Static | ZeroBOX

PE Compile Time

2023-08-26 02:20:57

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005eb82 0x0005ec00 7.99637831578
.rsrc 0x00062000 0x00000708 0x00000800 4.69562946409

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000623bc 0x0000034c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x000623bc 0x0000034c LANG_ENGLISH SUBLANG_ENGLISH_US data

!This program cannot be run in DOS mode.
`.rsrc
DUwg0SD
sQG}1r
0( /]%_
jZJ]Egel
-8q63vA
Xt$]A0,
T6,{,[*
BX7P,
/pFJ{<A
xLO%05
B>&x8*
m#Lera
8=ixe9Q-
i&lO|TYmBX)
D/eB~Z
HFAH$J
}ZLlxVd
(ebvjy
YpTeQN9
gd@d,oT
+;CQjt>/
oOIFc5
^h,Y}U
`C8/^_
Fm5QN|CI
8Xa2)!
hbEX7-
RQ]aj*h
u@*Oj-.
3@%G!7
(vc.^CS
dV8=ij
Jp |[Qq(.
V%2J~@
f'+z7f
On>MwdJ
R+t-Os@f
*j21 af
|&-7qn
nTQX<
PDSs0u
dlA,jR
/fD9_0
7 %,v%:
(@}cNok
<[?mG8
vn!A2g
"njA\2
Js{=LY
2xu5Y3
EY20d .I
=mOJ}M
M?V;s}
}bX}mp
cTB:FT1Q
@> !qjy
WIEh_G
XSA?}f`
]qlv
Pj(}*#
F?F~~Y
)u8`&cihL
[mE1+&;v
`U9h(V
>X>:Zp
zO!W_
s&04D
"iyX;V90(
Y%]{j'
}k9gnTA
{Y3T$x4
5DGVpW}
-Hdu#=Q
+x^Yz^>
E)E3s;
yQEwN%
q,8ebk
]bb0`i
yf%xv\
Nrj/65n
KAj&pQJb
F[ou6r
'x"dFg
{)hHuQJA
mT@USt
re 5=pY+
LJ&qkf*
<iHLk5
a9AP.C
/WW}\&
|(um`]
;OuoI[
1*;7?C
P/E64iAf
uBcW4Ad
;1dIM9
\g]+k9@S
}<Bd<F
xZp`AL
>d6)'Xb
l7;F/}
;Q7f+PF
j&:pWbj
TBi=o0c
Yts(v|
YP{(b*
6$;R<=
8E4Fh}B
@$q<];
AtP(4>
PU 'Dm'
c?>(g
=&W^Z(
<@YAu?I
)B/4@I
D`L@C#s%
kmMh<o
kyD{wS
3_qc!>
=!7$g*^
}a;usT=
F<q)?6
8UEGXC
v?t]b$
Lhwtp`
jAhz d
%+AN87
t&R+N|$
%$ :f
_n[W-C
cI!wC<^
HHa=d7
zRD"zw
i@iDSH
cO/H?XfR_4
^>{E d
SAsOk~\pj.
RM66(=a
J5j\A7
Keh4hc7
LvsyT G'Bw
-|BUd
,nGlQT
iE%J14
?g7./<
_^AeFP
IO^&lp9j
$sIgG
!rnadt
#h92?l>E
m10UDy
dN#%+9
2DQLIF/M
8'sM?Tq
.P^M;&
Gj"<Zy]
=@!y+#
tz^9}|
5qBUe`
ggQt@=?"zV
7}xPe{d
x>xV\&*
7l!].[
>sd.c)
4okBMK
1l7WJO`
:$o|RE
_Ub*tx
%n=\p*
tf%ZQ/
5!47Vh`
Mxu@lG*
POQ{d"
POQ{d"
-Z(|tK
YNK7I3
s)=8D%
rM3t`vY
K$uKzLsv=
Pq6NP7|
_`c2T`
l#gyEx
c.r:F8^
}64FQy
zWKwwJ
V>S.Gar
u>S.Gar
_7g^N/i
E%7;bhg
e/]j4yR{:
CSD*`X
Wt2pr
^uS@/^
o&K',Q
7|cyX6
U;AuF6
ROyaUR
e/]j4yR{:
7xtg"e
ghZIWZ
Tz{{\]
OSZ@ufg
_sv%R+
L=##%M
T,:ww)
^W%&"B
}mTG:1
Vy_R[9
")LjNL
S2oVJy
}FoZwt%
0-#JTm
7xtg"e
;B-GqK
e/]j4yR{:
e/]j4yR{:
~HECJ3
;1 0KD
~kBwkf
W%O}gC)uq
g'ZFZuY
e/]j4[
<KgN^y
*ISy@4
e/]j4yR{:
e}FeHa
e/]j4yR{:
ht8{N
5byQ'
msCI/v^
gKP"fKUyYy
0jn$)G
E)'9!a
e/]j4yR{:
:9cSE(
`8 *ts
L'LEMe
e/]j4[
jO"&9)
Dz+"Yq%h
zozJO(
|@;q%Q!t
b3zkZi
U;'?m<
vSKZH|
|z<vd<p
6]\&qA
3.`,xPHz
^'&#K=d
iBe],
Ui<ijn
aU1mG
'3f_iu
4lY3,i
.`5'N-
pNNBfh
_O-+)PY
\{(X+5
|46RXd
.*uSX,
NC_jg#
-LWCWW
JN%KxJ
xy#/.s"
p+lMCyL
We?0fo&
rFIG`A
vd=.2n
q)jM/36L2l
i08,.e
vd=.2n
953_MN
X&-O~g8go
p5ykI*
`F{gZ1
t.?"$:U
RdCia%
.SAo<
2gm_M9
OzAwn(
Q!yDiK$
;vBYZs
7L*QfuB
)W)W|r
.AKm?|
dg!S:q
^ok)_O
v"Y&g/z
2-(-A&Q
9`bDgY
d94iVT
_9vm!l
q:]T,!:.U
@eK1/ct
LnYstV
Gt<YV|
U{%j8{6
;u^dQ^
y4Z,Lc
g%~4/|
N\w<4t5?
IX'h=k
O1Ukkzm^
jR;}+bXy{J
U5x2]^@p#
?'uVo`
_5V6($
tsBjX]vd
y;d28.J
ds?-wRi
4j57As
buOr)W
x|C7t,P
q)gI&.4
eS9Z\k
F9bXko
U_mSG[;
Dn'}<-SP
95m>Y_
HHY$w6
!:@ah+
-I Q|E
5y-Zv=
gs`#)r
^{A>;yT
5+;Ipze3*
AuiF]=
n26+~(c
wJ~=6*
I?z,%r
7>%,ny
Kn~6#^U@
:r E!{A~
mwC2!GK
'X;GbodmG
y7/o?jW
{\>/ju
Zmx!#j
}\,ZLL
'=,B6ZB
{[N 9N#
-CuUWxS
pX"\`R
8N[D24
'k-MkP
~AlW:6
_C.t'M*&Hz
W`,mI%q
..|BclY
e1\^B]c
'=MI@??
|qQj{Jq
m/O%fp
8#'yOQ
"Tz2la*
'X!CArS
m}:07(<
~r0!%OL
n8V9kB-
xK>vvx
*@k$[6
W^K!E>
*B0r[DB
:HomHO
jLWZ]#x
YSmK;=
&Dp^R]]
!$$}TBj
rOi%0~
KI..{i8n
7D:$p>j
pb{ {x
3fifgg
x!|HB)
O'0&KD
\CtOJ*9
parTq5
9w-(z
mj)S~$_
pplHfw
Ff*xK)jD
DtsZq]lk
X`Y;e;
^Y''s_
vSw96\L
mDo!St
}fKy[(_
Ch)=]w
OeaUW6D
yj+hF8
AM-Lt}j
QTM`|Q
cJsEil@;
~SwUKDg
^oqheS
s>H]~UZ*
>(h4xP
:1(pj}=("
`\?lmr7
?\ugFn
$r;\W!
9;D`>:
x+t.f.*
k9alwT
&p)N'G
{>"pIgY
u1k2p\
)&@1Is0
Knaq*60
jAYaLF{EPz
?le)]+J&
6EXN(Q
wsM6En
zV'RiU
._(MxI2
cr}#d']
cZJvsjK
a+vPA"f
Vi+HU%
U|Apd<?j
4lXJkp
dm2gP8#
2)+(g_Y
/`Q}Ii
>?_@bV
t^uM7 Ga
w$'?z>
(:}:w_
R05d-01]
%@(iRn
n/b4F*|
3`-a1+
h^GTvw
W-S.l=
~GxJS
:no\Qg
f\G6Kns
im\JZh
.YPFL{
#]@BO>
h-c.Ak
)>dDRI
ELiE(z
&(+V{?x
)pLy-&
G7}7u)
c[7dt'
`8AC]
Zo|CIa96w
496[9Gjf
@-3o!L$F
w&2vT``
q|#+&m
LiL1J^
Z8:d>vHw
$`0|uN
e\k=1#
/n6[p{
V0pk'%
/KQLtL
%0zKQ2#|
$lMz3mV
4S"+sNha
0|(\yG
8H>l]aU=|
J6zvyar
!j`O@5
<~RuU}
I 1{,p
L7DK+A
p-5\(L
h]5~Ky
5,J.h`
|f=jZ~
"@"Ie" Q
.Vw/|De
|#/YvvC
VSW=~R
^pDjvma
v__8IT9
'g^IY"
b>tA)?W
J_;_l_y-o=
1q)vWuEV$
'J1A>B&P
iipO<ku
1g$}!fmx1
aIRb'(Q
T*A#l
H,:8f:
<;;u=a
09C;
wv`hB1
BQ,*dO
GpF{h~
-2<Zy>
$'\_~GC
B8f ]D;xQ:
OwfeNqZI
"J8Nw6i|
ABjW E
r*f75N
FxRiCi
,h)2*
#;HF2|##81
F8rbp'
q*zX~HTb
v/e`\<
c{6fQz
-u.:-&FqK
H;{ T{%
[xB_oY
~N /5_
1cWR~+
=rH3S:=
zCcv1}.
x\Oyy;
-cm0%D
1<Lwe7hwn,2Q
O!(R87XI_:
Q2bj~W
Jg?j,}yf!
nvdNtU
m5~9pP
6X|evU
|kODE'
qTDi8<
2)W+/&
7T!xia
BL;fw
rSQst@F1
5qi>gz
6+n{vpn
%`K=t3
KQhqX-
WpOlm:
dj(&;1
`da0f:+
QbmOP,
+s?+]Ow
MzUuZrJ
)*j~m:
LD3EO#
,Zl-w]
\&fIu,
xW$(#4
c+rNH"
YAC}lN`
_4s4\+
O]sw,P=
X~qr/A
4--FuMHa/
/L'q?K
:9L"q!
AU/%B1!
nnbi:2
wslw7EIT;
,Q;2f3
h&FzKX
IRs}N<
{?Oevi
CCJWTfQQm
U-2fk"
q)Pb@tH#
8Kzw\
:7CceB\
G-;DP3
qB>N.Mt\
_j0!<0RX
R6VE4m
{g'>qx
\-6&7f5
6,UT,2w
9 9r'}
6JQx$|e
]VGb
C"4B2O
U0)pfF
NZ$]u1
T1xV5G{
x{[uB|r
&/XMh{e
`C>xow+
m8ucbA2v~
%Og|jq
[Eo/EM
}6*Cc(
2|t?Wdo0P
3wc(MO}NFMO_{T
>AY^{\
xoa=NF
i7:B#9|&
fRhs0j
mJv*"r
!~Wv%(
o9~pM)
oQ~T3%
eCo<tJ
"R0Cq6
P!7SbRc
V77$ij
9pVx8b
p:2,$ 4
cdD}Fn
Fl)^M1
:'xz.0
YBl0fkN
ff0 vt
Fc?3yg
9 <b0h
ZuNDSE
u,@;s66
$zdNf
$_7J(uU)L
mJ6(-([
1pz"vA
HVc#l`
j.\s_o
Jd:~8gn
-U$hU-;
{v'y{\2
JLe)IY
%w}|g=\
Y\rG{$w
x -)en
Uj)Rp#
wvCl;! T7
0>i[WKL4
{Mv}*Ib
i'kv4Hk
=3ka4[
rb$|"
~\D)^4
3MFly9tw
Ukv{v-
[A_%yr+J
GtC2a+
YSIX06
S[%\)]
i6Z<99
w`~eN`r
Cz<$b.;
|1 1|N
U;anbf
lgLz=>
XbZsUPbm
<S=f#*
^o}-^ol
dS(0]c
{]OI J
)^z@z>R
GGb96sn
a,+v"~S
r h LF
XFwlV=
1AdP"a
Qh&K`w
O\Rn+
-2_wFb
1}}pW?
&#iVgXS
vbaN6S
IXP%y
V?eu14
t%jJjKc
^zAO+wX2
pMD~Z)
m:`s}#F
,|%Ce.0
0}|90b'
b}XW{9
"(*j;!
2ECv5{TnY
l%n:
VdrlJ?"
X\h9Bb5
M9/MR
`&:9Je
C5k=(i
*.]re1
O:'nHh
^{2C(w
%n##D6N
0$:`\!
\(]q@f
Ehazhq
fn)bW3
P9Hu)p
E*7 b\vU73
(v_Dlo5
}L\U*r
/@a*qC
n/8u1:
v4.0.30319
#Strings
'$$method0x6000003-1'
D84F4C120005F1837DC65C04181F3DA9466B123FC369C359A301BABC12061570
Ldc_I4_0
Ldarg_0
Ldarg_1
Ldc_I4_2
Func`3
Conv_I4
Ldc_I4_5
__StaticArrayInitTypeSize=6
'__StaticArrayInitTypeSize=381968
<Module>
<PrivateImplementationDetails>
9F64A747E1B97F131FABB6B447296C9B6F0201E79FB3C5356E6C77E89B6A806A
get_ASCII
mscorlib
DynamicMethod
GetGetMethod
GetSetMethod
password
OpCode
get_Message
Invoke
RuntimeFieldHandle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
Console
WriteLine
ValueType
MethodBase
CreateDelegate
EmbeddedAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
ObfuscationAttribute
RefSafetyRulesAttribute
Encoding
FromBase64String
ToString
GetString
DeclareLocal
Marshal
kernel32.dll
Ldnull
System
ICryptoTransform
Version
System.Reflection
InvalidOperationException
MethodInfo
PropertyInfo
LocalBuilder
aesCryptoProcessor
GetILGenerator
UIntPtr
System.Runtime.InteropServices
System.Runtime.CompilerServices
OpCodes
RuntimeHelpers
GetProcAddress
AttributeTargets
Concat
Object
VirtualProtect
op_Explicit
System.Reflection.Emit
Convert
Callvirt
System.Text
InitializeArray
System.Security.Cryptography
Assembly
op_Equality
op_Inequality
GetProperty
AllowMultiple
Inherited
Feature
cloner
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
q8ugrO3il5a4W+hiY8UnWg==
qLgb/BCrwRTTr78SxLUMRw==
Error:
EntryPoint
Invoke
ProcessVM
Create
Padding
CreateDecryptor
TransformFinalBlock
EGA+uSQ0MjAp0kgyjMDq1Sh06T381wPFpmPneiNF8KM=
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
FileDescription
FileVersion
7.3.2.3
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
7.3.2.3
Comments
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904b0
CompanyName
FileDescription
FileVersion
7.3.2.3
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
7.3.2.3
Comments
Antivirus Signature
Bkav W32.AIDetectMalware.64
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.ba84cb431da839bb
CAT-QuickHeal Clean
McAfee Artemis!BA84CB431DA8
Cylance unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.8d6044
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.GNGA
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Fsysna.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Generic.fc
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan.MSIL.Fsysna.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Clean
Acronis suspicious
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DHS23
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.121218.susgen
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.