Static | ZeroBOX

PE Compile Time

2023-06-07 18:44:57

PDB Path

BHNh772.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0007f5f4 0x0007f600 7.93744085259
.rsrc 0x00082000 0x00000596 0x00000600 4.08356573382

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000820a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000823ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
jXGjPo
1Gqhb9
&a$fL
w?RUvu
X\57jC
cj^>'
rx4xMu
\=KoN.
R~y#A
}G'\So
u{E6~V
S?,bQO3
NH.zbW
*#`.+)
.\]:z~?d4
00,[z;
U;Uy'L
C^m`^YPR
H<kS9s
|~1V9s
C|vwy<
(WLi1+
GmX38
KiERpTi)
($:ND<
r`]^Q@
e*K1F$
"~\,-{
A$LIdi
O|^}&{
J/G}2A"r
N8wj}+
"a42cP
PHwr7f#
2)I2Dr=
';-IY`h2
Etq-t(
wr(,xN
80k1S@
)HSIHi
9&exZ[
nzURnOX
kG?RU=
r)m-3~
S}CEFt#
!lH\u2
!i5z"hb
w;:ejrzG
0['#J
$}/#_/lr^
ca^(\@m
.}YuC9
w(9W+l
JONFi
TH^+)Y:
yMEAE*Wd
;T0N?~
A|R9XD
4y~`*W
Q#k#(R
i|`RhR
raz!+1
QV1au@
!"Q}rz
TqYb"A(
c5J-Oa
bW[aY7
QO<='a
;Wd%%E$T4
LOK.?*
LAz'`Jno
"_NG%NZ
s `c*c
B|O@$o
H|kt=u
Okn~]@
wn>EIf
v): ""
Wxoy%Zv
2iC#i+_
bv'oKw
G}0<c"Zp0Z
kKQ$p4sk
\b;m.#
/X3gP9
t$(|hGh
%Ao-0y@"
?m^LA7T
$Rf-D@
>2lBKx
GcG%,=
{A~5$`]
r-SDu]
2MPg<&
,d?O6u
o)KM'd
+T|$HO
8Zgf;_
Hjwl|y
M'5Lx
.vl])O
eVX#"(p7
G8\GXc
E_)@`ra
w^}J~#
<oFb6W
ts]@\\
A"Gh5'P
F<O}OP
k*4>,G
D92%=do~
"JZd[(
*g]*&V
aXL}4L;y
DswK:l_
cav|QD_
)=sW'B
}c8?29
+o"$ "
3{\0
(voeV/
^ru-zH8
\$|gTW
[7uZPC
35B]]y
BFC2Ib
jkFK?t,
9l*3u{
"py|P/
C{m!SM
K%0$?L
Bn"'[`No
'H?#a.7
^K<b7KQ
N;$V1>N
6}K65q
k!htDAv
=T3rvB
<:=nDr
RsG7f}cL(k
6C:=&a
^f7+pb|qz
(5~U0;
r7k6dTi
lGg*(|
cj_o?,
|Xi"mWX
HHPoH)
%WCw\=
No$zE{B"
F7mZ*J
V"tluI
?GgdO
?6*?\h
oO4@}h
>BG1hP
wT4YPd
DXS>QZ}
]b)`Na
-(d)CR
P(%tl8A)}
K(vRo8
ff34KJ
&RTe:>
`&l_s)
_\<^I6
KE`j"AO6
4?`/Vd`
;&]0A'
9MX|.cD
cz"Wd#,
$MvK{L
$D:Y;z
X{g2\{
IMY]oU
QfL'F0
4Qv!cD
ZX{mvk
x>BZ*.
s]]-_U
cF}7<j
t_PjY=
{<o;>?Jp;X
T&[*~1/
%,x|w_
g[vJJ
f<Y$<)
Y9o)xQ
'9[9*ue`
)k,b~@H
yOkJ4t
5M9X,16G|
rI@/}p=D
4o"Qct
|}{9qcQh~r
1A,n,-ad
(8D3[
]&(?\8i
y:OK`q&
fy3)#K4
RtkcLp(
SZHo%x
5a^m<Z
P]kr8;
d6I,CMF
."hr]{
Wj< SS
}W=XeG#
5q@rY<
}Ra@Un
@cfUJO
k|degE
Xh}EE9PZ
8\`d\RC
/xO^i;
Mg~a8\
$!#rYd%
J\}|r]
'{P|r
s(9Ni!4n,
Uor^vld
%KtlXg
O9S..+
7aiGW-
<-l]m+
V|o/9)a
25ozz8
}\(}&<
g99BX*=
gD?m%r
l<vwT_I
g@:hJ^
P;LmNW
\)vG;a
W%TT,MMy
vm'L7p#@3
0ZI]r0g
@&ejoeI
xul8tqo&
@"/5O&
#0vk<:^
s?gMdk
YJ5/`b|
H<v+<:
uJ^M0R
6g{[Xy
$U94B^k
y0b\Phq
>iG`)r
C?XyZ0,R
S3E_?t1
*idK3Cmr"+y
y^qee'*>
[$9u0/
MxHY12
fx%6I(\R
j%1!S5
JgB@K9
c]Kxt?^
XkcQ0V!qi
4VT,xZ
O3FAkv&
/=~dKw
1jrMg}(|l
p3uyj:0
9d<_:E
xHA:=$
t{H 6w
$JqT.M
.\Ko3!}
Z pp#?
/<Ew$1
h|ry0-_qH
1^aIO-,h
FFp-;S
,3<C\cX
'&USP~
?:kS{Oxb
) JibZ
.AJ,]1-
UE:-hR
+#)B7E
ktxRsUb
C/]g|=
Sef$F
2r ?}8
!YFp[r
5[!0CC
o$6+3]kdq
\-h~ >
1_q(a&h)
mb|&Wf}
oI4L|+w
q}rc#LNP
NXN1 &
FkHb@>
8A[0c>
Di=SBz=I>k
<OL"D
mq6T6.
uiVU}k[
@W=:|"
BOy&Fd(
X-i-@
|CZ"[ *
:7X9Xo
cZlxUG[C"%6k
j.l$:i
L 9Y0RT
j}eYKtw
8w:1w^\
[2R<o0
9h^&[x
3n@0lv
Yu,V|G
2~#I#QU
J]YvcJ
z6k+,1
ih@N_e
IHx3@+
L1i(Le
{q^eS[5
f!xzw
BMu}<
:SG>oqT
n:KJ/3|
Hjr0|3
c`7wjt
RU/Dv
xNI4Xx
^F'PY`
5-B}""
sgcj/]
3VEjt-
vzW+lq
T,j`6do
/&%2l/
,<>oow
K0VVxS
zM(+&
Lk/C[t
lw:^*~
PJBye:
k&&~?x
p`G{rn;
-LZ@13L
RZEY8S
z6Gd26w
3"Y!X?Sc
cy>*a
$U|!1]`
{J#YZd
}9er_u
F5n@CU
F;KkRz
8u8C48
(r_RE_7
Ig|/2
O>xHOet
n<Ic~Q
t~Y!*A
c\s_Mi
9p[g)E
jOXsia
Ope8=|
*|/`;s
%z,O|e}
YOmyrY
-jI1!BMW&&|
\;S9KC#
suh:8B:
<a#mD]
_beU,o
/<?cq0
Cv<M7>pO
,k}FxJ
4p\?.3
}5Ldy|o!
({LQbP
C 9%Q:
&kT{8Qj#
{1MiGd
`PLt=j
\xx%nas
pREMDn
>"p}w1
|lYia
JxE!nM
pLO~*~
\}DHL6
}@>)b0
5tzk-Wf
6kHhHz@
*yq*
aEl]w}+l,
%avvX/
hnw|l?
#th'V6
#RxoozoC
j5Jg1'F
$//;nq
QTifu6)
cDD/04
sKu;(6bz
Hla<x*
B<0A\u[[
-dN^Ca
b{.-^:6
k=aU
DRGPpt
*K?XCs
"_hm4s
nd#E{k
KZ}G+*
WX"C$a
txTH)j
qrb5`
+c.0]0
>kFrJ^CT6
mh4V)nx
3u_q!CR
hHZ !m_
C~HzTS
<XdFey
7/'LC;
1GRz<'
F~rjOx
EFD6(mu
3Ji6.2
*iw0O;6
N$_%g}
/RXUL53
($8Qo=
1k^pL9.
8FK%XQ
7xdNh}
6(p|_
-hAXbIK
L=O/FFdWW/O
c"puYA2
*k'0[#
C$n-X
GhAX@#
<:2;yM
KC4"c|
3NMTB4
rR<rg%
Y3P7H?
z3B9:Vc
Zb-Sn8
I_`u%l_
H(9Ja,
;fb"0O
nRX]hF
%a*\L+
vy(5e9L
Qz&Rq(~
.R`WY'$-
wkOlU~
U<c\M+49vTy:
c$2\eY\
#U$(!O
S?Y2=9Q$i.M
Yzfpn-K
5NR:6%
tFZ(iM
`It@t`
[ty}-1F?
)qBl}d
jRI:mv
_bB5iM
+TDY!mH
iV^ 'q
,n~CdRaZu
^OI)0En
M!1amz
A$@$tI
>vYZ/E
&qrsrm
2G[y4p
S8YO/Mf
-ae 03
JMHBlu
VONiH)(K
e 3YQhA
o.COt(^
*c6b!]
|nD-pKY
s6Y.$S
$O+?~|
?OV|Su#
3}Qv8x
0%+=/&
Yj%7QX
e1D6ynSV
<;kg)X
4qeHeG
Ka5>L~
yeRuBk1ga
j}E/TJ`
4]Mm%`
.+{PyO
w|,/52sqLP
j0yQ%0_1
wfH$q3
(dDcBJ
iJR-d)
bT(Fr-
?I\~Ga
y;8d1?|
uOE}K/
'jC8H[
b^rzEU-
7O\W:"q
(Tz%$\
EEgb\(
:bu{-r
Hz#G%p
cxGYY0"(
lni c\?
G&n2Dn
R5zV`
%k,]D4
h=.tQL
~yvGL#
D,z,yaI\
~Bx5@
ezn>6
rq}EG?u
G2Y!W%
0SU,n!
-N1I-fD
S;#(OjF
EeVv*<
)qC10^
l)s%C{
V0*JXs
iMQc9>
ZY"y16.
(Vb.{{
I^*>T"
SbPHf)
BnUiU*
e&0[|T*
/>X|JL
~TI@2Aq
>'X@ew11
aOoVey
A]Ew^
BUvM_sS
}O99Ls
\OCL~}
BH.hhZ
54qp+g
=<ix]Y~Y%
MTL2P}
IP_WShZ
ey*mpO
l%b$8Ft
lE[(;S
-xSw<!
&'%h<d
}m=2@
C%E#\a9
q3YH5b
7XLD1W
_r:QC!
Do#N.0bC7
UvhB-
VT<N?0
@5Ig2_
4O 0'!?
U&3l:M
Y{_1E/
.$Te*
}Yx8%y
jCPbZ?
"ZXrAB
.}_j1oV+
n7:.dx
A@I`d|^
\OE#ay
!|_Q"d
c'O>3xq
H%7;.9B
zAYXn
`&o7p
+kq6CF_M
v{_YDs](
)S:iva
H,nDQ]tt
}Rwxt,
ZIX=H(
vL%^k:
?D [}jZ
$5x$Oj
@Fi*&PW
p0T6?<
iiTmH#c
MM['hJc
M`%>7w<TE
>}P!=f
P7.:vj
>W,y|G
zB_7Mj
17E3^>
cjL}bR
!zTV$n
~I@Ml>
uV5(=pH
Y($}F{
FG5z
[nZ"R\\9
n=Dks?N2\)
$g,$tI
|WlPEq
+1}nQN
HWP*}mpW|
bB*C'Q
5rO?csPxz
;Q5|q{u
c+!ZXg
eC)}<%
74.aKr
:vWr(t
0QC#?-
k@NV@t
?nJDy1
NhuE'@
~eHymUim
%=bb"S
S3m=<_
!mEu.V[
e7k4IV
'Hv@<S
DBT#j}
\J")Fn
1.c`oY
?.AY:`
(J/usoQ
J|Vw%r
lqxX8g
:30Ry&_j
)NCg{xC
}lSB}
+l;cjN9
f.80zB
U2{ABKg
p=EEOS
m:m^4D0=
`lJ0UZ
89=(@2`
T;70fC
`"=7Y^n
up(>F~P~z
i-]5n#
fAFvP),
,d1>tw
=d|L`>
<O.s$VB
0)17&
3@Vzv7H
REXef|.g
7?D&s
IY?YH#
tUR*1%D
3|O(.s
V/ ,zp
nsU:I_
{X,)\E
!*Rk+x
O1 m*TsMp[vm
,6d0@X
MA!,RU
659jd`
C?I_q
n1^8U=
iNsUY+
%:t8@d
B'85Z'r
S?xn})
m9QsOB
wn2*3ib
,q>%)!K
HiX45=
%Tk$"i
0t%BB)
lVk@y{
$q5#]qJ
]N}yQj
F^j=IW%
||ew.c
+CBnfk
JI%pw*_V
Z1phlV
{u#:D
\myWhT
hs0Je
^h=a:)~
flS+or
%+QlWz
/`W^(+
_x4^~m
XHidbS
^yH$2B
?X8\g+
h|KNy[/t
5UOEKU
=hr MS
9kUv5T
F[!v;[z
^k8!/0
\Q":N!*
BOL`z)
#tPW}z
S?+,rA
L5oAS(/j
?a=3KlX
v'-}M0+~
9b!l%
9_8.1M
ghuzXc
Nd\5;%2
DPTCH+
ZCrwjK9O
a1&bfn
^~`7@bBy
nFqqD4:
a6xmWSi
uG#qWx
EONh+6
=bK(qn
\IvYJ`
k1jGVk
\cdDTW0X
e9J$!"Ux
b@&juA
#GxOg.
dU1O/_*
xD:F4-
2A\NC#
fE40]1
e%)1+<
#y_GNC~
DaV]-3
$4{ap^K
or&kP:
q_RF%~,~R
ZUjTC_
.@6#CQ
}U(|E$
t{^|#}.25<
290{.F@l
mIu?%x
psQ$FV
37Ei:7
meP;
<qPbw!
yX?5[{B
'v.`z,z
V#Qu5bE
7db*H;
i88X8E
lG-i/]
b`+^Ot
qrSB{Q
rc"qax
r?{Z:3G7eP
!~hQ_l[}
P'yUeG
{I^loQ
BybgI
XBRy$$9
'<h+Qz
'lH.-6
(8,m0/)
&vni|+
zqwTu$
flb6\Y
GFr/7o
ADG2ym9[
F5~7[u
Z7lWC<
/X#`CX
noEpk{
r(j9[<Q
|pn1nj
8UL![&?
hKh8S
v&<` z
C<k{{f
>%9@!.
q&m&.25
ew\Fi2
aXM"Ww
j:dmD-
A\q!F)Rg
}Q@!tE
6weve9
W}p)r
l'A^1p
SzW`T.pw|
YRCL]k
uH\/Og0
6{&3qoS,
mN7.`E
9)etvokO
l2&,)?
PxZ Q6
~gZ 8W;"a86
';O0%+
l+jZ e
}:}a8u
4NZ mw
@Z VB&
B#WPZ d
Z Cp1a82
Bk(Z N
ll?RZ
nC%&8P
1*%&8]
K<xZ @
0Z VI|
ytZ h,
Iu0Za8
_bj2
ls$JZ
_bY*
oA^a8"
MmZ >Qx
2Je5
!3sDZ
DJOZ G
Z E+2ca8w
{ Z A$u
Z ~0%Da8
xK;@Z
adqq8n
Z_bX
V#%Z '
B^Z Vw
Y_cX*
3$m%&+
-R +2E
4KPZa8
JHZ%&8~
18Z NP
IVQa8V
[w|!8-
%&& 8h
;6H_Za8x
mHZa8O
9Td]%&8j
|wF'8
>ksZ E|
v4.0.30319
#Strings
BHNh772$
BHNh772%
cf595c41e34fae9d34a62be861bbebf51
UInt32
ToInt32
BHNh772
c8870bc13af2770de926d16fc75f3a824
ToInt64
ca7e8b056ae5b4203a039346f2f8d53f7
get_UTF8
c2135129d04cbdf3a825d2cb3976c0bc8
c3bafb76ede496e426f66e14e37129e39
<Module>
nlbZW6'hZg<eI^%%,CXi#KhjM
System.IO
set_IV
c1692e0dec345c6bdfc756ed39a9d601b
c92b8f3af304556f07caf6257ea1a2d6b
mscorlib
cc5c8984fa43fe4fc7bdcfd24dbfb2e2c
get_CurrentThread
thread
get_IsAttached
set_IsBackground
GetMethod
c248fdb8a044a5f50e405976e03871c8e
Replace
distance
CreateInstance
CompressionMode
get_Unicode
Invoke
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
ToSingle
get_Name
get_FullName
ValueType
GetType
GetElementType
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
BHNh772.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
windowSize
dictionarySize
IndexOf
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
GetManifestResourceStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
AppDomain
get_CurrentDomain
System.IO.Compression
System.Globalization
System.Reflection
get_Position
set_Position
Intern
QHKxEtDVvmBYrXpFaTobjlVoZvXo
MethodInfo
InvokeMember
DESCryptoServiceProvider
sender
Binder
rangeDecoder
Buffer
Debugger
ResolveEventHandler
BitConverter
.cctor
Monitor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
numTotalBits
numPosBits
numPrevBits
Object
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
op_Equality
Confuser.Core 1.6.0+447341964f
Copyright
2023
$7f84feb1-d02b-41b7-a951-b990c00d9c93
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
1.0.0.0
BHNh772
WrapNonExceptionThrows
BHNh772.pdb
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
BHNh772
FileVersion
1.0.0.0
InternalName
BHNh772.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
BHNh772.exe
ProductName
BHNh772
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Remcos.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.67420584
ClamAV Clean
FireEye Trojan.GenericKD.67420584
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.67420584
Malwarebytes Trojan.Crypt.MSIL
VIPRE Trojan.GenericKD.67420584
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0059b63d1 )
BitDefender Trojan.GenericKD.67420584
K7GW Trojan ( 0059b63d1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren W64/MSIL_Agent.FNO.gen!Eldorado
Symantec Trojan Horse
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHED
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.Remcos.gen
Alibaba Backdoor:MSIL/Remcos.82886f0d
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:1Sy/5kfP0Y5gNGYR8ooVdQ)
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1326434
DrWeb Trojan.Inject4.58116
Zillya Clean
TrendMicro TROJ_GEN.R053C0XFA23
McAfee-GW-Edition BehavesLike.Win64.Generic.hc
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.67420584 (B)
Ikarus Trojan-Spy.DarkCloud
GData Trojan.GenericKD.67420584
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1326434
MAX malware (ai score=82)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D404C1A8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Remcos.gen
Microsoft Trojan:Win32/Remcos.SD!MTB
Google Detected
AhnLab-V3 Malware/Win.Generic.C5438285
Acronis Clean
McAfee Artemis!2B262120999E
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Backdoor.MSIL.Remcos
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R053C0XFA23
Tencent Msil.Backdoor.Remcos.Ssmw
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.73696032.susgen
Fortinet W32/Malicious_Behavior.SBX
BitDefenderTheta Clean
AVG Win64:RATX-gen [Trj]
Avast Win64:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.