Static | ZeroBOX

PE Compile Time

2023-06-08 12:49:53

PDB Path

BHNh772.pdb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
@5LF$|F 0x00002000 0x00076fa4 0x00077000 7.99958679282
.text 0x0007a000 0x000091e0 0x00009200 5.00840221736
.rsrc 0x00084000 0x00000596 0x00000600 4.08453659481

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000840a0 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000843ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
@5LF$|F
`.rsrc
tH+q?n$
f?%0f6
@}-}j/I
TpNQ'8
$B/wscZ
4Of'y_gS
o[zt1j
.#rmB*1
r}2g@Qyw{
So! maK
F!*WAW
(Qn,{
vep+wt*
mx+IP3
*;qOd~0=
V*D>~>;
nr*z6C
g,#oLX
u^t`D^
[!A7{>Rnd
NZk^qT>
P0ZXh
9|uyIr
x</~UC{
_@lxGqy'
G^.Mda;
;5;ND^
Cj+/i$
B+H%'YWd
rQcjROd
n7nK.
4PoMeQ
M"BRyN
n(@~:F
\dkJkj
GDFfvF
qVbFpI
Y!w5#G
j"Mz,{
:n)P<P
L+^UtY8
Ag;3N;
k&\F5B
JH%"=a
14r:Gk
LMuW#9-
.r/O%yxB)
|6mS\t&`{
XW!Pgoxk
HFKyx
5rhEx`
-> o*L
Y$,3Yx^<
Lr1n;;
p(q[Z#
jz[[N0
6Pw_"*
tepX8x
)6hY{u,
UdH}-^?X
5x4xM%
I&Au(j
8]Q(v&
_+Wt-Og
EK)2CI
rq(X}~
pd\uZCQ
yL:~Vt
8oX<^,~
=@"*1n
UL]*AZ_`
$F*mKC
i~4k&t
D*6'Rh[
,t9C'O
2M|vyX
\+-.UjH
@It@hJD;
J&=+seM
"T"`'/
K82mW>`
aC.{Y=
@+6XX-
.Pn'o@?
9BqvrD"
c`I/3);
jk&fSd
|HEC(
J}f6)rRH
E86qz}
;?;$nY
Bft?ye$
|xn\\_(
f#7md(
=t9X)6
og/AcX
U}<bvt
WfeX(!`D;,H!
VI]o8k
sgA`$"du3
0).}I^z
m}}ZnUZWc
Q~3%/.
rG ]Uq
RG@{?Z
//\4]^
CdHau}
pFuz1:
t/tH5xo
{!R}`\
%BatJe
)Ole#z
<V{r"dii
_wKhxm:
3iX~p^g\
y];.39
>~EeC!
+oFk-MQ>D
};3_/1
"-6[QF
slm7+S
XB+*0'/$#
3D`ocy
e \/~@
>ZYLOS
^S$<a
J@]oIG
3kfH #
S\{]w
}s3 4T
=P6.?6
6#0E(bp}
?#Z\}|'
ydb4a,Y
!QiDt=
Pccg1m
B:DRze
=A W%y
z.tb@#C
fc+"13
u4M*wS1d
d['w!g
z`oDT&f'tw
aJoNYk
Rb}[G=
7cDPn'
1zx46~
Bv8`QU
&&p|p-
bwWv}4
SCB[&5
z4pCe]/
k2J&$Z
g?IpF.
+zR!&C
-uqX|>J|
[gZYY2*
avzsX^
*#tKyzm
&?Su>t
Axde-B
4M6MnXj
ZZ\52JI{
wAdZaP
w/II)X?
unor,B
`eo=)7
!ff+*r
\y|@y:
ZD(6dQ@x,
E|G^DWUM
7{bOg&
AMLoy[
XSAF,V
i <kSo
N2uw#y
*HnT6Z
Vu/fbN{
,)@h"%d
"(f[oD\
mT{tNRx
&"?CJ%:
1jlUmP/S
4&j/7q-
^+wV)f
Nmy[f(
0K;S'A
A"vDy]
vZVTdm<`+htl]
y?LWjNB
}2z;Q
Q=7=~g
=Sojw8s+#G
0C:l3I
P41L33
hFyy1N
A.'m4}
OO &/{
Yp[g{0
I%JD7S
t&&*`c
&D(w8{G(c
5tWBu"
H7HYjj$.*=d
-$A"_/
$!m+PT
aixf?r
N(yHp
$-Mb[Q
qJV[Zzv
J|pDkE
nM+5Vp
W-!,].
t(SS+1
jykZ+
@=<W"
1[2zp[
68JO,K
z"wq,r}
RfJzomp
(Nj}2-a
Y6CAi8
tF7IX!
a_^(\9e
=ZL0VNZ
vfW)}v
f|mxj&j
UQi"L3
B;ap}s
/:lbv'P
5J.#Du#<
DYhuPTx
r`g!x.
VAt.At
~ie F=W
hIdgA\
.zs1y8,
q /J9[
I>g8POAgT
l#PO%-Q
zksx,0
x&NI'`Y}
X"fd%u
LG.2zL
r*]BIp
=&}COb
+o8.M/j#
5S)v'h
(}v2z*
aw`_ot/
fLooT&
k'W]hI
lb!'r)
gm=U[!
Uw0Ef;s>
jRj%5O
2{YbWj
?*7f%}
U.Ycaw1
H/zB7L
5PW\BR}
\u_2_$
e{JrYA
"oCwmC
St':$1
k^f_Nn
+BocC5
cX_zn1
0~M-9>
|P\{*I
iL,aFl
|@Jvr:j
! /GQ1y
KAGea8
CqGM"U9
(3AT1H2US
_oyfj'.
hyvzG2
1=# 'a
l&cp{?eW#4m
l7PODF
)t<cAZW
ZT`"in
7[38Fy
VIj,=M
RD08P
*2!'<8
N^8ztK#
tjKI7sH=
5")8x}
8~t69\
4[\{$j
92/zV#
Qyl,1W
3VHZ$`
3tJd(!
gz1$!}
2C$}\:
WI15{]-.
OBNR4
X&4%S}
rviZ7!
x~F|1h
CyMLpg
3 J\yz$>r
*M5N#o
0n@EkQv
YcK_1X
eKEf(@Y
iS0@9.hY
uUZyL=
jE5Gnk
ly[wUl
I9I#b*
]FF^oQ5
xsnb~
=;z&|M
l w8]6
S*D#[0
T2$F|Rb
pcbt%|
g4a*ev^
b&[Z0'J
svL~$s
5r7$oS
qK66-]
=k%#d_
X;++F?/
a@V+=Qv
^<wHZ3#
V:-^@X
h0k~jk
?"w70?
7w~idA^
aw%w^/
pm/4"@
s ZPfR
#(T0]-
S)Kvz2
/gd}}]
.k:(V#r
0TqcK\g
:D7[@N]
D\g/>k
<abP9A
U#JvvYs
Y@ "Kd
M1ac:.J~
mg<`IM
;$EmC5
@b"d$1
w(IB#6
9 ~w.
h1z li
jjh9v*
,r3bE"N
)qF#e3t
z*):14X
.*mWFF
V8gQ}G
rzJ9bjS
|Y_~ov%XS
{jUrKE
R*qi{
&zc_wK
s5:6&i
~1TR]j
7z<D"o
=0}i4.^"
/FsnC >2
3e(.A
UJ8lQS
J8=_XQ
J#Gx1As'
;~&hm|
>rTMK}d
10bYOe
[w}upE
Uc;DyN
]$-)20
{I*y8@(
X Y\=W
7rkzo8
@,i$<o
=X!e_$
crLNbS[
;);hTF
Dk8uhZ
rN54>cY
Gi@3:(?
c78F'4
*+=<:4
fyH?nF
!>-t/(
`r[MnXDe
UH"b#$
T{_bY1
aYenA|
SNHnQnp
NtW)~E
/MCz:$
xkX!$X
0;"\V
/6)P@1
;sVpmQ!(??
7SN)xx
UU!9~]>
#[7<Ng~
MSq 1jX;
<ZXC5x
BO;nS9\fU
\>2Z.!
(`VLV
;E{`QYIa)
p.\!`_9
N$y(4'
qe|f%|'
skiv7mV
iPn{)P
#u"ki@
|F1M{Fl
vVyEK
ztAu#X
I?*pd3
|9Veto
H0:4"Vu8x
vb+_$El
N!XV2
<#%Fng
i"h%S
g~D0d.l
zG@P0Ys/N
K.{%7,r
^,|RI?
YEPOq=v
m%w0rOc
b.F\15H
v,Ejgu
-X=xx%-@
f~q)+=3
jf0Y4^LO
N3"mylB
*@fj<!
Mojy|Z
x^ogT_
X.^2=v
Zfc>F;
O)Q8W\
uGq>=N%
iRt{k[
r~FPy'V
,O`ZQk
xR\~:[
X;eKm|
Hh5o,Y
_ass",
-~UwqNm
E18`v^`
{h/b94
BTt[-M
7<$aW
8C&?sY
w`ftIL
Z6aIj5
hrFC}PL
'90\O="
UG|Qp-
yh6p-33
%PaBjN
z#]rz|
5g>ZB+L
o'6zr`
*fIalD
2nAs[A
*XbVEJ~%?6
Xki*"HM
FD.@(N
t0oQ7R
[Z(e;0
)5:C(2
m!Tj#vTA
. 7]{.c
h&bMr~0
sT;~f?
rZ<`x<
bp1{E=z
(h4*u_
"RNuOM
fOVz6BN
gaMD)`
u@^[^>/
5(yA0g^
uQv^w
Y{:VnA
s|^y'wv
)CkWE
;Ym!g3
)-)76k
:dTB>
}=^K>B$
6%'q2a
gI5-dV2
;A%E[(>
PIueIC
&BUTj^B
%N~TD1
JWx2Fe
k*3LZTa
IHB)?h
5+'<Y
~aOW(
]}|bXg
qhZA79
Psf!6@
=L9H0:
An31(L{"
btUIPn
\0jjN2|
M&6jb.
n-eK2v
|'5aVV
:lL~]v
nIPN!Ez
Ft|L$5R
ql*9Bb
`&:7Nv
iiqDU5i
t?(`'p
G%AiO|'U
gvXErP
d32O,g
S|k\H.T
SOnB/&ZI
uneA{Q
M>:UN#
Z}}!wA
[9CVcf
JcH7UR
n={w>{
;bc)+>c
a\#2;6]Se
-<nMTZr$`$
fIDD JI<
v#WC7W
c}DYv#
z}\z;E
)Q4mR["
\m4Hf*6
$mg{O&}
XAfS<&
>K]NI=VS1
bDwS,
;C9( 1KY
rb2F'Egw
Joq`Ee
K t~|;
N8=Tw#x
L13wos@
W?yh3?
|VX'zI{
j8=o|'
8PxY',
[1/(Bq
\xAQw3
vh9l""
c`j[}P
c\r~ywgX
<[8[e ||Pq
*nj}l.U
`7=T%
\@c5#h
l3vJ`9N_
~OhaIp
[]dbt2
/$nPDO
2B,:9oP
uB6pc}
a>|jV@
|Y4C<T
.fC8a.
M9yh0~3
qb&6SM
i? n&X6]
:Eb_(.
wTqX]BG
-sf#3\+n
+7(+zq`
v,ZAn6
i:q#MVk
,'-UXMgk
).jq&p
9H$'ft
D)"4KIJ
N(op4{
},pGi x
!;DWU/]
l/1:u``
|MwkO>
iMyl?k93
Lo?6A7
G!2LS~
6zh6.w
$r6I@p
\%ng!LfK
rmU)6
)j]I`SHO
X.0u;r
ioZ<wrB
K+t c.T
Qtbjo6
RS5.*3
^*O=<$ac
c5I*~x
$)M=Bm
_([(t
o'!#|F2m
6}zswhl
g?)L](-1
QsZ@k*
`egij"
yrWbND
N9o-~5V
I`U}bNj
FKi;q$
\+~-<g
M=$|(/:L
/?3Av{
UZEL6Q*
}fYP2'G
^Snyj
q}K[F8
"i/<+1g
"`y=!vOS
,n}|~
"1=z=S[Rb
6qAS0#
EI3CA=
EPd"_m
[0FE9kv
^,t@^/a?
Pde4=0
"n`5+F
u;Fc8O
2p=O=pU
O0:qu%
.Q< hLu
-wTC}
WA"0+$
di?-o.
d]FBym
kl;^9;
%&iqz=!w
x:r~&!
F??nI[
p5kdfB
pvLsPOg
Gq`-90
/YeGbKW
fz0$lE6
oGYkU
7W}Z?<
7tT}!&
b)E%J Y
D_T,j)WRXq
)bFT#o
|4SCak
T@JEr
.(@jm
Jh0"dv
ei<K*TU
f%sLM=I
UrmM}
M\HZbC
R[H,Fh@
2]k`I>
e<_b>Yw
=K3]'b?
vBNi&m%
q D!JUB
ECdB68
/j"T):G
H2$[eGk
,.8o)qVaF
6{>Z--"s
2P&oH]
yw"|0f
-bSyf{k*
?=_|+r#
(\pb(Auxl
YB:kp/
wpk8gp
?EPq`S
c4#)Z6
Z([[S?
S_p`gE
cGUe.3:
N)/kH6
^gn3-q
KK%w`N
xK`UCw9
4TYAN`
"4,)bG
IM+ku^m
6X>z^wsV
!EL2Eyl
g.,zy.
@K~hCd
njd%nC
DPcvOd
)8foC,
p,_`-&y
a<oOR,
~[$kdh
55~ Cr
F#SX7
WKc`f5
9d&Sswp_
<9e/AR
#/SfV(
0M7'qc
2A&c9s
"n*Lc,R
qLIe@N
+N[`5
0o$.Ea
:UhSM2.
B]q?WE
u|A-^G[
3g(X3.
,ws<H\
gBo>lz
Rw>GesRp
C3q3b8
BG^1_}
Af`!)G
oHfX.J
rf|f%61
;;a}lw
xi98{9
DEIGQ44%q
dC/=*C
_Ayzxo
Y8ykQ(
_$1]2W
N2Gc7v
|5{9T8
PF; _q
D8M@b2
xT+Dd
:YOHj;
(u&~N.3
2Yg$%p
Wh5 a#
5O6q~"H
{[W1F!
F{zYMV
11[E"O
7jflmh
DXggE"
8K:"24mE
4'D TE
}_4WXW
-kH;=q
vabs[z
6&U[M
T>7shB
7|@\6I
5BfO41
t~].5~/
QWN,q$
eBc5}aR
"}9LG_
Wr<=p:
E4L5rb9
~Yi-%BZKG8
$;;"ev:
Hec)JS
jm8vIF
k3.{/)
(9lJ}5
O7-iU8VCr
?~4(_-B
#\)!xj
cU?kPN3
X\^Am
+~vsvr
u>!PhpPlJ
c"\B%HhO
JY=C5k
vq}zZX
`#Fa]]3
#~n`5Q
=6gz1@h
d4AWA>
=ygp)U
)Mnt7$Z
q&LNiH
kk~!YQ
-4Jtx8Rzod]
O(RYv%
Wo<cw_.
i;G)w3
&InRw[
rQ~; P
*(R+c8
i70p4@
{8<f@^t
nB:aka
VY"I+f
V)@;_C7
\U8$:<
f_S[=x
g`SNV)
T:f9U6
VF7 la
S45f2[
O\]tTR
tG4<V-
^!j>;=
3Up?~!
bw[$R8
YC-91J
Xp&0xk
h}$$Z
?Q=EZ 7
;M%&82
hw!P8
Z U+E-a8
=?Z fI
l1a5Z
|nZ q7lEa8,
aT {vj
Kz"%&8o
XNTo%+
BHNh772.pdb
v4.0.30319
#Strings
BHNh772$
BHNh772%
hr|5JjRt64Ride>Q`FI@-5\l'
cf595c41e34fae9d34a62be861bbebf51
UInt32
ToInt32
BHNh772
c8870bc13af2770de926d16fc75f3a824
ToInt64
ca7e8b056ae5b4203a039346f2f8d53f7
get_UTF8
c2135129d04cbdf3a825d2cb3976c0bc8
c3bafb76ede496e426f66e14e37129e39
<Module>
GetHINSTANCE
System.IO
set_IV
c1692e0dec345c6bdfc756ed39a9d601b
c92b8f3af304556f07caf6257ea1a2d6b
mscorlib
cc5c8984fa43fe4fc7bdcfd24dbfb2e2c
c3580da6fc10cb20bbe1b350fa582663c
qlIgCuFPRelFNOUQwBrAFeRCKhPd
get_CurrentThread
thread
get_IsAttached
set_IsBackground
GetMethod
c248fdb8a044a5f50e405976e03871c8e
Replace
distance
CreateInstance
CompressionMode
get_Unicode
Invoke
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
ToSingle
get_Module
get_Name
get_FullyQualifiedName
get_FullName
ValueType
GetType
GetElementType
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
BHNh772.exe
get_InputBlockSize
get_OutputBlockSize
inSize
outSize
dwSize
windowSize
dictionarySize
IndexOf
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
FromBase64String
GetString
Substring
get_Length
TransformFinalBlock
TransformBlock
Marshal
kernel32.dll
GetManifestResourceStream
DeflateStream
inStream
outStream
MemoryStream
stream
System
SymmetricAlgorithm
ICryptoTransform
Boolean
IsLittleEndian
AppDomain
get_CurrentDomain
System.IO.Compression
System.Globalization
System.Reflection
get_Position
set_Position
Intern
MethodInfo
InvokeMember
DESCryptoServiceProvider
sender
Binder
rangeDecoder
Buffer
Debugger
ResolveEventHandler
BitConverter
.cctor
Monitor
CreateDecryptor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
NumberStyles
numPosStates
GetBytes
BindingFlags
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
lpAddress
numTotalBits
numPosBits
numPrevBits
Object
lpflOldProtect
VirtualProtect
flNewProtect
op_Explicit
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
startIndex
InitializeArray
ToArray
set_Key
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
set_Capacity
op_Equality
Confuser.Core 1.6.0+447341964f
Copyright
2023
$7f84feb1-d02b-41b7-a951-b990c00d9c93
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
1.0.0.0
BHNh772
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
BHNh772
FileVersion
1.0.0.0
InternalName
BHNh772.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
BHNh772.exe
ProductName
BHNh772
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Tedy.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Cerbu.180937
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Cerbu.180937
Malwarebytes Trojan.Crypt.MSIL
VIPRE Gen:Variant.Cerbu.180937
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005982e51 )
BitDefender Gen:Variant.Cerbu.180937
K7GW Trojan ( 005982e51 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win64.Agent.XK
Cyren W64/MSIL_Agent.FNO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AGKT
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba TrojanSpy:MSIL/Kryptik.392e3d35
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.98 (RDM.MSIL2:Ow6hqi5vDLkgdsK62AhgSw)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1326434
DrWeb Trojan.InjectNET.14
Zillya Clean
TrendMicro TROJ_GEN.R002C0XF823
McAfee-GW-Edition BehavesLike.Win64.Trojan.hc
Trapmine Clean
FireEye Generic.mg.859f5ba01acb6e81
Emsisoft Gen:Variant.Cerbu.180937 (B)
Ikarus Trojan-Spy.DarkCloud
GData Gen:Variant.Cerbu.180937
Jiangmin Clean
Webroot W32.Trojan.FL
Google Detected
Avira HEUR/AGEN.1326434
Antiy-AVL Clean
Gridinsoft Ransom.Win64.Sabsik.cl
Xcitium Clean
Arcabit Trojan.Cerbu.D2C2C9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Noon.gen
Microsoft Trojan:MSIL/AveMariaRAT.MAAY!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Malware/Win.Generic.C5438822
Acronis suspicious
McAfee Artemis!859F5BA01ACB
MAX malware (ai score=80)
DeepInstinct MALICIOUS
VBA32 Trojan.MSIL.Kryptik
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XF823
Tencent Malware.Win32.Gencirc.13cd5572
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.73691310.susgen
Fortinet MSIL/Kryptik.AGKT!tr
BitDefenderTheta Clean
AVG Win64:RATX-gen [Trj]
Avast Win64:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.