Static | ZeroBOX

PE Compile Time

2086-10-26 21:26:51

PDB Path

NNJj.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
"1tT\x1b\x10"l 0x00002000 0x0003cf80 0x0003d000 7.99934540441
.text 0x00040000 0x00004c00 0x00004c00 4.88585934517
.rsrc 0x00046000 0x00029802 0x00029a00 5.01854718516
0x00070000 0x00000010 0x00000200 0.122275881259
.reloc 0x00072000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006ee30 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0006f298 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006f31c 0x000002fc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006f618 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x470000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
:5@N#tG
sia_*k
uKTM1r
k]G"{*W
;PF[5-
wkSM`R
3)a+1}
sGHRT3^
B]"g!z
MarDVV
,c\(l
O ^FD)
},r(\_
CV^d3G
W7|%dj%
Pw*f:0X6
_,'3Uw
\9B_M<
^+}NMF
#L}`IY
GC^&3C
r9[\~.-
S~$.FXhp
cKj>"b:"
1S<0VK
%c+JPQ
:s*b9C
oFjT.y'$
0r1:<W
jf|.)/;
Npsrrk
Em-,D~
IK/yH%[
O/76we
K.T>_+
F"`r>@;=R
THbv2*
H@0MKe.
<3gg|'
u=(z\,|
N/T1l!
EVD_5I
*817xvj
g]L2,\
&Y<zNm
g-@TWhe~
asIy@To
s4R"Q6"
7(UtfR_
Y82{$Y
3F^S[=
C./ki"]O
.cm%kp
IZi3ny
?L|oU
CnEqP,
-282Ks
)Hf4r}
`m_4.jk
$*{ErM
>X)UQg
7[jp&a
:hm!&Q
,lt85yN
PX6+$(
]';97F
ntY_:H
R1HNQ
si>rtJ
SRA)/lO
cx~in\
@KI{WC}
JEh-`T
goySo
"v4?e>z
m*^lb$
ZzmFBi
hl}j?!
%KuIf/
H^i)NY
?'busJ
?sC\p^
bSi$}J*
v))3FsPR
HKvumw
u,MQjJ
^ePX-0y
o=|EDLl
#H 0=+
t$'[\>
Vv1J T5
Zzys0!
!_y_J`c
gH5)nw
xbCgfm
k=aS}HSos
4iCD#+
2'oks>
kQ5U.z
lj0y@m
,t9;[3[
Jf d[F
FU;)<Z
YP2Gs
'u:+(fn
,*,L$I&
N[+uhL
|<WgY~
k5_P)]
\Z,w(%;
")7P:}
\,%S<V
pFv@+&
>f(IG)
'0vZ\-
~VfYOd
N (\%%
mF/!ti
z@+{9%
E"jU]S
-_5e[a
)APm:4[
ix]\i~
l.>h{i_
%.v9tK
#kU6O=5
Z,Wii{
q"RP(
&S|epUz
F78>$^
UQ-Ia
Z0@hW.5
tuw=C2
'K^up3
fS#Fs(
OX0s"8
ZHB/'1
@(8~(Y'
ju4()O
c8{|0
:b+AE.R
rdtb$q
!6Mxc+
=!K[;Xsj
td|j\B
K*1>]v
^-\tuq
O0_kBk
#4Sx|k
E;}<V_
1?*6[4>=
hgX"$=
cc.(_a
P)w%]C
cF<Cup
Wv,E5m
)`]E>v
Dt9g0<0
l7iElR
Y>\+9e
0g;'[57
~uG%s
G`0L(:T
UVlfg
|4AA_DI
xE5UEeB
c VyP[
&WK7?5H
:?gVO<P
yY0 a/
0*+b0F
xd#8GV
<GB))D
YLP0^r
&AuusR;
Jp0y%8`7Na
Tx.dcp%
b*3 2!R-
5SY<:4
/?iIx4
KAGiOtZ6T
cfy)BD
s^x,Xb
2 .n%b
* b}AFO
%kd?m@
P}My<nq
*_t'3
={Ow1<E
VsjoYu
EQ)5@V
J)jENV
esk?UK_
BPLNi%6D
c*dK|g
i+s:fd
jg7L'S
N +QjC
6g98Rol
oDEHI<@
H]SK3F
zm,C3?
="<1k
5g|?>x
TpD{sRr
1zVR/u
XS Q5)
}OgHu\
iCg8Ou=
m[:[.b
?V.,-I
Xc(9YlN
~8T?,ML+
WJy.~!
4f_7.esjN
f#'b#N);
(&_ers~&
ja$E7p
,{`%[n
j$]q=\YM
kP4w.p
n?Y0G+Y
j(K#,d
Oen)1@|p
c@UHqQ
Lf?5y
WY:Os)
pfgZJ^
Z!Z`GnZ
hVW[p.
GhdVF(+(^7
X]9_9w
5bB-Fo
SAz.2G
~rX:H<
@5'2J&
%fWZ'o]
*8(^CJ4
b\w)W!e
AEY8;b
u$<h5;
7-GbNt
K%q6gB
I4PVi*h
9\6~^`|A
#yCWh=X
TixOAU
=wuX#O
gL =oN
$gLNZ
fUPUTF
ISHLvw
?DRo}QQD
h\n]Q}$4"
}f(|"X
]hz{&;`
Nh$v"\v
jjR}=;
"mOs[X
rscM'b5g
Iw'd)I
G|m.U=
0<,X hf
pg9sns
LnxL"G
UhQ%-QZ
lZ@V2}
@$7$={s
J4m[=i
4+X(B#
d==\gs
W42m.
3lR<ls
IAf!e{
FxUWDGk
}t)WhP
gr2CkC
C#)@.C
]4M7zaBb
^qU@aT
b-Y\#)c
,%*whf
R4Y\b,
)wAa<
F_nxqA
KmaG+r
GU1{"q
|bJlAb
XI]p|
nX)f=B
rtfU"?#
~wWbz{
9VG6I`
5ze/yC
hOsNw<
xD\wEf
5,6/^c
,Y!Suv
yvGJw'"a
`kU,ldu7
C?!Gk\
WNPN6rR
;:k?`u
VIm9gJ^iZq"
<|L`2>b
wQg}_AzRq
%G:f%FT
<MTQg.I
+"`U e
XXyWn.@
hx&9Gy
lmMFO0
`(zs_=
@C@L&
wHoAXM
p*BK7'
-6deB3
L~ (VV
feJgF{
(0esR7
VQvWlP
Z|>j%nPG
#D#ca$
< mq5Gd
RF68Ub
wxs_j@
soyp.C&
%%N.f~XZ~
j[ZZ(
[%D)s,
%|B"#SK
|Ou %2L1
Y6#DVA5
|A7 >k
tCDW,
e,n5mQ
{ybi|2U
%usN*ls%
74:C'9
Jw\o(Q
4,]+Ga
V7J%3(
l5vk.
JL,`<&
#Dn!M|z
8?"4[0
L+.Yzf
B(rKf_
#~bA_h^R
SF]}}[
skF9:$
&N]7W~k
S%.*PKY%
jj,w]U>
'Z'n^
?3H83]
"cZF<f
d^R%nN
U!``H=*
Rf#*}V
%D_,4J
x#v'<$
@=[Po?s
o=/LT'
u56E8X/K
[VAbXQ
5:,6B<
t %Ek/;
8Ju0~sK
aj)Lh-
|:N(6$
74kkju^
%ca V,?]
:fyns/
%j`^>7
c;hSkq
a'KJ+]#
(v5hcj
yTu}"%
.@KDKwxf \"
BKkvqP
Sbmo+]2
r#Lf-F
XT`i,;
4fd,$|
gxmNf9
Wce"6Z_Dl
|Sqyaq|
}.k$B7
`D9rK1
bbNTT=
6X$$"J
J`wS8pdu
PI6DLq
"n,=8[HQ
.Ed8ZkU
J]emA2
S33-1u
Q"Jy~)C
{F}$EKX
?v_=]K:1D
]DffG&
v\hB+J
b:M=&a
Z18'\9
a6|O)kOz
K,Bal-#9
.IOZXK
np(W38W
QP19lVx
]z3P+P]R
IW5^4#f
1c1lt]
Ako<Rr
hp\|^Y
{<Xw}j
iDA&=c
^[Hn;#a
d[wNd.\k0'
4*-CFH
1nVq7@1
]j}<FB|:
=/!}\&D
xc[4lo
W'%x-I)
[[SY<w
Tg)_5Yj#
MO[Wn/
_SQ*P
bTD#S9
_5KYiF:
[TGtR6^
Uj4VeJ
,#M9K8
v5Qy|t
uSMNG0
NNJj.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
Service1
UInt32
ToInt32
get_UTF8
<Module>
GetHINSTANCE
System.IO
mscorlib
Replace
distance
CreateInstance
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Module
get_FullyQualifiedName
set_ServiceName
ValueType
GetType
GetElementType
ServiceBase
Dispose
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
NNJj.exe
inSize
outSize
dwSize
windowSize
dictionarySize
Encoding
System.Runtime.Versioning
FromBase64String
GetString
disposing
get_Length
Marshal
System.ComponentModel
kernel32.dll
inStream
outStream
MemoryStream
stream
program
System
Boolean
IsLittleEndian
System.Reflection
Intern
OnStop
InvokeMember
Binder
rangeDecoder
Buffer
IContainer
BitConverter
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
properties
numPosStates
BindingFlags
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
System.ServiceProcess
lpAddress
numTotalBits
numPosBits
numPrevBits
components
Object
lpflOldProtect
VirtualProtect
flNewProtect
op_Explicit
InitializeComponent
OnStart
Convert
System.Text
startIndex
InitializeArray
GetCallingAssembly
GetExecutingAssembly
BlockCopy
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
Copyright
2023
$4c64d1a1-6eb0-4e31-9e55-ed7c216a6916
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
h9|k\h
kC1\95
e~9y)a
JdG=g.*
<W_J"cr?|[o
\1:$!:$
]m:;;]
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
NNJj.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
NNJj.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.Common.72C3C045
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
MicroWorld-eScan Gen:Variant.Lazy.377778
ClamAV Clean
FireEye Generic.mg.840006dac67d23b7
CAT-QuickHeal Trojan.IGENERIC
McAfee Artemis!840006DAC67D
Cylance unsafe
VIPRE Gen:Variant.Lazy.377778
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005a1d701 )
BitDefender Gen:Variant.Lazy.377778
K7GW Trojan ( 005a1d701 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Trojan.Win32.GenusT.DPVE
Cyren W32/Noon.AR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AIMG
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba TrojanSpy:MSIL/Kryptik.8af813bf
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.94 (RDM.MSIL2:5OiQKhvAoHrnzZjd4d+5yQ)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.pgfcg
DrWeb Trojan.Inject4.60263
Zillya Trojan.Noon.Win32.30292
TrendMicro TROJ_GEN.R002C0XHL23
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Lazy.377778 (B)
Ikarus Trojan-Spy.FormBook
GData Gen:Variant.Lazy.377778
Jiangmin Backdoor.MSIL.NanoBot.t
Webroot Clean
Avira TR/Kryptik.pgfcg
MAX malware (ai score=87)
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Trojan.Heur!.03012281
Xcitium Clean
Arcabit Trojan.MSILHeracles.D18482
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Noon.gen
Microsoft Trojan:Win32/FormBook.AFK!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R519514
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Lazy.377778
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Trojan.MalPack
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XHL23
Tencent Malware.Win32.Gencirc.13ecb019
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AIMG!tr
BitDefenderTheta Gen:NN.ZemsilF.36350.Au0@aO8FfEc
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.0d2cd2
Avast Win32:CrypterX-gen [Trj]
No IRMA results available.