Static | ZeroBOX

PE Compile Time

2043-12-16 00:00:33

PDB Path

MKInI988.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
*H\x1d}\x06\x03>Q 0x00002000 0x00000250 0x00000400 7.82044575369
.text 0x00004000 0x000017dc 0x00001800 5.95027614154
.rsrc 0x00006000 0x000005a6 0x00000600 4.08849039952
0x00008000 0x00000010 0x00000200 0.122275881259
.reloc 0x0000a000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000060a0 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000063bc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x408000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
O$EK_r
j":u|l
MKInI988.pdb
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
UInt32
MKInI988
get_UTF8
<Module>
GetHINSTANCE
System.IO
mscorlib
Synchronized
ReadToEnd
set_Method
defaultInstance
set_AutoScaleMode
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
get_Module
get_FullyQualifiedName
SecurityProtocolType
GetType
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
WebResponse
GetResponse
Dispose
Create
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
MKInI988.exe
set_ClientSize
dwSize
Encoding
System.Runtime.Versioning
FromBase64String
disposing
System.Drawing
get_Length
Marshal
System.ComponentModel
kernel32.dll
set_SecurityProtocol
ContainerControl
GetResponseStream
System
resourceMan
Boolean
System.Configuration
System.Globalization
System.Reflection
CultureInfo
lCPjosq
InvokeMember
StreamReader
TextReader
Binder
get_ResourceManager
ServicePointManager
System.CodeDom.Compiler
IContainer
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
MKInI988.Properties.Resources.resources
DebuggingModes
MKInI988.Properties
BindingFlags
Settings
System.Windows.Forms
get_Chars
lpAddress
components
wTirNVUvqNt
Object
lpflOldProtect
VirtualProtect
flNewProtect
System.Net
op_Explicit
get_Default
InitializeComponent
Convert
HttpWebRequest
System.Text
set_Text
JARjnNzYiWu
get_Assembly
Confuser.Core 1.6.0+447341964f
WrapNonExceptionThrows
MKInI988
Copyright
2023
$90380a20-8194-44ff-950e-3a8dec2a5fdb
1.0.0.0
.NETFramework,Version=v4.5.1
FrameworkDisplayName
.NET Framework 4.5.1
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
http://84.54.50.31/Ari/2xxload.txt
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
Better.Better
http://84.54.50.31/Ari/GoodLL.txt
MKInI988.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
MKInI988
FileVersion
1.0.0.0
InternalName
MKInI988.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
MKInI988.exe
ProductName
MKInI988
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.Common.85FB58FB
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Tedy.419780
ClamAV Clean
FireEye Generic.mg.d5eb2ad29761398e
CAT-QuickHeal Clean
ALYac Gen:Variant.Tedy.419780
Malwarebytes Backdoor.AsyncRAT
VIPRE Gen:Variant.Tedy.419780
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 0059e0c01 )
BitDefender Gen:Variant.Tedy.419780
K7GW Trojan-Downloader ( 0059e0c01 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36350.au0@a8WbvUl
VirIT Clean
Cyren W32/MSIL_Agent.DGI.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OOD
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/Stealer.0e604cdf
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Stealer.Agent!8.C2 (CLOUD)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.pufhh
Baidu Clean
Zillya Dropper.Bladabindi.Win32.437
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.lm
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Tedy.419780 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Gen:Variant.Tedy.419780
Jiangmin Clean
Webroot Clean
Avira TR/Dldr.Agent.pufhh
MAX malware (ai score=85)
Antiy-AVL Trojan[Spy]/MSIL.Noon
Gridinsoft Trojan.Heur!.03012281
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!D5EB2AD29761
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CHJ23
Tencent Malware.Win32.Gencirc.13ecb08a
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.OOD!tr.dldr
AVG Win32:RATX-gen [Trj]
Cybereason malicious.44b354
Avast Win32:RATX-gen [Trj]
No IRMA results available.