Static | ZeroBOX

PE Compile Time

2023-07-17 12:09:56

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00031144 0x00031200 7.88790476205
.rsrc 0x00034000 0x0006a118 0x0006a200 4.83573434612
.reloc 0x000a0000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009d54c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0009da02 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0009dac2 0x00000430 None SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009df2e 0x000001ea None SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-;&&*~-
,k+'~-
91`~D
-r&&&&&&
-a&&&&&&~]
-X&&&~_
-~&&&~m
-{&&&~o
-G&+3~-
v4.0.30319
#Strings
SjiShb.exe
SjiShb
<Module>
mscorlib
System
Sampafsle
Object
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
PoweredByAttribute
SmartAssembly.Attributes
value__
YELLOW
ModuleHandle
Dictionary`2
System.Collections.Generic
String
Concat
Console
WriteLine
TextReader
System.IO
ReadToEnd
Exception
get_Message
Assembly
System.Reflection
get_Location
ToString
Stream
IDisposable
Dispose
Thread
System.Threading
Environment
GetFolderPath
SpecialFolder
GetEntryAssembly
GetExecutingAssembly
GetDirectoryName
Intern
op_Inequality
op_Equality
Directory
CreateDirectory
DirectoryInfo
GetTypeFromHandle
RuntimeTypeHandle
GetName
get_Chars
Exists
IsNullOrEmpty
EnumerateDirectories
IEnumerable`1
get_Length
BinaryReader
ReadInt32
Encoding
System.Text
get_ASCII
get_UTF8
GetBytes
HashAlgorithm
System.Security.Cryptography
ComputeHash
Buffer
BlockCopy
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
ProcessStartInfo
System.Diagnostics
set_Verb
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
set_UseShellExecute
set_CreateNoWindow
set_RedirectStandardOutput
set_RedirectStandardError
Process
WaitForExit
GetDirectories
System.Collections
DateTime
get_UtcNow
TimeZoneInfo
FindSystemTimeZoneById
ConvertTimeFromUtc
FileStream
FileMode
Marshal
System.Runtime.InteropServices
SizeOf
Convert
ToUInt32
BitConverter
ToInt32
IntPtr
get_Size
op_Explicit
ToInt16
get_Assembly
ResourceManager
System.Resources
GetObject
FromBase64String
GetManifestResourceStream
ParameterInfo
.cctor
object
method
Invoke
hfsdkffddfghseffdfaffdchd
fghhfgsfffrfddfdffddshfdasdfh
cdfffdfadfdfrsfsshdkfffgh
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hjfdffhgfadffdfdcdffffskhj
ffghrgfdffffffkhsjd
sfdfffdshdffgfefdfkfghj
sddddffhedfgddffffgjfsfkdgsacsafp
sgfhjffffgdhjsrfhddfhfffadfsfsscfgdb
dfjffsfhgdffafcfdssfkfhgj
ffchkffdafhfdssfsfj
jffgadffcffgfgfshfskffj
jcfsdfrfdfdsdgkfff
fdfcffrdgfdffsfssffj
jffffgffrfdffcsdsgkffj
jffffgfdsadfsdgkffff
gdddffdhfsfgh
fhfsdsfhfdfhhs
hfgggd
ffffffh
shssgfasd
sdffgfsf
sdffffss
sffdfggfs
ffdgfdshs
gsffddsd
gsddss
gfhfsfs
gdffdg
gsdffssg
gdadag
hdsffafs
adsfdads
jddssf
ggfssddfh
jfsgffdfhg
jffdfdffgfdgs
jsfdsfffdf
jdffdfa
gdfdsfffddj
kfdsgffh
fsffdfg
sfffaf
ffdssfs
sfffdsd
jdfffssk
wsfsssv
gsfffsds
gffssfdsx
startupInfo
jdhfdffsffsdkfj
hdffhfafsfsdkfsh
hdffhdffffffkdf
affdshhh
sdfffhdhff
hffdfffshdhs
hhhfgfffdfh
fffffffdhs
fdffss
hffdsffsf
jhfdfdfdh
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
SjiShb.resources
{715ce2f5-68ba-4d3b-acd1-f7ba2f936ef5}
System.Windows.Forms
Application
get_ExecutablePath
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_ParameterType
StreamReader
FileNotFoundException
RijndaelManaged
MD5CryptoServiceProvider
InvalidCastException
TripleDESCryptoServiceProvider
ResolveTypeHandle
GetFields
FieldInfo
BindingFlags
MemberInfo
get_Name
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetModules
Module
get_ModuleHandle
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
TryGetValue
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
Gq;,N`
W1.Z+[p
*;6j!6
kTb8i]
!q'QG(c
p$<qXwQ
X LQ@
) W.,H
_N<ww^
fYz,&Za
gTKypiE3
I6XEuv
j4b&;l"
N9$kV$
E5f$9n@O
"-?ywG
Qn8uBY.Q
/bc[g\V
(Eh:rl7
{L)Yg='
XyAnnU
V|~1?"
>30*_Qn
?"#EO`
&\$WJ'
h!F-]kU
T+kYbs
/`csFM*
z+uTIf
sV!!Aq'
-7o[L@D
%n4%*V
MMO&9-
S{]_{myR
XZF@$b|
VfVB,>
rTP?]`1Pj
Js"fRA
8|3?kb
L^l?9|
(a;2V4=
jDs<./
&hUV8eA
X](2FJM
^h)DoU
i(yM=>
T%Iv)=
pNe? N
QMyI2a%
u'!/3}flBVBb}
1vx54_g
iQs1!hE
--9/T%
#ng K,t^
5+D&T$Y
dg~VDe
QN)8>y
_@@gf=
halJ*|
Yv_een
\LJNMgm(o
kL,8Qs "
$}3Bv-
h!V80<
Q)UIM1
-(0\Be
:S1po2%
kw~~X9
h016x{
>VmQ(~
{7!ipx
|gb)U_t!
56lUS?
3-L,&o
Rb^G$|
di|q$@
eON;dC$
!)x*>F)
{\XHF:
>mmLQ3`
j.'sD~
fK'9FI
LL{02A
Ap/{z-
@yIr,:
37d'G:
ej;VAc
u3CL&'
5?~VR!
c79Pg
L2#1<YqC
=ew+X3
rXD_XX
3FwI/F
-Q?U5m
$xe)Z
|,JT;i?
>p!:Hf
3r<'Tjp
@8l[~~
Ub]xpa
BYs*'i
~Y<V'e
;2G2d<
r%j@a$
8(#J&i
>=chB
/eq:FS
FLud_H`q
Msm]D?{
Jn{<O>
[j`|>Rm
kKa\c=
#<sM4R$
q!4* &
ebEYPY
5%rg>s\p
^C,IJD
4t:gF8Z
ct8>uE
y^8*-0
lw]hAzp
+v2KA)
22_4 ]C
=?udnz
.CIwy}A
?Vs+v2KA)
-qsq$5
MJ]@M-1
<g9~xe
Kz$zBT
SRKv*e
lb\1$j
[Ytxlv
cSs"+V
h-{wC!
:a/u+)-
UG}QZ)
'4*g>c
Plsl\R*
[)-h~Cr
f"{w}Nd
N;UE[bf
'/ps4z
4>~]`xB
%IDjh&6
}sk_+(
W<3dd;
[.YUv
c8Qq )
KvBuQ3
k U4AB
*%r)b>
i8h:mXM
ODf/9n
z%`QFET$j
D{D$Av
SrtGRM
T@$#F(/
qdm'$
POFSo:
yCyGx&h
1Gf;^S
N;UE[bf
+gFd'l
;+gFd'l
aJ^!ZE
{nA3i<:ld
1t+ppx
J 2rk
`XIe"
*V\BRY
F?hzA#1
sW87CC
2XF^*HE
#|UFyy
%93wfE
zsP, .:
vv8Zz*
t3X#C`
ai0sVn
:Sd'yj
V+Uu(u
l#Q<Wa
O<;/vr
:8&!y_
tlx?=;4!
qKtChm
fF<nz
sXi|`G
$*U4q+
tP7K!?
MC)5y:
'BQN-,
HGD5.BK
1H9G$6
0fIs"9
*+]2qg
9g;>YD
`=+yJi
lX--~Pl
`<:mZF
F]hoep
[LWi_WE
2&OR~<
XSpvI@
t;[(tCG
:Vjgla
i >^o;i
Q1i T6
|/B|>0KA
.AWcf&
.QXfD
K?PB\'
H,9Dzc
GyB}Hm
&~2?Gy!
q;4d"As
[v*|y&
Ls,rN(=
??]l*5
#~0eIy[
>,nR`G
[~x4-?k
Z:d3ES3]PJJ
o/[r.D
s3wkIX
ih3ajDX
Hx%q#Y5rC*
%l+~Hh
pcc\H;%
z"K=KsfT
]e_`}d
;WoR}$HhL
a=~zETk'
2w7_LP
FUB\#w
FsXqX#
AHF*|dIx
px&lNi
*=7hW:
4RxF`@
Yl6M&i
`*$OA(
fj~C<kW
ef8;H]c
)1Zs7_@M*
~(EC#Y
FsXwMz
cOLfs"
fkLlnub
wZ9,:+
{X!'LN
59Y>]\
19oRZ%h
g-0=F>
F/'@@JdP
)e%il+
[ <%s>
Sb)'hV
BB?1?)}
N<K=^R
V)etMU
9b,f8Q
==w?I8
[OhCy~z
3uI~?`
fkC:yR
%PVt-o
*{,QC
lJ=zZp*
C~*}y@6.
ZFRd(MI
!NN{mS$D`
!M$m"W5
wuz|$<
bY'T\B
9WTy_)
Fb{6Tr
5oN<5C
jCRl;#j
O5Vt$1
m%drrf
=Y_Ie5
qp*LUy
O$"?Y5
qG~3rly
X(e:*`
YbvhJJ
&dXl x
PG?bkL
|Kl[A1
osjrj%
%36n|8UM
/Yn,<E{
?u5,#py
@|A`x"}9
Zr'0+A
:@rY5G
1gUec@L
kf^Y8$vI
fnZv}OP
mNx;pN
u`] <W
d8ELdD
F)9x49|
'K`aK*
j'4}%U!"
: 'd-m-%;
]Tt_=Y}\
yVhSQ7P
-4\eMar
,Vml0RTVUSkhTUjlkbU94T3kwU1pPMWdTQnlsS0c1UmU=
U2ppU2hi,Vml0RTVUSkhTUjlHdm56MkloQnh1bGdTQnlsS0c1UmU=
RHluYW1pY0RsbEludm9rZVR5cGU=
ZXEvb1V3S09XWGM9 NG1VUjBDbURsZmxwNlNKV0RmRTZsdz09,TVhMUjZzWGFCeVd1emZRbTFqcVhzQldXc2hvait2bVY=,V3BrLzYyVE4wTkJ0OXdLem9aV0JDRmdTQnlsS0c1UmU=,aUFjeUh4YkVtU2hnY1U4QVM1RExVZ1NMWHlXbStNYjg= MWtGUWM1RktXenRSZDEvZmVDQkNYZz09,WFRObkVpQVNTRGpvYlpyUTFveHVCMHc0cTRnTW50SSs=,dzJDY1lqUkljaDJ1emZRbTFqcVhzQldXc2hvait2bVY=,LzRUNG1USW5FOFp0OXdLem9aV0JDRmdTQnlsS0c1UmU= R1hiTXIrUEhBU1BEYjFsYTE4MU95Zz09 TzY2NnZzQWxVSWxwNlNKV0RmRTZsdz09,Qk1rc2h5VGRJZmJRd2xhMG9RdTkvR2VtRWJqa2FSVzk=
VGhlIHZhbHVlIGlzOiA=
XGZpcmVmb3g=
ZmlyZWZveA==
bWtkaXIgIg==
ZmlyZWZveCI=hS1VMd3h5Smh3Ukh5SWZjMHlhVVhaN2hYcFdaZE9DQUxBRTFqMWhrTEEzclJ1YytGU3ArVkJqREs1TCtBSU1RaVR2QlNoazJoaW9vPQ== ZmlyZWZveFxmaXJlZm94LmV4ZSciIC9m
TFkySDhReVg1b289
ZmlyZWZveFxmaXJlZm94LmV4ZSI=
ZDovZmlsZTEudHh0
ZDovZmlsZTIudHh0$Q29udGVudCBvZiBmaWxlcyBpcyBzaW1pbGFy,Q29udGVudCBvZiBmaWxlcyBpcyBub3Qgc2ltaWxhcg==(TmFtZSBpcyBub3QgYXZhaWxhYmxlIGluIEVOVU0=
TmFtZSA6IA==
ZGFkYWg=
ZGRkZGRkZGRkZA==
cnVuYXM=
Y21kLmV4ZQ==
RDovU2FtcGxl
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
UG9wcGVkIEVsZW1lbnQ6IA==
RWFzdGVybiBTdGFuZGFyZCBUaW1l RWFzdGVybiBTdGFuZGFyZCBUaW1lOiA=
SW5kaWEgU3RhbmRhcmQgVGltZQ==
SW5kaWEgU3RhbmRhcmQgVGltZTog
Q2VudHJhbCBTdGFuZGFyZCBUaW1l Q2VudHJhbCBTdGFuZGFyZCBUaW1lOiA=
c2FhZGFhYWFmeHQ=
U2QgICAgICAgOiA=
IA==$VW4tYm94aW5nIGEgaW50ZWdlciBudW1iZXI=
_CorExeMain
mscoree.dll
Pvvvuhhh
+2jH#*c
(/hFuy
(0j:@Ew
in{DLTj^CLd
JSh^hmzDs
^ctABJb
^csApz
hm~?`fy
gl|?lz
-.Je"#B
#.mKU^
"+hy-=
QXvn!&V
hhh%\\\
LQf0:Aq
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
{715ce2f5-68ba-4d3b-acd1-f7ba2f936ef5}
SjiShb
MAINICON
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
FANTECH
FileDescription
Setup Launcher Unicode
FileVersion
1.00.0000
InternalName
LegalCopyright
Copyright (c) 2015 Flexera Software LLC. All Rights Reserved.
OriginalFilename
InstallShield Setup.exe
ProductName
FANTECH VX7 Gaming Mouse
ProductVersion
1.00.0000
Internal Build Number
154432
ISInternalVersion
22.0.284
ISInternalDescription
Setup Launcher Unicode
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Ransom.Loki.8883
FireEye Generic.mg.30f4b0670b2cd0d5
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Trojan.Crypt.MSIL
VIPRE Gen:Variant.Ransom.Loki.8883
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Ransom.Loki.8883
K7GW Clean
Cybereason malicious.19ba24
Arcabit Trojan.Ransom.Loki.D22B3
BitDefenderTheta Gen:NN.ZemsilF.36318.Mm0@auT6vHlG
VirIT Clean
Cyren W32/MSIL_Kryptik.JLT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:RWAMYLIJGiLMa1iBAcppOA)
Emsisoft Gen:Variant.Ransom.Loki.8883 (B)
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.high.ml.score
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:MSIL/Redline.AAFO!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
GData Gen:Variant.Ransom.Loki.8883
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.MSILZilla.C5442250
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Ransom.Loki.8883
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AHBB!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.