Static | ZeroBOX

PE Compile Time

2023-06-28 23:17:58

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005e414 0x0005e600 7.98161141477
.rsrc 0x00062000 0x000004d8 0x00000600 3.71888438191
.reloc 0x00064000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000620a0 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000622e8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
"h5nu'
p%/8^[
6v%c.,
gm$B:A+
\<Yg:D
/8d,LY
>>1F4:
qpx=g_Z
kL}Oyy
$hq^9Pi
8;Rl{:
eu{{Dn
e>2O+*
`S]|Ed
7h9I>@
ffq$$y
mjs<N^
]Js?iZ
|kV0~]
kL/D#L
_=dJ5M
D@?ize
"z*eEs
{uc5{I
bA1 :?
I=+4jm
|SB7ZC#
koR"Wg
&~q5GV[
G"X$RB
CX1+d*
F^'E\W
SEo.EW
'^T)c5]
;^=m@j,
c;i,6h
5n_IYq
sA-D}:
HJ4:Z'z:
t@J~[5
_t[I]c
br9,"`
=kYl=%
sEj&)[
&0GbF V
]p1@)a
oaBzPF
}bJ|V
(ac+Vq
l"Tq+@
"L%?5{
ZVu_2E&
0c@Rb[
1G^H !X
U6|DTYA8
[|EW
PYHqE8
AxuY==4;%<
{|fx=H
>df|53g
@+ .udj
;elsH,8h
]y8bKQ
7(J;NJG
UKrO+q
sD]Zf,
N.<eP2
`WplLY
<?7^u;4
X],)nK
M<}3pY
8{g>!R
b'$.m=
R$xZy
4a5)PIM
x@5b*6VS
FmCk|c4on ,
^!^6zkEK
1hfF06
zEX5 c
/$ojr~
".D*V1
bs[m9?
5z<l+i
#e?mp@
|j&Tkq
4sIk8e
ZheD[d
Kw}4MB
^|nRj
+gbv`k
`qCl7Z(OqAL
)!w3+uiZ
Pdw_$j
Fa4|=}
xvL<>M8lD
UpG]Fy
6TvCp6
7wCUO|
~4tWgDx
GIJaN0
9sUt.s
=689G`
3.1$aO
I)QH+nb}
!f-.^'@
fv"xcZ
?(o5b|
lb=-&r
Qj(6|*af5CZ
WR[&_\
q3E120
@5^<=4
zDJ L(
KzDJ L(
zDJ L(
`zDJ L(
BWe94W*
GFz:$8
.zDJ L(
bzDJ L(
@zDJ L(
zDJ L(
i`yIktE
~Mj]Tp
6>sb.w
v4xtqb3
fe(Miv
%L9o]1X6
ftLc"M
%6y7R!
HW,2.
$!-[[E
A9K)&x
u}Z'(|v
Y/X*M
3$c3X1
e"*NsQU
7~vXrU
4KW#V_
zNs-nwP
':hFlG
G9z(oT
h&,)H8of
L;zj S
|]P;Mz
MOs|<F
R<Y$&w'
9.*vwC
n1_qzV
OgBEY= ,%
P#xog."
LWQfo
Im7rI~(
Le1Q9%X
d&ABY3(k
n=5Ede
z(M/pg
PVvLh
?AibDm
=7@b35
g-]prf}
t!:W}d
FQ.]yO
g-]prf}
*}:|1_
gy{W[T3C
Mp`Nq
=`u]}=
oPc<vo
Uo3kkx
q_yEJt
1$?P!5Mu/
C./E6Yg
1AWY`G
Uo3kkx
g-]prf}
nRx9_v
stb]LA
wqS7Z3=
*spsjP"
h!7Vh+
KHd:>X
4&Zcm5{
[xwUs[
/DM.VfT
g-]prf}
]-6b#g`
Uo3kkx
8lBJ%5
VlL@PX
U.imQt
0vvMpT
+);G%IS
O.lz4-
A1}ynX
zpW$2B
b?XE[.1
Uo3kkx
>r'?si
%HmxtJC
VlL@PX:
0vvMpT
+);G%IS
b${XF\
Uo3kkx
VlL@PX
K3zN~
Uo3kkx
VlL@PX-L
\Hd:>X
mrt"Y2
g-]prf}
H^O&q\
0AULXK
zAL%B7B`
`DV!t;
CZFt.+
w1(aubM
qHnbqW
.sq=1.fX
gdhA@z
49S?:t6
w1(aubM
-#e*Oj
!<|Q]l^
%Tb@:xH
>T+]F,
4a)6KS$L
w!0?*%S
(zveI/
Xe(5)2
C*)D*Y
}Ua m4/
'_r>_h
{M&q/2
@?h)Su
0vpz:(2l
+imps{
H r(q
e<,wIq
%3vml
#,![ST/
@qFC4fT
BB1D.l
[UinUz
:^#P+G
g FQ!{k
u zYd$
z."pF^
}Ww->"
a=HZ}1
<J)kjQ
P$"k'yC
XO6Mtz
W.G!f[&
FIR8Xz91
J7/#$&<
dGy//I
|1%,mOF
tdP^7F)4
4D]IDe
5ghu)wIM|
zN<$@8
@1).>L
n,nPrT
_lkK[<
z\Lf+;x
K/;Q>YPA
[8hjDJ
39 d97q
L(u*^D
;4s#Ah
YSr\8F
4D]IDe
5ghu)wIM|
^J>2(w
ZfP@#&
&<%Gmu
;}ID+Y
Db>ar? A
5S4pWL
_|rem)@`sDWiSp
OBefH1
Tj?]bo
e%+w]%
G_P/01&Nu
t)*m<N
zHZ~4l
8GEg9J2
8'F_v(
1Veb..8
u(; @&
d$PJ"z'
k2w-nK
Eo0J{WaXv
tC9{1F
t`ob'~
\A?EA@
z`Q>'Bj
3"&T;x
x+lZ/t%L
cug!B
IJ"$-:
?\F3tW
NKb'tY(
C5*U.Ki
=i^f+s,
8`}Np
uYnBu:@
T{(YZ_
5SC, n
eM06?B
P}LB;`(
e6Rxz,
v~37[T
02fB?4
AnDwZO
9?iuq-
PA1_XR
x{KB{
Eu4In'
hS/Klq
zbRg[Co
(Rv$"C
:y}T5(
fLN^iji
k0+t{v
{Z0)"|+,
2=]A/Y
yQf|o>b
5Cm608
VFj'!;y
z5GtWG
@m3Wk$
s%/w{v
kgpSJO
Q|P_dY
5q}k#/
}l,<=,H
&|pLyB
z>N/Cm
`Q'9i2
#g^B|k
eT?zh.
@f0t|'
3>9dv[
W^h&H\
IV'v/"
8O-$=M
@,.n4"
]`AY@X
9}xOwE#*
fA2X4Uk
,(r'kLG
"5.?Q*
mk}!`'
ZCsCeC~M
09iqRY
A4;3@w/
;)|B29X`
j%i97mW
ua-~]n
Qvyno-Q/
Ur:I'Pq
PPv!vPy
4bNqL6S
Z*Z&ea
.FQ/l?U=R
3A5(|
s-!R&8w
Tr5$_gh8
n[[R#e
o(Ri.h
IG\FW/h
7F6:`&N
vd^m?3
M'uy.g+
'^uEb ?
*6(HvZ
5X5NFh
gNjqkm<
I53:uP{i-!
#ggp%~G
~/__5w1:
RCy>:#
aN4 v&
6S"`Z
Z4)dAD
6v#7IX
2`}^u]
)v`xL}@d
qL f?!>Suv
X5OtOZFt
9)$5=bx
^X\;H2AB
ktRiw:
%od7qoi|
Mvz!jR
"*c*1,
k~kUIV
RU{xym
3"&T;x
t6GkRW
pl/[A_
[JT0U
3n 7.9c
*3&68v
~\EvOY
'oE_(C
GC_U}u
f-MTdP`)
O3B\fp
e^0g{
:DL;qs
no+B$-
]3_h'a3
I`@)1;
uH7npIza
d0()F"
q6L9;%
w:a^%8
)E{7:n
|OI!eo
e4_lT\
iGvz$Y
Kl+31G
CQ7JXQL
=j{$Z5
"88%niY
0+*g U
+bYH=1M
$=;}+{
9h!` x
G0q(+8o
k)cSYK
UTDpfeg
y\T!a5
MKmX%8
JgJ;s:
%!a5<)
X_1e%-
*Dy/^K(
>z'Rt+
N&gC[y
32QbOji
Cl]SQD
^5k@6v
8VMP|
HG(nh
_>nK&9>)OL
&,<D08A
&,<D08A
&,<D08A
&,<D08A
O!J$?b
`?y BYT
xW^[.l
E".OkK
bUXQ?<;
F0owiS
dX8Zz
#4Sp4+L
~# xq0
tjiqw
U+*9Q,w
MaH\c|7C
)`ob>?j
!XH@tCl
.Pc}PS
a~"s^(\
YD|^Ar&
_+Ws"zaK
d80C3vz
{/gB,g
w+jyCB;
(/8!9!
-!/qgD
i66y~,
ZWapHh
Bm<>tG
tKrpf]
VY#pv,5
KSs%ri)s$
o?1'J*
q!6Ti<
![m^Hf=9
8i,]C]
2#jQxa
72pf7
TZ8/Yo
^0rfF=
bHf46|(V
&7)L&q
OqC2sV`
I<"YkH
Q-Zmp*r
3?nKg*
mZig;M&
1$%YD;
DHSy&d
GmtD>"
!( &:J
!B&mE:
B.JwGj
ud_68 d
]I^jT|
Y$J=~_1
y_=,k!
"X)p-l
Zxt5%Orh7
V<9d4Cu
Lr[C5_
dg-=#P
ctV`%R
`,q%N8
m==C%8
<,Y*ot
!b,vRp
/9$3[g
%P!~_u|
P/I5 DG
g:)m#q
P=Vn\2
zM*3cy
$\%Do|S+
8-`%?
[0%+b_
H2-SA3
;J"+Wb
J=E'uE
:DL;qs
uEc|h7
JF~@O\
b;Twj%
[aaN;E=
E*8i;.
#pi_;p&
fv"xcZB
fv"xcZt
fv"xcZ
fv"xcZ
xg(EuA5W
^@7JUq
!M}c0l
t{Dist
iD_DMB
#.$weJ;
YqQrZmY
J+?NQ%|
b1Oi9O
V C.Rat
J!-6X$
|?;GAqJ
Gu$.r9o
ZVBnV~
"nh^Z5
nyzGk-
:.@\
$2pOc6
6ps{Yd
D<uznn
QoYh4{
vVqQ`kx
ZIb}HK7
=Cyx!D
]IB]M$
*)>bn
pEv8?[
j'Wy\g
e.L"B+
;/@g}a
;FeN0l
/6t"uc
xMz#(>"
7_\7~Q
ct:4AT
Kwh[pM
WD<CCv
qd$*yv|
,(UN$/
_*E>OUg
PA,8ZOgu
'*bK~`
MEU$G8
]+dwwS
$?? FV
hY2}r
$@6TYDO~
K.!Hs8hFd
5|{cj.
n?G~=w
H[$_L@
w8R#)\
BwWJB-
go2\uD
_-3TVg
:C84lWD
Q%wo$c
?bU:P*bf
z"i*gr
Nz/De'e
ZnL *B
x{Stm_
O0TaD$Q
%lf2!)
.zdbsn%
y&?unaH
>(MDGo
%.F55Cz
czH*=[m
J[trU)
v4.0.30319
#Strings
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
Program
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
Microsoft.VisualBasic.Devices
Computer
System
Object
.cctor
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
Equals
GetHashCode
GetType
ToString
Create__Instance__
instance
Dispose__Instance__
get_GetInstance
m_ThreadStaticValue
GetInstance
AES_Decryptor
GetTheResource
System.Threading
_appMutex
CreateMutex
System.Collections.Generic
List`1
workpath
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerHiddenAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
RuntimeTypeHandle
GetTypeFromHandle
Activator
CreateInstance
MyGroupCollectionAttribute
System.Runtime.InteropServices
ComVisibleAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
String
IEnumerable`1
Enumerator
Environment
get_ExitCode
ProjectData
ClearProjectError
GetEnumerator
get_Current
Operators
ConcatenateObject
Conversions
Strings
CompareMethod
CompareString
System.IO
Exists
WriteAllBytes
Process
Collect
MoveNext
IDisposable
Dispose
Exception
SetProjectError
CreateProjectError
System.Security.Cryptography
RijndaelManaged
MD5CryptoServiceProvider
ICryptoTransform
System.Text
Encoding
get_Default
GetBytes
HashAlgorithm
ComputeHash
SymmetricAlgorithm
set_Key
CipherMode
set_Mode
CreateDecryptor
TransformFinalBlock
System.Reflection
Assembly
System.Resources
ResourceManager
GetExecutingAssembly
GetObject
Contains
AppDomain
get_CurrentDomain
get_BaseDirectory
Replace
ExpandEnvironmentVariables
STAThreadAttribute
tzvpjpqmebyybi.Resources
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
GuidAttribute
AssemblyFileVersionAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
Output
Output.exe
MyTemplate
14.0.0.0
My.Computer
My.User
My.Application
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
WrapNonExceptionThrows
$2d27e133-4177-4c44-8ded-933b0ff4a227
1.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Popup.exe
postmon.exe
postmon.exe|True|False
Popup.exe|True|False
%AppData%
MMcrynsAcAn4K3ddr
tzvpjpqmebyybi
%Current%
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
Output.exe
LegalCopyright
OriginalFilename
Output.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan IL:Trojan.MSILZilla.25637
CMC Clean
CAT-QuickHeal Clean
ALYac IL:Trojan.MSILZilla.25637
Malwarebytes Trojan.Dropper.MSIL
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.25637
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36270.xm0@aKjV@Yb
VirIT Clean
Cyren W32/MSIL_Agent.ERT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FPO
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Dropper.MSIL.Dapato.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:UY+uln4R3IJxA6Ig8NJR8w)
Sophos ML/PE-A
Baidu Clean
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.MulDrop20.4429
VIPRE IL:Trojan.MSILZilla.25637
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
Trapmine malicious.high.ml.score
FireEye Generic.mg.d699bb26d34ae6d5
Emsisoft IL:Trojan.MSILZilla.25637 (B)
SentinelOne Static AI - Malicious PE
GData IL:Trojan.MSILZilla.25637
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/Dropper.Gen
MAX malware (ai score=83)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D6425
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Dropper.MSIL.Dapato.gen
Microsoft Trojan:MSIL/AsyncRat.ABJU!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C5161034
Acronis suspicious
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Zilla.5637!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.6d34ae
Avast Win32:PWSX-gen [Trj]
No IRMA results available.