Static | ZeroBOX

PE Compile Time

2023-06-03 02:51:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001ecbe 0x0001ee00 7.8810500364
.rsrc 0x00022000 0x000013fb 0x00001400 7.32441340241
.reloc 0x00024000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000220fc 0x00000f04 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00023000 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00023014 0x000003e7 LANG_TAMIL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
#ffffff
#333333
915(4
v4.0.30319
#Strings
oli.exe
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
PoweredByAttribute
SmartAssembly.Attributes
Dictionary`2
System.Collections.Generic
.cctor
ParameterInfo
System.Reflection
object
method
Invoke
nhffskdgsfkdfffdddfrffffdhffsfcfdf
hkgfffgsdffdfhhdrfdafddsshcf
chfdfgfdkffafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
nhffskdgsfkdffddadfrfffffdhffscfdf
hkgfffgsdfffdhdrfdafdfdsshcf
chfdfffdffdafsfhddhdshdghf
nhffskdgsfkdfffdadfrfffddhffscffdf
hkgfffgsdfffdhhddrfdafddfsshcf
chfgffdkffdaffhddhdshdghf
hfsdkffddgfgffhsefdfafdchd
fghhfgsffrfddffffdfffddshfdasdfh
cfhdfffdfadfdfrsfsshdkfffgh
hjfdfffhfadfsffgdfdcdffffshj
ffghrgfdfffffdffffkhsjd
fsfddffffddsdffgfefdfkfghj
gdddfffddhfsfdgh
fhfsdsdfhffddfhhs
hsffffd
ffhfsh
shsdfffasd
sdfffsfh
sdhffffssf
sfsdsfffs
fsffdfshs
gfsffsd
gssdfads
gffshfsgfs
gfdfgsfdg
gsdgdffshsg
gdsaffagg
hsffgdafs
adssgfdds
jddfgsfsf
ggfgssfdfh
jfsdaffdffgg
jffdffgsfgfdgs
jsfsffffdfdf
jdfgfffaf
gdfddsfgfdfdj
kfdsfsfgfh
fsfdffg
sfffaf
fdffsfs
sffssfd
jdfffssk
sfffsdv
gffffssds
gfssfdfdsx
startupInfo
lSoSlffrScdmrdeSggjbdmdSpjSmjedjcibihmAmlkbiemAmkhmSSmrSd
jdfhfdfffssdkfj
hdffdffhfasdkfsh
hdffhdfasfffkdf
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
oli.resources
{ea67f1bf-3f34-4c73-9ccb-1a23f948ffd7}
Console
WriteLine
System.Management
ManagementClass
GetInstances
ManagementObjectCollection
GetEnumerator
ManagementObjectEnumerator
get_Current
ManagementBaseObject
ManagementObject
String
op_Equality
get_Item
ToString
MoveNext
IDisposable
Dispose
System.IO
ReadAllText
ChangeExtension
Concat
WriteAllText
TimeSpan
op_Subtraction
get_Hours
get_Minutes
get_Seconds
ReadLine
Convert
ToInt32
Directory
GetDirectories
SearchOption
BitArray
System.Collections
set_Item
SetAll
Boolean
get_Length
get_Scheme
UriSchemeNetTcp
UriSchemeFtp
get_IsUnc
ArrayList
Double
ToArray
Remove
Assembly
GetExecutingAssembly
get_Location
GetDirectoryName
get_Chars
Exists
EnumerateDirectories
IEnumerable`1
Subtract
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
ResourceManager
System.Resources
GetObject
FromBase64String
Encoding
System.Text
get_ASCII
GetBytes
Rfc2898DeriveBytes
System.Security.Cryptography
DeriveBytes
RijndaelManaged
SymmetricAlgorithm
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
MemoryStream
CryptoStream
Stream
CryptoStreamMode
get_UTF8
GetString
ToCharArray
TrimEnd
Resize
RuntimeEnvironment
System.Runtime.InteropServices
GetRuntimeDirectory
Combine
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
Marshal
SizeOf
ToUInt32
IsNullOrEmpty
IntPtr
Exception
BitConverter
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
get_ParameterType
TryGetValue
Intern
GetManifestResourceStream
WrapNonExceptionThrows
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPO\
-}gIs[
"z\`Vj$
,~Ii]K
6U+'dK
#Q!(C/
z6\@af
nf;un@t
yDs@y:
/r]`SgqGuEsk
&xTjPc`K
;do;-5
*mNoHX
LEvmFW
,,<z
S|gH~w
'q~T>Z
_aViB_
KOrExD
`lYvq\
fbThB^
'mOIyY
WziJ|x(9
Hdd\tu|
&{tv{7
,]Q&p
#nKJq@w:
/u{[haB
/iM`kKS
?0.Y]sIm
:yYaMQ
$}H~h"
i|UiG[
QnIJlKxV
;uiG]uV
&?{aW_
jmJOdA
8xkShqoE}W
Yl[v{y
Fe\sq[
dW`Uym=
R~@tP@
>`~1W$
;i]pwZ
FmTqpJj0
!oU]`Sb[?
7y_]}5
Ifam~WjMZ
Of]oYurS
Dg^uv)
kIS}BwFu<
rGpKnV
)8bIvS
o[k_km
AmUwqS
,nFfpd
Dg^yMwj)
CkeRlYm{d1
lSxiHo
=umPef@
$#uAqC
eWaSme
*gaMytK
[\zFvK
5o_kcq'
mZunI
?7ZaQeQ
&,;zb4
AhUz}>
M8:xa,
gRfPr|
JafRut
Kc_iW}eE
MsF|Xmo
/ah;DQ
=yWmEY
@oqs`@
Xh^bl<
BhXxO`bh
IbaF{f1
NJt@sM}L
5{cqvX
Kj[oRw|O|
_+jRdb
DfbLxJ
QQ"kw1
9y[f^]
(iLKvHt
R{pyz
iXmdV
AmQ`UdcNyT
nYtmJw
o[mYuw+
QceXfzOxS
mPiF_~
vOrEx=
PdRnLQ
RIO/:r
hGxCr`=
rlO`c\
H|Nza0$
)s^tEpO
'slAy5
+ShK`_
"zX`NJ
yQkMOg
/xuyo3
AXwBo6
PoZgn5J
tZbPpv
pErMf7&
PvyjF3
/kMCy9
%lS^~<bw
,}bKxR
@j[nYtoAWK
]/YZ{DqN
?~cx 1
dRnHT~
\hz5gp+lIR
V*pauO
QjINc8
au_aUiA
{TiJO
o^xtUn`@
-~gHxR
Ic^qoReXT
]_wKd9A
G^uDtF
[[yCn1~
i{YaQjc
ZIoHU~J
pCrKg1?
W6`voZ
jUu_q;
XqvK|R
7jaP~F
2eYUeu
BYxMzV
[ecOIH
eMMwW3
R{lOFxR
<.$w^stwz
,"yXmZ5 zZnXT
rGsCqp]F
3Hd^tl
M'v_cM7
Ic]quU
yTkNQ
`"/3<{
a"@;(d
}(*1=
U21Q8F
*8=G,G
^.;S*=I96F
s+*A%!v
:K9=G22}
fh4!_)D
2%7F)0VF
Z;,R#L
>"A6?G7,k
}*-1G*Q
U-T#?b
`$>E [
Y.$K#W
|+=<H0
A>K6<R5;P?^
d&&qly
x-&A'>c
1Z92TG
X#6T;.
4(5C%.2I
+=<@ G!D4+\%
}*-)E%H
e$7C%5B+L
s:<=?;I<
w---7h
j`"FMN
hM.(~P
I|1W|'Fm
Ex!.f^
a\7HXp
\b0(r\
@z4Pa<
`*dX<>df
{i#Ft&/~O
I3\v,$~T
ux1Ns&+`c
y_7KQe
Ds0YWg
dj @t("g^
dj @YX
9SVg6
r{.Aq+&
F{4)va
O5Xn45
vs4Qh)
N;Ty"Lf
D(^`L4S}#Id
jF:P[d
F.Ub5
Z-Yd1.w\
Cs1XvT
@v,Ej?.
mB=P}&Hj
Rqw`Mm(
+fXtL{daQ
%wdHwoHj/
}-,B/%k
ZS&B@!4H
e<%]$^
`*8R%%a
Fq|\_vNd
TcVaRefQ
AdeWoz*
B(rcH
#ypaON
8sq^u}
-iNCyI
]`Xi^hn
Aji]ri(
)t]`WjEXy<
#~YdMP
/r]`QdSnIT}@wJe8
C^yDm0
!|UhOR}@qDsNi4
A\uHo2
PtvzOt]ji
/}gI}Q
^t7'j[
R\db)x
RH qj9.'
My7T-d
KfaLvZ
@>/[ C3;Z
A\uHo2
%x_bMP
'zUhILk6
9|[fQlEX
GZuHi,
%xY\{FqLe8
)t]`WjEXy<
#~YdMP
/r]`QdSnIT}@wJe8
C^yDm0
!|UhOR}@qDsNi4
A\uHo2
QyA6IHswfQ==
b3JpZ2luYWx+Y3M=<Ly8gQ29weSBvZiBvcmlnaW5hbCBjb2RlIChub3Qgb2JmdXNjYXRlZCkNCg0K0SG91cnM6ezB9LCBNaW51dGVzOnsxfSwgU2Vjb25kczp7Mn0=
QWRkaXRpb246IA==
U3VidHJhY3Rpb246IA==
RW50ZXIgVmFsdWUgb2YgTiA6IA==
RDovU2FtcGxl
R3JlZW4gY29sb3I=
MS5EaXJlY3RvcnkgTm90IEZvdW5k
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
Mi5EaXJlY3RvcnkgTm90IEZvdW5k8RWxlbWVudHMgb2YgQml0QXJyYXkgYWZ0ZXIgc2V0dGluZyB0cnVlOg==
CUluZGV4IA==
OiA=8RWxlbWVudHMgb2YgQml0QXJyYXkgIGFmdGVyIHNldHRpbmcgZmFsc2U68bWFpbHRvOmFydmluZEBpbmNsdWRlaGVscC5jb20/c3ViamVjdD11cmk=hR2l2ZW4gVXJpIGlzIGFjY2Vzc2VkIHRocm91Z2ggTmV0UGlwZSBzY2hlbWUgb2YgSW5kaWdvIHN5c3RlbSB1c2VkIGJ5IHRoZSBXQ0Y=lR2l2ZW4gVXJpIGlzIG5vdCBhY2Nlc3NlZCB0aHJvdWdoIE5ldFBpcGUgc2NoZW1lIG9mIEluZGlnbyBzeXN0ZW0gdXNlZCBieSB0aGUgV0NG0ZnRwOi8vQUJDLmNvbS90ZXh0RmlsZS9uZXdmaWxlLnR4dA==$R2l2ZW4gVXJpIHVzZXMgRnRwIHByb3RvY29s,aHR0cDovL3d3dy5pbmNsdWRlaGVscC5jb206ODA4Mg==$ZmlsZTovL015U2VydmVyL2FydGljbGUuZXh0@R2l2ZW4gVXJpIGlzIGEgVW5pdmVyc2FsIE5hbWluZyBDb252ZW50aW9uIHBhdGg=DR2l2ZW4gVXJpIGlzIG5vdCBhIFVuaXZlcnNhbCBOYW1pbmcgQ29udmVudGlvbiBwYXRo$VmFsdWVzIGFmdGVyIHN3YXBwaW5nIGFyZTo=
UFFS0VmFsdWVzIGluIGFycmF5IGxpc3QgYmVmb3JlIFJlbW92ZQ==0CgpWYWx1ZXMgaW4gYXJyYXkgbGlzdCBhZnRlciByZW1vdmU=
ZGFkYWg=
ZGRkZGRkZGRkZA==8U3VidHJhY3Rpb24gb2YgdGltZXNwYW4xIGZyb20gdGltZXNwYW4yIDog
U0BMVCZLRVk=
QDFCMmMzRDRlNUY2ZzdIOA==
AA== elBPKzBJa2twVnh3Z3crR2tSZTRMZz09 Ty9vM1lFSkdubm5BdGVqMUxFZVNBQT09 VHo2MVdsNG41K0RGanE3NFhqZ01YUT09
RHluYW1pY0RsbEludm9rZVR5cGU= SXN6UFovOGtidTJzL1BoRWIzWWZ2Zz09
PGh0bWw+PGhlYWQ+LPG1ldGEgY29udGVudD0nSUU9RWRnZScgaHR0cC1lcXVpdj0nWC1VQS1Db21wYXR2aWJsZScvPg==
PGlmcmFtZSBpZD0ndmlkZW8nIHNyYz0gJ2h0dHBzOi8vd3d3LnlvdXZ0dWJnZS5jb20vZW1iZWQvezB9JyB3aWR0aD0nNTYwJyBoZWlnaHQ9JzI3MScgZnJhbWVib3JkZXI9JzAnIGFsbG93ZnVsdmxzY3JlZW4+PC9pZnJhbWU+ dUN1eWdNbitFOTUvbkdSL3YxOG1UZz09<d2I2N1RxSktpeWdBSzlXN3phcC9RU2llRHpHc0hESDhBOG94Z2RFajFTMD0= OCtqKzhqVXJYNEtubFRZdDZSakZGdz09<dm93NE9VSUtqNW9WRVpjT3dJTWlVMnR5bmh5OEpTRzJwNFNSaThtV1Z1Yz0= M3dxdENJTVI5VDZ2Y2FJNmtUT0FNZz09<RG1heWd6a2NBWjZwOTFpTUtwZEVGZjliV2U1L2hLMVN4UkY3anFZSEJiRT0=<OUJFa0V6WHJtUld6TSt2R05oUnNyekt1bEk0NWNvY0ZlQXhrTGpEWkJEYz0= aGlxRUhZNnBqb1RaN3Frc0YwU3Y3Zz09 ekdWRXdUNjhtODVYM1o3SGRZa3NLQT09 alBad2tNMmxreGlNdkRSZHpkdldLZz09<cy81eHM3czFRR2ZBbVFZcFFkenZtdnMvV2VKeitWRmdyVmwxNWgvRHNBYz0=
_CorExeMain
mscoree.dll
[Ok[1H=
iu{GN=
*~mtg0>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
{ea67f1bf-3f34-4c73-9ccb-1a23f948ffd7}
MAINICON
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.67450215
FireEye Generic.mg.e49ec6789a1b633f
CAT-QuickHeal Clean
McAfee Artemis!E49EC6789A1B
Malwarebytes Trojan.Crypt.MSIL
VIPRE IL:Trojan.MSILMamut.11009
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.67450215
K7GW Trojan ( 0059df7d1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36250.imW@aG7tytaG
VirIT Clean
Cyren W32/MSIL_Kryptik.JLT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Stealer.56014de1
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Kryptik.132608.A
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:1wNAsHiauz/YpnqlvW7lZw)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen8
Baidu Clean
Zillya Clean
TrendMicro TrojanSpy.Win32.REDLINE.YXDFIZ
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft IL:Trojan.MSILMamut.11009 (B)
Ikarus Win32.Outbreak
GData Trojan.GenericKD.67450215
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/Dropper.MSIL.Gen8
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Malware.Win32.RedLine.bot
Xcitium Clean
Arcabit IL:Trojan.MSILMamut.D2B01
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Injection.C5430792
Acronis Clean
VBA32 Clean
ALYac IL:Trojan.MSILMamut.11009
MAX malware (ai score=82)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDFIZ
Tencent Msil.Trojan-Spy.Stealer.Gajl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.ADWG!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.9bd194
Avast Win32:PWSX-gen [Trj]
No IRMA results available.