Static | ZeroBOX

PE Compile Time

2023-08-30 04:59:41

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00087590 0x00087600 7.9944072331
.rsrc 0x0008a000 0x000006d0 0x00000800 4.71682429709

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0008a3a0 0x00000330 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0008a3a0 0x00000330 LANG_ENGLISH SUBLANG_ENGLISH_US data

!This program cannot be run in DOS mode.
`.rsrc
o)AcP>r
Q_9<l]
2)f7lU
_)#/lt
iBDuu?
^8kEX
?_zJj5
U]W=[9K
ie8{rB
QK ob3
ZP&>t_rr
*F6p55
e!@bqXO
&u/Z#]
IWw%S(
?')a1"-
JFQU)O
A4`]3k
nt,b7pf
!\<OrjO
lxYk{9
MQX{!J
!?y0AP
L>#w)B
c,iIT+
8~@2IN
)rKF?vS:G
Pmws|G
&J~UH=
ccjXEc
5VI=m4
=M8XkK
:z`S#c
X%!\w:_x7<
C={F)TN
Q8qohM
z~VX*#
u&i~'%
ULM{]0D
[MN OZI
QgX5Vp
*S*+jV
4$g|5db8
C6!-%c5ax
C% @TX
(Ox%dD
{|zE1|
Qc(B}`
tA.gHd
pNu(o~
)7-!Y;
QA53ho
%UzUQ_
3g]V4Z
HEM<}5B,
merjbu
V\P?)l
3wusm[
,_UP;`
ktu-}|
Ms={x;
`Ap- w
1@1m45
AX%9hr
XZQULQs
Z?%#jPUO
-~oO3,Z
*?z)(U
DYEu*7R
wla*:4
t23Q`2
9cB)9i
vW^u'.
n>VU5\$r
buR.fXJo
c`"OM.GI
X^h&fk
tAJ"%+
HeA&rD
krVx>b2
euVN}q_t
918Ug;%l
.07oGiT
;*!=ET*_*1
#=1a^.8HW:DIT
}'[%b>xa
g;\c>`
l#Bx~LK&y#
#mv;xE
4Hd,'-
=p?A'ft
_."/_wA
-@R${*
'*KST6o
#Rvg%>
H&\76v
XQrkMw
F5dN=S
a3%/R5Dr
U9'np`
[\/g}0
9q<5';'}*
lclKs
=zt0;]"\
^@vV%K
Ay>Tw=D2
26B.9vL
=301=?
AJMm']n6
dBS9>*
0/j47-
B=] qv
NOo9X
Iki"|e
{ ; Gl
U*A7}'
[=mMzt
"6FZZ\
p^gjS80:
E20:2~y
!Do`\)o
@Er4ty
5`:c$L
Vt%}i{
4x/yZB.
nEx1")v+
yE]9+
J%F%LPS
y~K(3a
~dPNZz#
9\Mk|g
`H-i:*
RH&.T\1
44BFG
8FpHzB
(\A]c7
<9j-q2
mO8IKi
GD,|2T
kjUc>6
cs[]6B
nwCts&
@7I&XW+
8Og`->
*brz}6X
1O<n6YI
K)2~Q_S
Ne^kdd4
LL['\b!
BJeO=kbXh
(M;5}(
@WZ,*
NASby(
'(foR6"^I'Gv
R3ii,|
e[G;t3
<H&EgQ
kY; [`",kz
c+#BI+(
A\eCW!
o%Og9Q
Mc#(m-
'~;-U3
&YfP(R
e(i&b9
qD}~hw
m2N@I
OWGS9<$
0r3:GHIi
E\.fe-=_+
#c8Mj[
47t}`R
JQ**|@
MDI&5c
05ayuB0
Flv\xq
<dzEvH
Ioyt:4rBh
VXCo*H
8i1!wgG
EC`x/y^
>nB,M'
0ZXuL'z
O="Huz;UC
#o68ip
g qR%rI;
}QXaxT
5YDlau
QcRN>xM
yVkW\F
70RC&C
BoU-RBz/
ew"(N$Q
x'v?kJW
&ggI(hM
h_x+ea
Fh[]bm
<-PFc.B
u?&;M>
[j[h&~
d="8Qb
/ux-ll
Lc6-R
:>J==
n0Y^Xn
~auNK+
RXf-5W
[;S[;'S
Ug/g58=
cMaJaf
*aS~_.Y
t038J+
[;S[;'S
m1(r s6
PO4W$V
VTPiOu2DY
@%R@I)
U62L8l
rv{5;5
C"4t'D
c7J|Xv
EQT?Wv>
f%D6:8w
Te &q<R(2
M)*Zt?
UjQ{P8
S/N31j
<"J*qM
i ZKw'
<[",c]
5\ok2u
.|f^y#
ZUHbfc
W@STFs
CM]0Bu)
g[/4}'p
&). S>
EQT?Wv>
>/:<H#
e-7K2L
=eF0@kh
MnNzh)
X-z;byI
0jrm '%
A)'u3n&~
j(`n@!Z(g
24#b-]
<#+4y?`TmX?
Ut,A##
OiAx9X
XwbCfF
Kb^~d#Y
#['mQDgU
_bVnP\qW
%&jL>!H
|PnOUX
=>,R+ N
uvv|O5
OJzx>_
=>oa~t
|8BuIF
P8hsS
ow'Dsf
5qOh!B
NK_"xc
d}uWSC
Z<P+CjA(W
DaYyo
/-4Bh8
1JMuzQ
L'#^?(
LAV#<k
O/f.5?_
8pB!T>gH
sYD|)Phrv
F1vcu*
cdEBQ%
ftio*8:g
rv<!;DH|Q
*bS@*+
L4*4~*
_l+WKNb
H}tqO.
<C@W,'
xEYV\]&
Y;N7cG_
x?`W5d
w!o[;V8
VPOCFV
@/V?/t
vUGS)2
@6Q@uWK
1w1Lhy
srLcj}
0;8c\L
7ClLc.
woJ02Ql
r!mp46
Jy=9KMW
YFaP{_
?W@"'a
2#rh~w#
`pZ,7=
{77>!>u*<
NMoul
R"y]!l
l9w2fC/
6[+<8
(7[)Z%@
^e7fYs
UL=//7
|JLvgnI
)J{,I`9
xh(J)[fj
k;4Pvr
8E|3KF
#:PrqFE
MaNk\n
&3&\fa
!`?jaB
hppfT
9"^'mZ
f9~e08
]o]G-),
>4/iw;=3eK
)dWkuNa%
yr&B5*
wDgaoI
}';(*ZD
EbP/ow
N2KX3(
/('`.2w2=
h/TC8K%C
?b%p&>
&Y}Ns_
b)kIUl
zyX`3\C
}f*/v]W
,z-%FK
drSeZ$^
hJs^>Y
:FuXOG
A*hjEW7>6
Dm*>r$
iy_pf7
\aV$t%
&0v3@j
)auX)8
MPUI_Z
:6{6(j<G
`AkEo{
!w'KBQ
{zsF>1W
z\{PRG
nFH?lo
g"!jQ2
V/p||K
3)tqv(
]cGb*p
o|&a$p
;$V_4?
'Kh;`d6
sN]D$t
KL:f}W
*f1C`:
[X6kxr
z!&+c<Z]
:d:DXM
EW~k`"
qi$xu3
1rRqXn
X</{"]
~2p5="
YbS4y%
5TBb"c
2hjm..
Fn( 'Y\
^ `Q-.|
kuJZd&
{+y$HXU
%o#<a/
Uaf!:!
e3jR#i\
3Z7}=}
Wm36SG
99z5"}[
sP]>^Q
5{9-nT
70i@e-U
>\pd(T~F
z)\7$<
^!cv2H
tc6U/*
y+,i18C
i=TR|k
`vl$5Bj
rT/m$u
<|HL4S
:a~Y\6q'
W={>'uOI
=? <(j
d##6Bz
@Oer@u
ll>K47
hYY8gs
q4*Kh95
4HvIsac
[kcKgt?
%@bcwc
%@bf$-
c.uqlMz
$0L21I
RXh7YS
L^\N4n
Vz6"|n
\wTQ4d
\1VI7d
+rP &[Q
|Hv4Q
-~8^O'
vCF9Jf
_N+<(_m
wlM+M
wg@A`k
FNKNYx
FNKNYx
FNKNYx
|]$$iU
|]$$iU
|]$$iU
|]$$i
FNKNYx
wg@A`k
FNKNYx
FNKNYx
|]$$iU
|]$$iU
|]$$iU
|]$$i
FNKNYx
FNKNYx
T]4"D{
N0GkQ?
}%AX|51
`CJ#j|
h{^ {Y
q-HZV8
TFMR/.w
{k-H5
DB@'7|@
>rh>jC
{U~:k&U
^@erM?
xU^3f!
Zt[CZx
6)^jxS
5lxsg
wg@afg
n"S]w&
,dpz:,
7q+:o<
6}L\LGB
&ycp6V
mV7!+R
c:3nyX7
mC{erY
(x}wsi
g4%#p'
yQkq=m}D'rY4v
C]_(Go
Ie_/_q3<
2P1`:.
bZ:94q
8PF(Q|
D8Y7xr
i4B7,{3
`CmfZ#
'MdO^T
3"&ij1NR
:!L=N%F
s1i&3F&A
yB*T/J
&cFKe8E
/{o?q4V
+&tg5lhW,
ba7r^\
Q{fF"u
Iq+AR92
|V7-R.
`:qq*G
`-rLab]
x<Pqq%zh
rRCmz'{
N*CG g
qp|$Kxt
{fU>:kt
@dLkB*
;Q*L \#
`^uGPxo
l+)^QZ
ni2@Wh
e/SGOz
T+zpU
5IxR/v
uJ2\\j
.a-\UL`
zyi,un
&?52To
h>aD^5h
FW&I <N
-QBe8=2
$@>57A
R"qN((
.=2H$\
H. ]+*#
(}e*@.
,2ZGS{
gl\Mo2
2VZW=<,
[JOBcG-
Nvkb|1
s/p&t:
AqU@]1i
EL7'AU
mF-x/H
5"A*d
G]8<~;
f,Hnul
a:NbWC
2G4QS~
q$b6?I
4(AC/
KnYO*cL
@6`fO#r
v.'\$7
mbfj(j
WNKo}=
ye#T[5R@
nJ]mg|`p
to"?Ng
)[=RiG
nEFqrG
#IHNKH
g*J/?.
Szvl=$
FL>=L#
7)IK:E
*3l@1\
'`B<XD
}x9UH+#
^<wSg^
YP89ZB
.,k]jyCK
`b,_'h
3WZh6u-
!DS:G-)
\7kQ]A
4wW|0f
$:&wu_a
:xH*p*
GA1}6s
e=4*o,
h@NU"_'0
g=HUE,
3C`H5\
=!%&;&
pk`e`y
9Xn>Bv
Mw0?eF
zfEIvT
L[' HnOwj
g1]"~J
6p9k8r9)
.UlWA0
,j0;O1
;N)@X#
}-p)8W<q
7c1U$o
8z^59Vy
a9$:&,1
OWv:J!
(`,[=
G~`C$b
;JdpA'
LJA[=_Y
${bsnHi
BjA/rzT
f\-&<iDC
,mygou
+Kxin%b
2Ngi6$5
M_NpEG.*
GOyAh1+[
R68ow0
RWy;`
e[:Jf( /
^0rYOO
O~$$y0
^\mCPJ
JXb)/\"
+TSDD#
d7y'[Q|\
rM?[i*!
{;D6%D
7]DyW[
G'1k^
g{yi,W
(lI8{-
<qo?4
UA04-g
Eguyff
0)>S24c
(?v0]A
?1jhaIt
uP^YJ'Y
Q;j#sF.
}?-ed~
Ra't:r
5Mt#k4
t gUR`?{Jh
1zrCvV
ugH{SB
K<~V"'
WWUvYF
'pI3#2:
hHa'g@
Z*aq"Ph
A]-Yk+[
Jri@bI!
\im4xa
W2>KOC
f(L*JB
ak~@4TcR?
a0&H|i[:I=-
2 )$~Jy
&T~Slt
n.:vD\
vW0"snN@%
8qs3e4P
m~lruD/Y
?RItjr
l\U3vH{
?bT16,
rlbR`d
|n6@H\
NYR-rl\[U5<Z
.;\|,<
(ttUu:
!}`#gD@
@(Kx1|
uq##U{
*]oMKW
LW{r@_
>uRtaMW
Cq>Z@|
KJuM4a
Kco=!c
fZQyG6
^1,3whDD
^pi5i7
=7GyR
>iAMfE
oK),\^q
|>yU,m
BC?VJt
c,/Tk]{
_"7eN+
I>o^\V
Ckm)Og
bod9o4
1Tg>:C
+bJq|6k
hnwS[y
U`?31$
dDSNw01
YcmpwpG
x}CBb)
V^?6)ZH
25x.i4
77 )?!D
DWrn4u
qI\-+?
}Hmf'M
9G<D"i
i?X/Jj
a`yRw%mj[i
)IW64
~)pZ!HF
Y[}.J7
mtPe<?
xtIz(N
>YiXB)(
NA@eDL
IO@ea[
<<NYnd
lSkf6)IxL
\1akJ>
in}z5X
s'<oX(
Ycgk;GKNb
eV'E7I
ketaIOc(o
LaN_#7o
i5V.{[*P
Me0)Ox=
?'tcWT
w`ho0hh
|:9Z``s
7_ki7r
yu539w
h`h$}/i
{j>Xi,
RyOd|_@
]S\f:
/TMG*Y&
&l=!@Tps
P(dYt<
8)_v0)F
&rYOVs
t=Q'5*
VSs C><
"V6c:i
GwQ29E
.ZS+Pf
+K7VxM
R~CPN{
M;v'68
xf}dF^
pED=2
qr_BXu
/*^G#&8
`ET"Yr
Pyb>=g
d=ey@O
cR%@'tA
\A}5$/
F5s4/3
An`E3%
kKr0qH9Mrzg
7Gt|0 >xLlK
M<X4DE
E j-q
U)(L2Z
{`rVV\
Zm&L?'o=i
dNQA~Q
BXA,08w
~3pQ0b
fZRd`H
)|1%J6
v~)<UJ
a5KN4#
6.*NCzs
V/eU+:
'!0=fI
RqBgYg
p\]R'+G;c
Gd{4:[
)G_ouY
'M_Q7K\
})k$Rl
b{8Lr~C
uy-0R^
o1cTzE
"%!$TX
)9URCE
\9uFk2
5fqynS-
83ze%7
NCZ1J&
D9tl!
ituc`|A
#yjHSe7
]<FZ>s
ZB SAG
>M:lt_
TMI0hp
5y06^bHVZ1
r9Yl"axF
2l;^Y?E
SIC,^?
P8{`5'P
/54kR@
$u&S4r
1?fJ?KD
xu@J5=
noPaZ/
!iZ 4f
h_^sV+
%*EFDd.'u
 "(Hatj~
7noMuZ
zvI;WJi
PU}E&b]
kc"(5j
-U{tbM$
$]kG@
jjdG,?
elyn_b
u#XN:<5
=NSE:J_S
yc)>~Dl
5!fJ#\
55*eF$a
cRP0YC
\LEl6d
k*%Lq
VZ;8?88
+@.\QP
-%?\#Y
q%/[Aj?.=.
'1d2U<c~
t-B+(j
}OKhoz
p`IF0
{0p*Q
,0h0M)
MPs-Nz
AMzPcI
xxmK.QH
sLD0d/
|#Ma;w
m]6Q\q
z^;VKz
-%4GIn
m JH!L]
\qm*[}
uhi!*x
g] iGO:
Fxsq-n
oP0)fH
xPOD;=
kt6ilY
jY\[W`
M@f<1-k5
%}C?&d
6.}pH]
:4{.J$:
b8_3:Q
l1N8F9V;
P6(|M{
/;_'v
@[;{j3
/{n(`{0b
Q9uJ2A
;qH5OCf{x
ms/b>s
cj2;KT
ObF=9V
IeGzke&
r'iH|K
pXTVU#
a^:=-#
%*r=-q
/] ?)
-^xD_5
',}?fY
-Aoht8}
Q6%N[a
kuW?|e
@Q8<'x,
gpxz$
sR@/xoe
L6?2(VW
f@R@\ !
L%{f2R#[
j3r~JY6
QO;9?.k
OP8%KR_(;
$.&27$A0Y4
v@pcL%
8m~^PA
X%)~f^
!+RS3u
%lak2Gk=
wyznsLH
3X9]US
^`x)[;
.Z (6lZ
u[o(*Z
qF|z@~
+B8^hp
tb5xz~
0!Ml`%v
6@n7:7gA0
,,TLbu
v506+%l
G2yg&Kl
1N<rf>
){5zl`r
y(p2zz
$\s#WZ
L@|+QTE
Wo5\$EN.
ftnhbOw
UD6[]A
~qk$?cL
pk%eG%
V\<K{Gx
}xH'TT
Vmttf:s#
#rX[:zQHKkEl
<^!=[R9
`W=8$e
vK<wi2q
\qqngynz
.w]RF4
5l3@C2
(]~Q=f
~a.@j+
l6|@y\
?W.]B(Kh
M5 Ejz
*e$3>8gp
MWaB@b}
8]&XQt
wgj>;Hy
Q!yR0,
VT|7FJ;
@N]Y6'
F2j`pV
hhW[O3
?^|v.k
59UDX1
opU;rU
+14'bO
YHoLA6
8/I#vP`
$QEZgl
&`$]O
4oPX!{
hEtn\"
ZE(["&
Q(AI(q5u
kJ>ih+#f
-oWqGaN"
]B *o
\+fzW:7K
c/:8Na
.$^uK^
WFNI~l
([-%*2
l6?/f$
v4.0.30319
#Strings
'$$method0x6000003-1'
<>c__DisplayClass2_0
<>9__4_0
>b__4_0
IEnumerable`1
IOrderedEnumerable`1
Expression`1
Action`1
List`1
'__StaticArrayInitTypeSize=544272
Func`2
get_UTF8
<Module>
<PrivateImplementationDetails>
Lambda
mscorlib
System.Collections.Generic
mysteriousSeed
GetMethod
set_Mode
PaddingMode
CipherMode
Invoke
Enumerable
IDisposable
NextDouble
RuntimeFieldHandle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
Compile
Console
WriteLine
ValueType
System.Core
MethodBase
Dispose
Create
DebuggerBrowsableState
EmbeddedAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
TargetFrameworkAttribute
RefSafetyRulesAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
Remove
set_Padding
OrderByDescending
Encoding
System.Runtime.Versioning
FromBase64String
GetString
TransformFinalBlock
Marshal
kernel32.dll
System
SymmetricAlgorithm
Random
ICryptoTransform
Version
MethodCallExpression
MemberExpression
ParameterExpression
ConstantExpression
System.Reflection
Exception
MethodInfo
PropertyInfo
System.Linq
Parameter
GetEnumerator
.cctor
CreateDecryptor
UIntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
System.Linq.Expressions
RuntimeHelpers
GetProcAddress
AttributeTargets
Concat
Format
Object
VirtualProtect
op_Explicit
FirstOrDefault
Constant
get_Current
Convert
ToList
MoveNext
System.Text
InitializeArray
ToArray
set_Key
System.Security.Cryptography
Assembly
op_Equality
GetProperty
$"p+06@
AllowMultiple
Inherited
WrapNonExceptionThrows
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
{0}: {1}
hhFlbMs7sErzFkS1Pgis5Q==
7a6On1GHux5JOk0Wn5Lcuw==
JumpOverTheMoon
lWp8+FneMSwQdH43lrDPhQ==
wuI6N14ruMzQocHOEJx/fA==
EfxVL0z7ifLCXk4dQpqWGQ==
z9QViG5ujcRyXEpvVq3/5hRv7QW5JQwq8CDAENtf48c=
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
FileDescription
FileVersion
8.9.6.1
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
8.9.6.1
Comments
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904b0
CompanyName
FileDescription
FileVersion
8.9.6.1
InternalName
LegalCopyright
2023
OriginalFilename
ProductName
ProductVersion
8.9.6.1
Comments
Antivirus Signature
Bkav W32.AIDetectMalware.64
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Trojan.GenericKD.69038368
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005aa8281 )
BitDefender Trojan.GenericKD.69038230
K7GW Trojan ( 005aa8281 )
Cybereason malicious.9bb17e
BitDefenderTheta Clean
VirIT Trojan.Win64.MSIL_Heur.A
Cyren W64/Agent.CSJB-7922
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AJMZ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Inject.gen
Alibaba Trojan:MSIL/Inject.abefe00d
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.69038230
Rising Malware.Obfus/MSIL@AI.83 (RDM.MSIL2:GuzXJlk/2YgVeVxJbuUY6A)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.isvin
Baidu Clean
Zillya Clean
TrendMicro TROJ_FRS.0NA103HV23
McAfee-GW-Edition BehavesLike.Win64.Generic.hc
Trapmine Clean
FireEye Generic.mg.60301a5126ba6d2e
Emsisoft Trojan.GenericKD.69038230 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.isvin
MAX malware (ai score=83)
Antiy-AVL Clean
Microsoft Trojan:Win32/Generic
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D41D7120
ViRobot Clean
ZoneAlarm HEUR:Trojan.MSIL.Inject.gen
GData Trojan.GenericKD.69038230
Google Detected
AhnLab-V3 Trojan/Win.MalwareX-gen.C5479139
Acronis Clean
McAfee Artemis!60301A5126BA
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Malware.AI.3786715805
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103HV23
Tencent Msil.Trojan.Inject.Lflw
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet MSIL/Kryptik.CUK!tr
AVG Win64:MalwareX-gen [Trj]
Avast Win64:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.