
.lqJxO\
5No}^j
2%>'`@
=:rjoe
{bcCeB;
ZzFUnsG
D`z_i[Yt
sS9/Z3
R]~5fO{
$`5\KK<t
x?jt`1
(r`wrl
CXSx5-
ybZjW
IYX`g%&
y-}.`h;
sp\)Ag
b}R4/I
o tW}km
6s)c{N
h;N}"y
wSEG(
nFXHD
">uZ>P
vlDVR:
)z'iQh`'X
7!]P*J
H48d?h
L)6=yQ
E8}xN~
\(`ujiw<
n+yG65R
G=K?U
/]WvPv
hd_Bfa
pXeX@M
kaFB?1
)WBY0!
= qgeSiy[
3=tOt^
>uwcZ<)
P/i!yl%
}MODy+
Zi@=>d#[
Q&TGCZ
ePXgtK
6!qv|H
op!W*5
%VjMb@oF
k="s5B5025
xe~L )Z
-R@YOq
sKb7b7
H1|Tq
*7l\b}^/
_q#)JR
ingcY
1L$Ozb T
'Xg6_x
RC;t'~p
$(}k~G
2%_)1=
Hd.Kz[
0sNn>A
jreNGt
JFIa)xf
x?/`H
cLw>&
5GSTS&S
r[gF~?
WIk~e`+
)=l}"z
v;tFd?
@~.}EKk
%3sioZa
JC1X<*}
"Y5/liu
E=jIk
ni~~f|tNk)
9 ;,w
f"o~3{F
'-0;FU
$g;-Q>
po'^nKh
R8T`G1
foO.+X
n`;_N
.ce}Td^
69eVV1
qJZkk|
7oTnH3A
W?3@.d
BR7D@(YR
O%>:k`J
yL?I6ZA
CsP?lt
gsIz`SE)
{v(!s+t
`GBzS+F
ygaPtc
!zVW8P
.f9(c'
ntX%t(
NOLaMQ
/Szsh+\@
r^o8-#
5=w&LD
3jCfmN
qV)/W'
aFYN]j
I_AP*q5UU
PqjE?J
3h;kio1
D.sQi)@N
"-X%}w
)}Lh(n
6D|8SBO
wUn(SXk
X$486#3
D}AWO}E
Hns/%k!5
"7(^)6
5Zi7#g
c&JChi$
My&}lr
W8IBI%
cYP+zV
OPnn=I
hA'3-Y
M4gL+$OZF\2
>-aHU8
zgl;!C
J RCBOL
\lojKt7
s~6D=g
aC1nHq
&G3Z2,
"=Q23D
0^G$7V
oNTaYfx_
4`cQ3O
$gV|hhalV
f"N~9P
5M~Av@
T^&XMM
NT:f#Z
2tV)'i
#;/Lp
MR*BVw~
<b]pV*u
Y&F8DSBI
r/KO:(
xah!llt
tD9opXG
!2QDwd
Fm8(K{
O!qKFE
~6{~snNAGmJ
0v0&$e
jCR`(2
;*dHBV
2RCysy
m2rCOWW
:FM3yp
2=iA[]*
vd"De|
PvoR&R
5+DynJu
>Ph~Ov
!}3Y?q
SIZ}Tf
2N,cxP
Cdv|(=v
J2!q9J
h=35`I
g(Ny#9
pjlH;jm
bks_CY
XZ[,$u
%x!Tlj~au
ois518
X=ck$#W
k{cB-.o<
dH.Uz.T
J~R~o2
3D%q~%I0
O<L2T&
{a /Gy
p6Tcf8
#6DFSl_g
o)B9Q#
W`(</#
n/pA(c
C-V-{m
]MU)f~9
vUD&uB
vnqb e
"jC8DF#
#2M>EDc
/VuLK2
pR=!1`
5N<a@ty
WC\YW.
)^)HFk
c1Ex[)
[Yj2#C
8fIG#B
m6Nrh
~%a=#Ph"
Ig.|qV
Q9^dgG0/
H`~%fP0*7{
Y0\"0#
V4nh5U!+
R[LXN.('
Xr7?G-
RKYO%-
nFY:v|0.
A3P$a[X
,6SJv>
s!@.Xlz^
iGkoD
12&X*Y
H}^gPLD3V
5`MI)a
r'xb{o
nlyyR1]
vqKc}4P
u`U6Y9
;Db2OG
%A3(w/
:c1,u`#
\!I5w$*
$m!!t
nE4ac6
2x|P:=6x
\ '|D_
j\gO&u+3
jZ7|')e
][!?&5w4
8Yf.,+H
E+e@oY
KNf`|N
oeGR1j
Mej~#
pa7!Fh
^DNVnF
I}m1^4C
o%:0B
'|01\|
;ON`F2
vilrq/
@S\[5<=
iq!>_nr`
Ax^$g9
@Ig:N:
s9*@0#
rr0@D'v
Jx^$c-
]?5u6Yxg
Y_}vvx
+]n8Jm
`;5qD<i
.3>=Kf
j0*(j3,MF
X]ev&D0
[%l"4P
skuz+S_
"l?OOx
7UUFA?
)!/-q\
/,1g,jduUC
NC#,Qv
@)Wfkp
AS,r2T
"M`n@L
R#"xy)
PtrG<V
f:;wCh
O2tL\E
_swyZK
P>IxCb
g'kO)Xse}
tA1u`q'
Pt}*dv
;iICz_
TJN`Tq}
wDZsx}
n"1s4{
#97;B^
_n09a}
GH%Q7$
5_er(B
a@TKGO
fRdE:
FGhjnU
bIb4TN
um\Kg[
9},IfHI6
N$Ca7Fs'
/(b@n
TnN\K)
Y5BsueM
\p7ZO'
`DVf"5
|8v`Mn
]Cz3't
$8?l6GE^#
4^-`(j
63iedz
f}+S:q
?RWvI&
Z$Eltn
^oTCAx`
eM,"Y3
J-OWfu
%Xxp>V
A[sKY
^_MjNt
L1)1oq
RJx}.D*
83C-k31
WyF^@XD
CglNA.0JU
$zV;vcx
5=`rJ=
Lsz.Pr
XpNZ4,^
l1Ebq-
eGl^n4
C"lQ-`LJ
x7E l/
8>g)Wg
kX5j'U
-uu0v-
f3>5/y#=
\Y'"uG'
)H|GT<j
wU}mae
6;M'SH
|@8R q
X|9Lf=
4?Rqz2@y\*q
.VC-$R|
WBz%-|
D4|-N>
t8pF2u
zM\zQF
iL~FFmXX
%Wt~Y|
uPe1EFj
vkYm6.
_o)j%'
!Pz^hoBi bW<
Miz[y{
6Ldf68~
\3~~$Q
k&s.l
#lp"G]
Yl](AQ
xZCh5X-=
s\vIvE
#@D^{l
fuN&n/
'7~!";"z
HDfUWP7
\"9~&&
:h1V[d
9=XP>fO
0hL\+1
Q>(a;
|SG1px?s
aRcARm
nJ._7Q
!9.Tc(_
/ZgaA}
ZL^!uu
"s4]'8
@BKpR92
;A1<Xv
2QO\3S
.We++q
IK=]"4
g/CUQz
`m\N(lj
v}U]<=
|1V3i-%lf
UZ7|@]
d+x7g9
Zq1)|"V
$lzkqu'v
,_.Z [
1LGHZa8w
QZ rP
JKZ Du
v ggsJa%
gaI9%+
qFZ 0]
8t7%&8
,7 =Ee. 6
_bj2
Vm;UZ b-
_bY*
` Ja8H
Z <>):a8
RI#a8=
Jog;Z
ls,a8g
Z #4|(a+
cFm%&83
8#;kZ
_1,a%+
CBZ ;7
_a7SZ R
i/;a8q
Z_bX
Y_cX*
rQZnZ
pG`a82
=0TZ 7
Q&Da86
JO%&8f
^{T!%+
f'Za88
d_dm%&8
V\Za8P
Z k: za8
p=Z */"
xc6C%+
h3Z GmL
v4.0.30319
#Strings
q(#dehQIY(=!"m<,OTRz2I8M#
BHNh772$
BHNh772%
cf595c41e34fae9d34a62be861bbebf51
UInt32
ToInt32
BHNh772
c8870bc13af2770de926d16fc75f3a824
ToInt64
ca7e8b056ae5b4203a039346f2f8d53f7
get_UTF8
c2135129d04cbdf3a825d2cb3976c0bc8
c3bafb76ede496e426f66e14e37129e39
<Module>
System.IO
set_IV
c1692e0dec345c6bdfc756ed39a9d601b
c92b8f3af304556f07caf6257ea1a2d6b
mscorlib
cc5c8984fa43fe4fc7bdcfd24dbfb2e2c
c3580da6fc10cb20bbe1b350fa582663c
get_CurrentThread
thread
get_IsAttached
set_IsBackground
GetMethod
c248fdb8a044a5f50e405976e03871c8e
Replace
distance
CreateInstance
CompressionMode
get_Unicode
Invoke
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
ToSingle
get_Name
get_FullName
ValueType
GetType
GetElementType
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
BHNh772.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
windowSize
dictionarySize
IndexOf
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
GetManifestResourceStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
AppDomain
get_CurrentDomain
System.IO.Compression
System.Globalization
System.Reflection
get_Position
set_Position
Intern
MethodInfo
InvokeMember
DESCryptoServiceProvider
sender
Binder
rangeDecoder
Buffer
Debugger
ResolveEventHandler
BitConverter
.cctor
Monitor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
numTotalBits
numPosBits
numPrevBits
Object
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
DyDXlviFbPYbFjBbwqqysLnWQtiv
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
op_Equality
Confuser.Core 1.6.0+447341964f
Copyright
2023
$7f84feb1-d02b-41b7-a951-b990c00d9c93
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
1.0.0.0
BHNh772
WrapNonExceptionThrows
RSDSnn
BHNh772.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
BHNh772
FileVersion
1.0.0.0
InternalName
BHNh772.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
BHNh772.exe
ProductName
BHNh772
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Remcos.4!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Crypt.MSIL
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHED
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Remcos.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.97 (RDM.MSIL2:rFp2idg6bjPQytmJeMPy4Q)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1326434
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.hc
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan-Spy.DarkCloud
GData Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira HEUR/AGEN.1326434
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Remcos.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!5A01A667C848
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Backdoor.Remcos.Wylw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG TrojanX-gen [Trj]
Cybereason Clean
Avast TrojanX-gen [Trj]
No IRMA results available.