Static | ZeroBOX

PE Compile Time

2023-07-27 00:35:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00008244 0x00008400 5.72921217178
.rsrc 0x0000c000 0x00000bcc 0x00000c00 3.49817150576
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000c130 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0000c598 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000c5ac 0x00000434 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000c9e0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
_d(V
saY [>*ga
/(Ya}B
saY [>*ga S
^Bdv w
saY [>*ga N
b 9!rxa}_
AV`2
wF9q 0
V]ff A*bta}s
5+ta}!
AV`2
xBee %~b8a}q
G+hWXf
v4.0.30319
#Strings
Zqbpytwp
Zqbpytwp.exe
<Module>
ProducerSingletonReader
HexIO.Readers
System.Windows.Forms
QueueFieldQueue
Zqbpytwp.Queues
RepositoryConnectionMapping
HexIO.Maps
Object
System
mscorlib
DataChangeTypeEnum
Zqbpytwp.Factories
PublisherConsumerConsumer
HexIO.Consumers
CollectionIdentifierDispatcher
HexIO.Dispatcher
Zqbpytwp.Pages
AuthenticationEventDescriptor
Zqbpytwp.Descriptors
<Module>{053e8f3c-7e69-4b70-ab97-e1cda472f281}
f8DB8E070DD66210
Boolean
m8DB8E070DD6891F
.cctor
InstantiateTask
_Thread
_Visitor
PopTask
InsertThread
reference
EventArgs
caller
CalculateThread
ICryptoTransform
System.Security.Cryptography
CryptoStream
MemoryStream
System.IO
SymmetricAlgorithm
set_KeySize
Stream
CryptoStreamMode
IDisposable
Dispose
TestThread
HttpClient
System.Net.Http
GetAsync
Task`1
System.Threading.Tasks
HttpResponseMessage
String
get_Result
HttpContent
ReadAsByteArrayAsync
isasset
ResetThread
EventHandler
IntPtr
add_Load
System.Drawing
Control
set_Size
get_Controls
ControlCollection
set_Name
ListView
Single
ContainerControl
set_AutoScaleDimensions
PushTask
CloneTask
CalcTask
Create
VisitTask
Convert
FromBase64String
AddTask
set_Key
RestartTask
set_IV
FlushTask
get_Key
PrintTask
get_IV
TestTask
CreateDecryptor
CreateTask
ToArray
ManageTask
FindTask
get_Content
ConnectTask
SuspendLayout
SetupTask
DockStyle
set_Dock
PatchTask
set_HideSelection
DisableTask
set_Location
ConcatTask
set_TabIndex
EnableTask
set_UseCompatibleStateImageBehavior
DestroyTask
AutoScaleMode
set_AutoScaleMode
ViewTask
set_ClientSize
CancelTask
InitTask
FillTask
set_Text
CompareTask
ResumeLayout
identifier
m_Helper
PublishTask
ReadThread
DisableThread
Assembly
System.Reflection
set_Tag
CancelThread
Enumerable
System.Linq
System.Core
IEnumerable`1
System.Collections.Generic
InvokeMember
BindingFlags
Binder
identstop
ReflectThread
ComputeTask
WriteTask
NewTask
get_Tag
InterruptTask
GetTypes
RateTask
Environment
OrderTask
SetTask
SelectTask
PostTask
LoginTask
InvokeTask
IncludeTask
ReadTask
GetTask
ReflectTask
AssetTask
MoveTask
VisitThread
Application
value__
m_Singleton
consumer
UInt32
request
RegisterTask
ArgumentNullException
StreamReader
VerifyThread
IList`1
TextReader
ReadLine
IsNullOrWhiteSpace
ResolveThread
ArgumentOutOfRangeException
List`1
get_Item
skipvar1
StopTask
RunTask
DeleteTask
CountTask
ResolveTask
LogoutTask
Format
RemoveTask
_Processor
facade
m_Merchant
CheckTask
LogoutThread
ExcludeThread
EnableThread
MapThread
num_instance
RunThread
IncludeThread
end_spec
GetThread
AddThread
OrderThread
SelectThread
start_reference
AwakeTask
ResetTask
RecordType
VerifyTask
LoginThread
IOException
IsDefined
get_Length
ConcatThread
ICollection`1
get_Count
InterruptThread
get_Chars
ToString
ComputeThread
column_b
Func`2
CollectThread
Exception
Substring
ToByte
PrepareTask
StartsWith
SortTask
QueryTask
UpdateTask
CollectTask
SearchTask
RuntimeTypeHandle
GetTypeFromHandle
DefineTask
RemoveAt
RevertTask
CallReponse
InsertReponse
CalculateReponse
InstantiateReponse
RemoveRange
ForgotTask
ListTask
PopReponse
PushReponse
issuer
adapter
CountThread
m_Field
_Parameter
AddReponse
StreamWriter
DestroyThread
indexOf_selection
AwakeThread
UInt16
previous_res
counter
CompareThread
TextWriter
WriteLine
PrintThread
next_cfg
BitConverter
GetBytes
RestartThread
DefineThread
counter_X
AddRange
stripinfo
RestartReponse
FlushReponse
PrintReponse
TestReponse
CreateReponse
ManageReponse
container
_Database
SetThread
m_e6e6a700e7464658b5b6a63a57cd64bb
m_262ba09984f540f4be73dec5aacd09a0
m_fa51dd953b254e1eaeb179c3633ac6ea
m_3bfa49a75953459ab7d583036f49b440
m_fbfee6aca8ba46a3871b60e3f45f89fd
m_e87f3616faf84b31809d5ab4ef51aee9
m_21a79507550b4532b822dcfa9a84ab68
m_8439009e441c43b5a5dc42af36ffca13
m_a31dabffeb294cc7bf2c9938b97b125b
m_9e1e53227218444196c86ea6fe0a868c
m_7cf776a3da4a493699c7727ff51823d4
m_096cd480cb4b4ca38bff1d83f6588e2c
m_f8666d964c664c8ebdc43baec54c4dd3
m_4f122ca3f8844eb491490a2678e7f6bb
m_571681eda1d24504bb9d3b50173e42bd
m_aa1c5b5a0852417f83ba4f716c751aa8
m_984e25ec44204f74b33adc2f1549b0fa
m_86b695fe6a5646c880cdc47a8c559e61
m_f5ac707109ac4e40822f75ad7d11f2bb
m_0083bec5d90a4643a4fba53992eb00de
m_7ba8be3b44b744e8a4c0e8e6b6588f1b
m_3d177a9fc76c40a38d2c8d29e2dbe1a9
m_3191824ac9354a0eb069bce62923a71f
m_201cd4c761ac4e7ab3e93c147f41a401
m_0b481d7c268e483d95f559d79232c71b
m_905793949c3b45f0abdcc1497837850e
m_f55b45fce61240a6a0f8463db2c37a5d
m_b60b1df8a16748a5aba00f43086fb486
m_f9aec897f8f748a6aea8213862f2a064
m_41fbb76d948943b8a9cd334dea6b4565
m_c30d07c60ba34d59b1e67936cac58fec
m_66df39902a9d40af9fa43dfa485650ec
m_5b1a4585b2e84ff49d34e16dfed32b58
m_cc0586e4ef444b80b653402f4017a427
m_1fe59a81ed104925bbbb24a1f8cedd46
m_92912e6ca6284260a784dfa5b3357ada
m_146a474be85f464dbcc3fcd95e3d81b5
m_8b8eb94fc55343c2bcc27764ca84dae9
m_f8ccbbf82aa04b0594314ed56c4c102c
m_650b929d53334f72875fc4870700f0f8
m_3a017018071b4c62b55fbeb2f9bc50e5
m_737fdd63c93b445f9c432ce743910102
m_1f7e8746658d497da88c135ad074b1be
m_e0ec470a75d648198495db8f68ab29dc
m_62d6620e348f430bbf21aea4c6b921fa
m_5d6b27c46e7f4f9ca3d93d9fc9d8bbdc
m_58b6e737f87648f7888c5393c5d7fec0
m_4f52f20c62f84e08905f13465a4bf307
m_7f5c95e5ddd047cd92de5669778d40e7
m_1907ae347e5845d2aa308ae78b6e4696
m_dcf2fc5be4dc4abb837ab9f1215b8497
m_179bbb049fed4efe9d7b23331dd0fd4d
m_42e21004e1da40eca7a5d419867e2374
m_aa248065dd904045b69edd346c288e7f
m_bbfd9f2eab984e4b83759f3981040cf0
m_8c89d81a28cc44b3b99c8fd7f8d2972b
m_ba687c1010ce4d0d8d18da39fc3f2210
m_d50c0e8223d449b1bd432807f4b88e3b
m_8070cfd2585e4edc90df62b21eb15e9b
m_636afb992ae045b99b3ae2d6616fefeb
m_310ff33f7ed14e449dcd46082ac4eb09
m_26e7af05cf6c4777aeec134fee4e6107
m_4b427a064ea44d6f8fab117b2ac88332
m_2d933b62c0b042d8a5616d6f556bedd7
m_1619a42730814dbd8a278d86b82af29c
m_1c20c43a74f64e65982ccc90a4c1fc03
m_dda459070fe942a6a93be427a43cdd45
m_7efd0ee7df164a9c954278d82554ebc8
m_32ccad484a6a44848f87957b47b7a2e3
m_8cb7d8eacd944f17adefc20ed9c81796
m_b3f2f623997545b5901c1067bafb1040
m_039898e79e1048bcad171865d1547886
m_754daa87b08c47249fc6c9599f0072df
m_d83ac077895f49a392519baee10fb147
m_3fc5369f9092464d8a39d270f8372bf0
m_c34a0f0b912d43feb63a98f660ec2605
m_210bc2bdd2cf4f57aab111a38b0064f3
m_419f534e94044209b0734a9c2900adc3
m_4b7b50acf58343a28718e9716ebc1f5b
m_f210f65327ff43bf91d68f240e8046e7
m_6acfd24417384231b7b1eee513619354
m_93f5e3877ab3459091227897129aa5c7
m_10f7a103838a4ddbbaabf31d765349f3
m_32d14bef8f2f42259bd34d1a36f00ca4
m_173f27b823b146edb74e57b4043ed026
m_f2c68a2826ba434eaaa31ee8f6adc360
m_f2853da28859438f8ddcb6b693a7a07e
m_33a7981829e24bc09726abd6c22aa722
m_f2b3815542fe46988bcd0d06e01c9129
m_f0dbd9b028ee48e5a6bccd8c7ebdaf7f
m_4c954223c8a3457190da6e50dc713f5a
m_75e19a9036494d1d9271696de12d9e2d
m_90576eec691048678c8d3dab55652314
m_e9dbd83572d3486fa39575656ad8983b
m_617e8226a9264dd5b27a4129a4f52b50
m_3c3b67bde02746b999927044e918b2b1
m_c936d3c8249747459ba4a4f5699592f8
m_6b0f143b662648be8ad3649f1ce93d61
m_95e17a0de3ea413895efa4e56173af35
m_33912f79c8e94dc98006d49c5e00ffe3
m_d294ec16824d4e78b983cad7a69a11e8
m_29625391011540f09a28b1194c2a4728
m_98af25d226aa4490a1d91c4a582149ec
m_db086c4b1c6a41a4aa78c01daa804578
m_9f7efa395faa4eaebd711e20f4f90fab
m_b0d697102202449da6f7efc3f1c2246a
m_78071cc9e72543de83528daa7d255df9
m_686f8e9b289044ba8384eb5e864605d6
m_085afa9a9a924ba697a2f72d9c9d32d3
m_c369bf2ca8794ee1ac518918b202eb60
m_6d900afbd9294566924ff8e95f238a6c
m_9103b7a2597c450ab56a19b48efdf13e
m_d4468116e8f04f7fb558c0b158f03a8e
m_275ca0832af14f55b6b788f81e522883
m_cbdcc1b0f9ac49b196fb58f726736f97
m_c2a814ea3c3f4bd7b6f0444d2fb70928
m_56ca6ab770ed442387be63f270e5eb93
m_d21d4127af054ae0a78ba6f02ff21e7e
m_975437b4e33b465f896059964a73e0f6
m_816333dde2d246d286b8a0a1e5cd111c
m_f86f0645111149f5b051e3c18aebce29
m_8af56835ef8a45c8ad08358b1d7a512f
m_62a16b9fbe124c7cb03c0a96f36ed30b
m_82f18d72dc684a0a8e8b48f902e9f0c0
m_85d2802d5ece413683581c13ad8458e9
m_31da8fdda0114a76a05bc6315a21808d
m_a1c086298edf4be8a92fc792b97b714c
EnableReponse
w9a9388f3b8e74c50b28e2b2252fc33bf
DestroyReponse
ViewReponse
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
STAThreadAttribute
CompilerGeneratedAttribute
ExtensionAttribute
HexIO.Readers.ProducerSingletonReader.resources
Zqbpytwp.Queues.QueueFieldQueue.resources
Ftqexicg.Properties.Resources.resources
WrapNonExceptionThrows
"IE Per-User Initialization Utility
Microsoft Corporation
Internet Explorer
Microsoft Corporation. All rights reserved.
$e04afa6f-de33-40ea-952b-7bb26ff259f5
11.0.17763.2028
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
kdR9E/LiAIFuRHSE0OQZzA==
3C8gz72kng8/anwUTh/u08IVdTdHgToHg33L8hEtOxQ=
http://80.66.75.37/Gqfnqspsx.pdf
listView1
DvAoXZBX5
stream
Unknown value read for [{0}]
RecordType
Line [{0}] does not have required record length of [{1}]
Hex record line can not be null
Illegal line start character [{0}]
Hex record line length [{0}] is less than 11
Checksum for line [{0}] is incorrect
Invalid record type value: [{0}]
Unable to extract bytes for [{0}]
address
Value must be less than 0x10000
addressType
Value [{0}] in not a value of [{1}]
AddressType
Must be less than 255
:00000001FF
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
IE Per-User Initialization Utility
CompanyName
Microsoft Corporation
FileDescription
IE Per-User Initialization Utility
FileVersion
11.0.17763.2028
InternalName
Zqbpytwp.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Zqbpytwp.exe
ProductName
Internet Explorer
ProductVersion
11.0.17763.2028
Assembly Version
11.0.17763.2028
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/MSIL_Agent.FOC.gen!Eldorado
Symantec MSIL.Downloader!gen8
tehtris Clean
ESET-NOD32 a variant of Generik.JBFBVKR
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Microsoft TrojanDownloader:MSIL/Remcos.CXJK!MTB
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!F369250DB766
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Remcos!8.10BBA (CLOUD)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilCO.36318.cm0@ayJbCcf
AVG KeyloggerX-gen [Trj]
Avast KeyloggerX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.