Static | ZeroBOX

PE Compile Time

2023-06-21 03:06:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000c10 0x00000e00 4.86760901131
.rsrc 0x00004000 0x00009aa0 0x00009c00 5.78049040211
.reloc 0x0000e000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004100 0x000094a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000d5b8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000d5dc 0x000002c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000d8b0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Task`1
List`1
<Module>
get_ASCII
mscorlib
System.Collections.Generic
GetAsync
ReadAsByteArrayAsync
HttpResponseMessage
SecurityProtocolType
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ToByte
673.exe
System.Threading
Encoding
System.Runtime.Versioning
GetString
Substring
get_Length
Nonqjj
set_SecurityProtocol
Program
System
System.Reflection
System.Net.Http
InvokeMember
Binder
ServicePointManager
Monitor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetTypes
BindingFlags
System.Threading.Tasks
Object
System.Net
get_Result
HttpClient
get_Content
HttpContent
Convert
System.Text
get_Yellow
ToArray
Assembly
WrapNonExceptionThrows
$37f19808-be6b-46d6-a47c-466abb381085
1.0.0.0
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kbNLhW0U4
http://192.210.215.42/v/panel/uploads/Dnlanfmltc.vdf
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
673.exe
LegalCopyright
LegalTrademarks
OriginalFilename
673.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Seraph.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67661411
ClamAV Clean
FireEye Generic.mg.7c93d0dd185ced28
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Zillya Clean
Sangfor Downloader.Msil.Seraph.Vwrw
K7AntiVirus Trojan ( 005a77501 )
BitDefender Trojan.GenericKD.67661411
K7GW Trojan ( 005a77501 )
Cybereason malicious.dda984
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.KVAR-1214
Symantec MSIL.Downloader!gen7
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.PIY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
TACHYON Clean
Emsisoft Trojan.GenericKD.67661411 (B)
F-Secure Clean
DrWeb Trojan.DownLoader45.58977
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.pm
Trapmine Clean
CMC Clean
Sophos Generic Reputation PUA (PUA)
Ikarus Clean
GData Trojan.GenericKD.67661411
Jiangmin Clean
Webroot W32.Downloader.Gen
Avira Clean
Antiy-AVL Clean
Gridinsoft Malware.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Generic.D4086E63
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/Remcos.GJY!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!7C93D0DD185C
MAX malware (ai score=83)
DeepInstinct MALICIOUS
Cylance Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Seraph!8.111C6 (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet PossibleThreat
BitDefenderTheta Gen:NN.ZemsilF.36270.cm0@a8rx0Nh
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.