Static | ZeroBOX

PE Compile Time

2023-06-03 07:40:31

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001a6ab 0x0001a800 7.84401776914
.rsrc 0x0001e000 0x000a57e9 0x000a5800 2.68169998398
.reloc 0x000c4000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_ICON 0x00080de8 0x00042028 None SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000c2ed2 0x0000005a None SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000c2ed2 0x0000005a None SUBLANG_NEUTRAL data
RT_VERSION 0x000c2f68 0x0000045e None SUBLANG_NEUTRAL data
RT_MANIFEST 0x000c3402 0x000003e7 None SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
#ffffff
#333333
918(5
v4.0.30319
#Strings
nSgraAjI.exe
nSgraAjI
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
PoweredByAttribute
SmartAssembly.Attributes
Dictionary`2
System.Collections.Generic
.cctor
ParameterInfo
System.Reflection
object
method
Invoke
nhffskdgsfkdfffdddfrffffdhffsfcfdf
hkgfffgsdffdfhhdrfdafddsshcf
chfdfgfdkffafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
nhffskdgsfkdffddadfrfffffdhffscfdf
hkgfffgsdfffdhdrfdafdfdsshcf
chfdfffdffdafsfhddhdshdghf
nhffskdgsfkdfffdadfrfffddhffscffdf
hkgfffgsdfffdhhddrfdafddfsshcf
chfgffdkffdaffhddhdshdghf
hfsdkffddgfgffhsefdfafdchd
fghhfgsffrfddffffdfffddshfdasdfh
cfhdfffdfadfdfrsfsshdkfffgh
hjfdfffhfadfsffgdfdcdffffshj
ffghrgfdfffffdffffkhsjd
fsfddffffddsdffgfefdfkfghj
gdddfffddhfsfdgh
fhfsdsdfhffddfhhs
hsffffd
ffhfsh
shsdfffasd
sdfffsfh
sdhffffssf
sfsdsfffs
fsffdfshs
gfsffsd
gssdfads
gffshfsgfs
gfdfgsfdg
gsdgdffshsg
gdsaffagg
hsffgdafs
adssgfdds
jddfgsfsf
ggfgssfdfh
jfsdaffdffgg
jffdffgsfgfdgs
jsfsffffdfdf
jdfgfffaf
gdfddsfgfdfdj
kfdsfsfgfh
fsfdffg
sfffaf
fdffsfs
sffssfd
jdfffssk
sfffsdv
gffffssds
gfssfdfdsx
startupInfo
djnfjdridIaenoFrmIffFIdSkSdFAmFAo
jdfhfdfffssdkfj
hdffdffhfasdkfsh
hdffhdfasfffkdf
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
nSgraAjI.resources
{a0a47d65-c25a-4a5f-b13f-01d9d0effb7e}
Console
WriteLine
BitArray
System.Collections
set_Item
Boolean
String
Concat
get_Length
System.Management
ManagementClass
GetInstances
ManagementObjectCollection
GetEnumerator
ManagementObjectEnumerator
get_Current
ManagementBaseObject
ManagementObject
op_Equality
get_Item
ToString
MoveNext
IDisposable
Dispose
System.IO
ReadAllText
ChangeExtension
WriteAllText
TimeSpan
op_Subtraction
get_Hours
get_Minutes
get_Seconds
ReadLine
Convert
ToInt32
Directory
GetDirectories
SearchOption
SetAll
get_Scheme
UriSchemeNetTcp
UriSchemeFtp
get_IsUnc
ArrayList
Double
ToArray
Remove
Assembly
GetExecutingAssembly
get_Location
GetDirectoryName
get_Chars
Exists
EnumerateDirectories
IEnumerable`1
Subtract
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
ResourceManager
System.Resources
GetObject
GetTempPath
WriteAllBytes
Process
System.Diagnostics
FromBase64String
Encoding
System.Text
get_ASCII
GetBytes
Rfc2898DeriveBytes
System.Security.Cryptography
DeriveBytes
RijndaelManaged
SymmetricAlgorithm
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
MemoryStream
CryptoStream
Stream
CryptoStreamMode
get_UTF8
GetString
ToCharArray
TrimEnd
Resize
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
System.Runtime.InteropServices
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
Marshal
SizeOf
ToUInt32
IsNullOrEmpty
IntPtr
Exception
BitConverter
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
get_ParameterType
TryGetValue
Intern
GetManifestResourceStream
WrapNonExceptionThrows
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPn
#cslZ.
ng~qw)
`[}B{{Z=
SFUk0(
tXa\bU$/
; PVgg
e +mp[
u{`c<
{qo[/$
(ouGhP
UmE)4PEZp
6a~|mn(1ut#
VNe?=:
C`\95M
Ae`CtF
lOJxC|cY
<UXvIN
K]SWuB
R\cJx{ljQ
sznh]p3
'tHK~2
NbLP{<
M'54A
ifcOvu
!nlT{<
?XaqUe
lhS4Ex&
&U^q6D
`kLpY+
XS`q_zA
lTa\Hc4
iWJPsN
]j{NlP
<gyLw9))
'g~qwQ
"QgJU{r^gb>
J::ZTi
P !?5:
Kq~VsH
k'R#M?
~xWuCO\
'(St`J
KA[l|Z
2dpaR+
_Eo`Y`d
\rFLs/
)ftd~)5
bcmkW]
eIpgL|
aip_}Q
?RUgfs:
`wdVD};
*MJP~J
P`j}x[}I
|xZ{H%M
]Un>Z9*&o
_62<G!
Kp6;|0 #k
e[}|Sg+
ZFXiz`,
h(lf, L::
<qb$u
KJ{N/;gd
?xPd..d
V/`ohTq
0a)<.
@K"Kr"
TNG{HG
fqlhnIvD
lhlLk$
Fqo^z@
zUF~jH
Y@xlW,
P.ivdU,
YN^ilc
Q_YjrL
VCZVx55
;@col^<
TOu-95
Q.'NQg
WGlNp<
\@EYs*h
@LQDY/
9LobdU_gD
pn7rrpyia
y}d\_]/
IVzPn;
V/?9\&M'
\8G-(R
k0M%A"
Pp&3*l
D~>)X_
#BEj:
'S7s~k
T8/Q%z
?,X?/r
;A64S23
}94XK"?9q
}=W$G%r
j3C .a
<4;$*-K
r|J~k=
02gyd0
a(`unH
0jRNuV
Dvvi_L~L
ns~aeD
nwSkb8
3vqUtg7
4Q9%;%@
QXW`pR
'OORe"
9|~Gm3
1}}YxS
^$6)V{dU
]VwYw1
9":3`yM
5dzCieU
]@KZq(
-ZOZlhE
.muIu<
vIyzcd=
Kijwad?
?x|abK
7asVqbJ
#7fq_y<
&"9-7%K
-~NT{+
J('\]b
=<+azJ{6
\4-\sWo)
1`wVu:
CIcj0
5seHrnK
GBiI-9
Y`fyinK
"WiZ3.
>Y$'LqY\
HdiKpA
Op=9!a|
msz]~G
T8"bxA
a`q8r
-tbhO}S
pEw~aW
iB|lglE}*
Dnfo3G
?%!<8w
EFjfa9
6u{mGr>
+{m}dt_(
6&,/0!
,gpZsK
vuXgfH
%:81-#
1y{ToF
%ydP{Q
lMsep<
QyA6IHswfQ== RWxlbWVudHMgb2YgQml0QXJyYXkxOg==
CUluZGV4IA==
OiA=@RWxlbWVudHMgb2YgQ2xvbmUgb2YgQml0QXJyYXkxIGkuZS4gQml0QXJyYXkyOg==
b3JpZ2luYWx+Y3M=<Ly8gQ29weSBvZiBvcmlnaW5hbCBjb2RlIChub3Qgb2JmdXNjYXRlZCkNCg0K0SG91cnM6ezB9LCBNaW51dGVzOnsxfSwgU2Vjb25kczp7Mn0=
QWRkaXRpb246IA==
U3VidHJhY3Rpb246IA==
RW50ZXIgVmFsdWUgb2YgTiA6IA==
RDovU2FtcGxl
R3JlZW4gY29sb3I=
MS5EaXJlY3RvcnkgTm90IEZvdW5k
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
Mi5EaXJlY3RvcnkgTm90IEZvdW5k8RWxlbWVudHMgb2YgQml0QXJyYXkgYWZ0ZXIgc2V0dGluZyB0cnVlOg==8RWxlbWVudHMgb2YgQml0QXJyYXkgIGFmdGVyIHNldHRpbmcgZmFsc2U68bWFpbHRvOmFydmluZEBpbmNsdWRlaGVscC5jb20/c3ViamVjdD11cmk=hR2l2ZW4gVXJpIGlzIGFjY2Vzc2VkIHRocm91Z2ggTmV0UGlwZSBzY2hlbWUgb2YgSW5kaWdvIHN5c3RlbSB1c2VkIGJ5IHRoZSBXQ0Y=lR2l2ZW4gVXJpIGlzIG5vdCBhY2Nlc3NlZCB0aHJvdWdoIE5ldFBpcGUgc2NoZW1lIG9mIEluZGlnbyBzeXN0ZW0gdXNlZCBieSB0aGUgV0NG0ZnRwOi8vQUJDLmNvbS90ZXh0RmlsZS9uZXdmaWxlLnR4dA==$R2l2ZW4gVXJpIHVzZXMgRnRwIHByb3RvY29s,aHR0cDovL3d3dy5pbmNsdWRlaGVscC5jb206ODA4Mg==$ZmlsZTovL015U2VydmVyL2FydGljbGUuZXh0@R2l2ZW4gVXJpIGlzIGEgVW5pdmVyc2FsIE5hbWluZyBDb252ZW50aW9uIHBhdGg=DR2l2ZW4gVXJpIGlzIG5vdCBhIFVuaXZlcnNhbCBOYW1pbmcgQ29udmVudGlvbiBwYXRo$VmFsdWVzIGFmdGVyIHN3YXBwaW5nIGFyZTo=
UFFS0VmFsdWVzIGluIGFycmF5IGxpc3QgYmVmb3JlIFJlbW92ZQ==0CgpWYWx1ZXMgaW4gYXJyYXkgbGlzdCBhZnRlciByZW1vdmU=
ZGFkYWg=
ZGRkZGRkZGRkZA==8U3VidHJhY3Rpb24gb2YgdGltZXNwYW4xIGZyb20gdGltZXNwYW4yIDog
blNncmFBakk=
XHdzLmV4ZQ==
U0BMVCZLRVk=
QDFCMmMzRDRlNUY2ZzdIOA==
I3ZiY3BhdGgj MXRjMXdtaUl6K0VIZk5PRGlhZ2ltQT09 Rlh2L1M0akZQRGRxT0docStWeHg3UT09
RHluYW1pY0RsbEludm9rZVR5cGU= SUxNTkVoN04wVDJsOVBWb21BWWU0dz09
PGh0bWw+PGhlYWQ+LPG1ldGEgY29udGVudD0nSUU9RWRnZScgaHR0cC1lcXVpdj0nWC1VQS1Db21wYXR2aWJsZScvPg==
PGlmcmFtZSBpZD0ndmlkZW8nIHNyYz0gJ2h0dHBzOi8vd3d3LnlvdXZ0dWJnZS5jb20vZW1iZWQvezB9JyB3aWR0aD0nNTYwJyBoZWlnaHQ9JzI3MScgZnJhbWVib3JkZXI9JzAnIGFsbG93ZnVsdmxzY3JlZW4+PC9pZnJhbWU+ S0pTamdNdTRMenA3Y1FzRzJ4bjNsQT09<cHQ5WUJjN2RaQU9kRGFyU281Qit1QXpOaitiYlBkZE9LUkVsZGg1S011Yz0= SHg0Z0lpc05kMDBjUXR4R1l2T2pZdz09<S2s2eW1XcnlkR3ZBQ1U0TkdXSGYyam9mM3dWdC9ESytsQXdEakFnSFc5OD0= a2tZRjdVb25kbkljZzBVc3VYTUZ2Zz09<a2pEUHdFVG5wclhBenBDY0ZxZml5SFJlb0o2a2VHcUZuMFh5a3NieTM1OD0=<dmdBcmVGTEN0YkMvSzNQcng2VXhoYU44cFFadGhZT1BGTFpXMVhReGZjTT0= TTNTbFU0M2tQSXJrcFpqelRoRTBiZz09 TFh4cTU5eWlaZkVEYjh3djBRNDJSdz09 dkdvcWlBVmVGN0drQkIzcjNXOE1Ldz09<YW85WnBndFlUSWxzMHNEaVhvL3Q0UXNpNG5JQnJpdkk3UG4wbDl2dEpiRT0=
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
{a0a47d65-c25a-4a5f-b13f-01d9d0effb7e}
nSgraAjI
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Acrobat
FileVersion
23.1.20174.0
LegalCopyright
Copyright 1984-2022 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName
Adobe Acrobat
ProductVersion
23.1.20174.0
OriginalFilename
Acrobat.exe
BuildInfo
VarFileInfo
Translation
LanguageInfo
EnglishName
English
LanguageId
FileVersion
23.1.20174.0
Signature
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Mamut.4!c
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Steam.35915
MicroWorld-eScan IL:Trojan.MSILMamut.11009
FireEye Generic.mg.3bcc1eb867ab6141
CAT-QuickHeal Clean
McAfee Artemis!3BCC1EB867AB
Malwarebytes Spyware.RedLineStealer
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILMamut.11009
K7GW Trojan ( 0059df7d1 )
Cybereason malicious.f03580
BitDefenderTheta Gen:NN.ZemsilF.36250.Wm0@aijrjNdG
VirIT Clean
Cyren W32/ABRisk.ZCGD-4061
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Coins.gen
Alibaba Trojan:MSIL/Kryptik.4986e5a7
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:vtRwOlYPd9Til3hSoPO4HA)
TACHYON Clean
Sophos Generic Reputation PUA (PUA)
F-Secure Trojan.TR/AD.Nekark.lwkye
Baidu Clean
VIPRE IL:Trojan.MSILMamut.11009
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.bz
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft IL:Trojan.MSILMamut.11009 (B)
Ikarus Win32.Outbreak
GData MSIL.Trojan-Stealer.CredStealer.BSS4DH
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/AD.Nekark.lwkye
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Clean
Xcitium Clean
Arcabit IL:Trojan.MSILMamut.D2B01
ViRobot Trojan.Win.Z.Wacapew.787456
ZoneAlarm HEUR:Trojan-PSW.MSIL.Coins.gen
Microsoft Trojan:Win32/Casdet!rfn
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.R579336
Acronis suspicious
VBA32 Clean
ALYac IL:Trojan.MSILMamut.11009
MAX malware (ai score=81)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014H09F923
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AHUA!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.