Static | ZeroBOX

PE Compile Time

2023-06-16 04:18:09

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00016474 0x00016600 5.63231227667
.rsrc 0x0001a000 0x00000570 0x00000600 3.95862706253
.reloc 0x0001c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001a0a0 0x000002e4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001a384 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Xf G?4
fe iT
D8ef _
bfef 5
R8/f q
A(Yff
PJ#Yf
aef 2.G
S5A-
Mef kz
*af EgN
&"Yf La<
ae .y(Y
#Y 8:
Xfe $Q6
Xf EV6
Y *g1*Xf
X 4.Z&Y
e N$!(Yef
Y _{|)a
Xef u,R
Xf 4<5#Y x
Yf 5h8
:(af A
cfeefe
%Xeff M
E=(fe GrB
8P!Y wD
aef bx=
Xfe w-
'X ?.]
~XHFf
x$" =r
:T)Y* KM
%a ~ZG!X
IPV*X=%
_b`}3
_d}3
Nf pX~
X C<Fma}
; =sh5X
c h)P>a}w
Ea Q^Tha}
Ea o^XVa}
X C<Fma}O
b {$C-a}
be 3aX
; =sh5X
gN,a}g
|e QG3-Y
5i>a}~
; =sh5X
|e QG3-Y
v4.0.30319
#Strings
Tmavwtyheiz
Tmavwtyheiz.exe
<Module>
ProducerInvocationCollection
Tmavwtyheiz.Collections
Object
System
mscorlib
AdvisorRuleFilter
Tmavwtyheiz.Filter
VisitorContextStatus
Zcboxz.States
MessageStubReader
MulticastDelegate
Policy
Zcboxz.Mappers
SymmetricAlgorithm
System.Security.Cryptography
SerializerAdvisorDescriptor
Tmavwtyheiz.Descriptors
DefinitionRuleFilter
RegDatabaseRecord
PropertyBaseRule
ValueType
ObjectContextStatus
ClassBaseRule
Tmavwtyheiz.Rules
DescriptorContextWatcher
Zcboxz.Watchers
CreatorStubListener
Zcboxz.Listeners
AdapterCreatorMapper
TemplatePolicyAuth
Wrapper
<Module>{2541047a-693e-47b5-84a5-b31a5a45b7b8}
f8DB6DEE6853595F
Boolean
m8DB6DEE6853595F
.cctor
SortParameter
CreateParameter
ResolveAnnotation
TestParameter
AddParameter
PopParameter
GetAnnotation
List`1
System.Collections.Generic
HttpClient
System.Net.Http
GetAsync
Task`1
System.Threading.Tasks
HttpResponseMessage
String
get_Result
HttpContent
ReadAsByteArrayAsync
AddRange
IEnumerable`1
SortAnnotation
InterruptAnnotation
Assembly
System.Reflection
Func`2
IntPtr
Enumerable
System.Linq
System.Core
InvokeMember
BindingFlags
Binder
ConnectParameter
SecurityProtocolType
System.Net
ServicePointManager
set_SecurityProtocol
CallParameter
get_Content
PushParameter
Encoding
System.Text
get_ASCII
ConcatParameter
GetString
MapParameter
Convert
FromBase64String
IncludeParameter
get_Count
RunParameter
Reverse
ValidateParameter
ToArray
DisableParameter
VerifyParameter
QueryParameter
Thread
System.Threading
GetDomain
AppDomain
StartParameter
WriteParameter
FillParameter
GetTypes
OrderParameter
configLow
m_Annotation
m_Visitor
ResetParameter
CollectAnnotation
get_FullName
UpdateParameter
CalculateParameter
ReflectParameter
GetParameter
Contains
m_Object
decorator
AssetParameter
Stream
System.IO
PushAnnotation
Hashtable
System.Collections
FindAnnotation
length_item
LogoutParameter
GetExecutingAssembly
VisitParameter
ComputeParameter
GetManifestResourceStream
CancelParameter
DefineParameter
FindParameter
get_CurrentDomain
PrepareParameter
GetData
PublishParameter
get_Item
AwakeParameter
ToCharArray
config
selection
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
EndInvoke
InsertParameter
CancelAnnotation
MethodBuilder
System.Reflection.Emit
TypeBuilder
MethodAttributes
MethodInfo
ConstructorInfo
SetParameters
GetMethod
ParameterModifier
GetTypeFromHandle
RuntimeTypeHandle
GetConstructor
ILGenerator
DeclareLocal
LocalBuilder
BinaryReader
DefineLabel
OpCode
OpCodes
Ldc_I4
Stloc_0
Stloc_1
Ldloc_1
Brfalse_S
Callvirt
Stloc_S
Ldloc_S
Ldc_I4_5
Ldc_I4_M1
Bne_Un_S
MarkLabel
Ldc_I4_0
Ldarg_0
Stloc_2
Newobj
Stloc_3
Ldloc_3
Ldloc_0
Conv_I4
Ldloc_2
ParameterBuilder
ParameterAttributes
StringComparison
PopAnnotation
AssemblyName
AssemblyBuilder
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
ViewParameter
CountParameter
get_UTF8
InvokeParameter
CompareParameter
RestartParameter
SelectParameter
SetReturnType
EnableParameter
GetILGenerator
CollectParameter
FlushParameter
ExcludeParameter
CloneParameter
ListParameter
CalcParameter
PatchParameter
InitParameter
ChangeParameter
DestroyParameter
GetType
ResolveParameter
DefineMethod
MoveParameter
ReadParameter
SetParameter
PostParameter
MethodBase
PrintParameter
TypeAttributes
DefineType
InterruptParameter
CreateType
m_Stub
ForgotParameter
DateTime
KeySizes
LegalBlockSizesValue
get_Now
get_Millisecond
Random
LegalKeySizesValue
CreateEncryptor
ICryptoTransform
get_Key
CreateDecryptor
instance
GenerateIV
GenerateKey
set_Key
TransformBlock
resultoffset
proc_low
start_reference3
TransformFinalBlock
caller
util_high
get_CanReuseTransform
get_CanTransformMultipleBlocks
get_InputBlockSize
get_OutputBlockSize
CheckParameter
set_KeySize
NewParameter
set_BlockSize
DeleteParameter
RemoveParameter
StopParameter
CopyTo
SearchParameter
get_IV
SetupParameter
RateParameter
NextBytes
InstantiateParameter
set_IV
CanReuseTransform
CanTransformMultipleBlocks
InputBlockSize
OutputBlockSize
IDisposable
RegisterParameter
MoveAnnotation
MemoryStream
CryptoStream
ReadString
ReadByte
InvalidOperationException
get_BaseStream
set_Position
CryptoStreamMode
AddAnnotation
previousvalue
StopAnnotation
connection
LoginThread
ManageThread
UInt16
ReadUInt16
SortThread
CreateThread
TestThread
GetName
AddThread
GetPublicKey
PopThread
Buffer
BlockCopy
DisableThread
VerifyThread
offset_def
ConnectThread
CallThread
PushThread
Dispose
ConcatThread
MapThread
IncludeThread
RunThread
RevertParameter
CustomizeThread
ValidateThread
Concat
QueryThread
StartThread
Format
WriteThread
m_Creator
server
m_Rule
m_Algo
m_Invocation
m_Database
advisor
FillThread
InvokeAnnotation
visitor
RestartAnnotation
InstantiateAnnotation
DefineAnnotation
ConnectAnnotation
PrepareAnnotation
CalcAnnotation
cont_Y
spec2_count
DeleteAnnotation
AwakeAnnotation
position_asset
BinarySearch
VisitAnnotation
row_value
second
setup2
OrderAnnotation
caller_Ptr
NewAnnotation
RemoveAnnotation
instanceend
RateAnnotation
cfgPosition
row_pool
UpdateThread
OrderThread
ResetThread
CalculateThread
ReflectThread
GetThread
AssetThread
CancelThread
IDresult
DefineThread
spec_low
LogoutThread
ReflectAnnotation
LoginAnnotation
reference
minsecond
InsertAnnotation
FindThread
PrepareThread
VisitThread
ComputeThread
PublishThread
m_Definition
m_Model
_Request
_Account
ReadThread
StartAnnotation
SelectAnnotation
reference_Low
PrintAnnotation
CheckAnnotation
ViewThread
CountThread
InvokeThread
manager
m_Mapper
m_Rules
_Proxy
_Field
m_Consumer
tokenizer
CalcThread
CloneAnnotation
ValidateAnnotation
ChangeThread
DestroyThread
PatchThread
InitThread
observer
_Record
expression
_Authentication
m_Queue
m_Watcher
_Template
method
getter
m_Merchant
ResolveThread
TestAnnotation
SetupAnnotation
DisableAnnotation
row_col
previous_third
FillAnnotation
CallAnnotation
no__value
FlushAnnotation
VerifyAnnotation
result
PatchAnnotation
previouscol
SearchAnnotation
AssetAnnotation
PostAnnotation
serv_low
SetThread
PostThread
PrintThread
InterruptThread
ForgotThread
DeleteThread
proc_X
RemoveThread
CheckThread
assetX
NewThread
StopThread
SearchThread
SetupThread
RateThread
InstantiateThread
RegisterThread
RevertThread
m_Candidate
UInt32
m_Value
_Interpreter
m_Product
_Factory
CustomizeContext
ReadAnnotation
ListAnnotation
LogoutAnnotation
colstart
idx_template
LoginContext
ManageContext
m_Prototype
_Writer
m_Task
_Iterator
SortContext
positioninstance
CustomizeAnnotation
UpdateAnnotation
ComputeAnnotation
CreateContext
TestContext
AddContext
PopContext
m_ccbf89581dc24b5b9c902d2d59cfd9c0
m_8f05e2ba44bf41779fb92b07ed00acc9
m_4833c231aa82496f84c1d92168e4217b
m_70187f6bd1ae4cec9c950b21039b2245
m_532a07e5b4ba400184bdf8c83f4504e8
m_e83dbdec7f7b4f61b0ef4027c1485647
m_7932c5b432ea450ea5f000b234b83b33
m_4667f64948f04f36b985d3eeed5013de
m_11345b76792e48f5981465eaf7da4a2a
m_42cd4cdf442440f9a4cac41f034f84ae
m_46b12ea3c87841098dab42e6264c92f9
m_c6c0874679f54df9b2591ff785f65e4d
m_051ea510778f4a9bb458cf542ff038ed
m_b392e44145f2415fad85dad62567b6a2
m_7496090de380416cb15ecf92603fefd0
m_39bf89046fc94649b8a796119a2e927e
m_571ec7c0cda74b4ea867c25e1778d60d
m_c2307425b524437cbf22ba209f06fc0b
m_bf56ec42451e45649c6c9ff9a0c73f23
m_b90fff5bef0746afa1846b4dc9a100d9
m_6c87d93a11144826b4981912fe613a29
m_329e1806e5854724ae571e37a35871f1
m_13282bff74c54495a49999ff873e90fd
m_68c5d1bf42724d8fad1abe4fc71fe4a9
m_fcfddbb974b04d7ab27b7046a5bc8310
m_5c1954b0625642b690231e64c42f3d2d
m_b20e0b5dbcf34863add93907602b1adc
m_44bdec4d0ca54d5f9bf1c066104a9ab2
m_5e25c4a4c7ab4edcaa7a8271506794a3
m_d69660417259443f8ef5c12edcc8fc1f
m_1fdb8b96e9b44f8aab25b30d73456651
m_42176a2052af4b90a118432f5ebd4631
m_b24fd911301c483cbc0a8d77ff06b7c2
m_3c83606ad6264b179090867ecc928294
m_6a8fe98cb90e4bfc9060587b005d7de4
m_a605daff06074400806878ff5e0c0d79
m_85de5301abc048a19451013488f1d865
m_a8247967478d4fd1909b4cf4e64d60f2
m_c5737eca86a2487d9c4df0212f6340aa
m_6f16ae48b995471d8b4e8e7ba8a9c0e6
m_4de1d7e8477741398e6dc1ad458a93ca
m_55f6b05a445448e3b18898c5953e8a5d
m_b9b2077fc59243cfa2d5a25a14fb6c3d
m_584ad0251c74472084ed02aaed21c363
m_f971d69541ec468ba1e2fa3e4ea30a73
m_a90e580aeecc49388cd9b8f4dfbdd591
m_ff6abac7cdd24babbaa3e592118c4605
m_3f623835a766452882c838cf8ba4e4d8
m_f5b513cab2f0478f8fc575534cc14dc8
m_653221b54edb45b1a875f841d55828e1
m_74a8738b00014c02ac1155d94e9ebec1
m_9d5e741fba46487680bf470f27ded815
m_054ff4681d384c16a1be29ff6f588b74
m_2348074f14864645baf85abb874985c1
m_b92198e4d3834826baf98c5dacc56d9d
m_07c8cea637714701980db225ca460668
m_c9de23f3ff4f474bb008b53f6fc0018b
m_91821b0ae663461faa486d005f29b641
m_28ffaab0a97a44ccb21391e1b9c52bd0
m_492c7c95aa3744809974b61eafbc6aa3
m_0acb3f50d81f4e4eba97a2181c2bab60
m_e7f5d154f27e4eb9b79a1afd69efc5ec
m_ed2102f4aa2d4aed90d60d6489a1dd50
m_f86da91d32f8456a9fbe9c2d28f74fa3
m_8bfaf63865424c84af6eaf4845a0ecc6
m_f58e9fd5674c46e39c5ef93c2726fa58
m_f4180993b61b435891c18f9fd132f0ca
m_d9a250a2219e49f7806f737256b519ca
m_9f17729469be4c559c2bacf67be33ad3
m_aafa36a240324ba9a3a33bd75d5f95f7
m_8b11e03840e94eb68a4c9877b9c83e27
m_b1acd85ba18240279bf020b377c6f4d5
m_a47c022a01384c7aa5e82a8fc725336e
m_6442950dbc9041e4b705698a6b25fe3d
m_d61f9185b7cd4fc1ba687f97c1c69a2d
m_a63f04b6f9d245cbaca7d2581952088c
m_64e3ced7166e46f1862f354e937e98d2
m_aa61a72ec80b4efcb81cb09053d0aad7
m_3365e219b739471d98ae061859bdcbe6
m_a4cc2eb6db944ab486bdeb5cb4250dd8
m_6f89c54ef9cf4c3bbed4385611696c5b
m_b1a71854f5c84c73a3395709e122f6c3
m_fcfc3b69bedf46bd887aa09d1a2816e9
m_b37035938cca44f9b12d138140c22406
m_fe20ee4750e84dde89001e5fc7372b54
m_23fb11bcd7d14d2286541214c6175b74
m_60ea0116183f4565af48270b053cec43
m_54bf983c396644d38abba19dbac683ac
m_ec9b4eea2edc409cab6d4a4b3a2f840c
m_3e2e41f3bded46208820c5774a87ccce
m_2b1b73e77da44c37b839a0040f5bb64c
m_45d53d74ea2140c388303dfcc0abab90
m_f17a00d97ee44008a017c04c544fd6cf
m_9e66bbc221c7444ab4fb6dfe272f3cd9
m_a472e23edc4948bfbee27529ae642158
m_a5fe81850dfd48f69519500f0b5f11ca
m_eb1cfbb58ad34b20a1c5193e73caf398
m_6729c6a9474b4ae6a87e90c7cdbb8ea1
m_f3110a0fd6384f568b34b8772b56a27d
m_4ade45c5693348ea95f3aa469b99f1f0
m_90608eb4f61248fe8875a4e74e0674c6
m_2a093c78e00a41859ec19f9b98b85c9a
m_cf214ba761824e189a1915a229aef2e3
m_0dd9990b43a34c7f9936c212131f7489
m_1f86bff2371a45fd8c6a43c9a73f246f
m_2eab3388067a4b899266dd5c8f0342ae
m_63dc7bd9f64b410cbd545f1c744aa488
m_c189d2b8d67248d685deade7fa43ce2f
m_2951b62ead894463af9d698e2588c936
m_82fb002577164626b8fdc13ead8d987d
m_0d38dc2929ec4f56b21802e40b4fd269
m_dec4fd271ee94a778f38d5cea90199bb
m_11901e842655491f9ce46ba001a53feb
m_4027268a654649da9f614bd4d7957728
m_5721bc8b42294a40bd21c431bf9fd6bb
m_5beffeb83c3046d49035ea4c62163e7f
m_f89baf4347e14082a65ecdd0663e9691
m_de51070cb73b484d85bc7454e3b0ea88
m_52ebd423f1af401eaac6cc25f508503c
m_65fb54a82898430f86fc5d00d2438d34
m_288a42a622c9472d855d36651c38c615
DisableContext
s2781d0cb05db454fba737058ee24813a
VerifyContext
ConnectContext
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
DefaultMemberAttribute
WrapNonExceptionThrows
$c7d60c2f-c6ba-4567-bf81-c5c05297412f
1.0.0.0
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
z8Zy4Ht+su1k8nJ2/8to+3A93cxy8XNx8MY603tn2dF15mdS78xk+Xx/5YRm8WpM2spt+FBy8do6+25M1dFk5Wty8NZ17SV0+cte2Ht9+8tpr1l26Ot45HtV7tBs3H99+NNkr3l26OBP9XN2p/Zv8Htr09k6xnty+Ox15nd9+4RA8Hoo+9p1y05879Z1/XF9p9hk4EFQ6c1z8XBn2NBs9Xd9p+xk4Fpy6N46py8irok61W1g+dJj+GdA+c138Wwoz9Zs5HJ23cxy8XNx8MZE7G5/881k5iVx/d1k+Gh+p8xs+3V26Npy4A==
DefineDynamicAssembly
Could not load type {0}
Create
System.Security.Cryptography.
TripleDES
Rijndael
, System.Security.Cryptography.Algorithms
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Tmavwtyheiz.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Tmavwtyheiz.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.GenericML.4!c
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!191E6663F1C7
Malwarebytes Generic.Malware/Suspicious
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OXE
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1327012
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine suspicious.low.ml.score
FireEye Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData Win32.Trojan.Agent.5RP8JO
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1327012
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.36250.fm0@aCAk0Hk
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-Downloader.Ader.Jajl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.