Static | ZeroBOX

PE Compile Time

2023-09-11 17:38:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x05\x1feE0JL3 0x00002000 0x0004ec80 0x0004ee00 7.99946522301
.text 0x00052000 0x0000a2a0 0x0000a400 4.56446402033
.rsrc 0x0005e000 0x00001220 0x00001400 5.038679458
.reloc 0x00060000 0x0000000c 0x00000200 0.0980041756627
0x00062000 0x00000010 0x00000200 0.142635768149

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005e130 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0005e598 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005e5ac 0x000003a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005e94c 0x000008d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x462000 _CorExeMain

!This program cannot be run in DOS mode.
eE0JL3
`.rsrc
@.reloc
EA:wk+
`$%Q?-
x[nRgJ
dR$pRv
yY ''.
6MA%h:
OdI).J
g}'n]'kD
]=)&QoQpA
2Z8ne@
~OQXog
kkj pu
2T):r>
vp>l,Dv
"44Tw?
b?Um?w
%MA7D=
g^YD3I
K4s]To
mEp6KUL
ijvVj9Z`
<_KvFk
@_ySH%
I|-6h"
Mdm,1G7
Or=Z9s
IZ|\bm-
|,>$rQ`
VBm5u^
ZR5E3^
c03AuH
)41I"?
r<F,vV
E>`8ze
fu 2Fe
~I%$'(
XishI!f
bSBd[6
{w*f:g
WriXt:
V1 WGF
<mx4p#
#O&7q
Ve39NT
h_$DNY1
F~E)B4C
0.:"_<^
hE2B}R
YqoQp2
^e?`zk
j}Ab&{0
oH3ex=X
[MGdr!R
`6iJ@T
6&NitBaH't
;no\5{
n{W0$#
V0/[cs
5&-_'QA
K3ow8h
XfRf!~
%>u)))
>%KCzm`
,E}4\.os
A3);e\
2?xJyI
$#7&2,W
L_t"t~
L^a),W
Cw]Ql,
qIHig|@
9e%agx
M8wp8d
Ec}Wx
*A"DWe\?
jJTj;H
o39XEs
TgfNn
\E)THu
=-Q<sYQ&`
$4TAnS
fOy=pv|W5r
|JLr1+
.,5NqJ
73#IK
C8/W`N
6BvMIg
mA9U"6
oyH{)F
,jtj$jO;
>(0`@wZ
QIX7`K
Um7aus
osV69!
FCInvUb
<|0/v<
#h333z
2]j`m,
%gs;`P
v?/%"K
r8,/ l
1sN;~r
V`8ug;
U?YZeE
=F?].
O@j@o#
yjAXNu
f$Df}9R
T-5@o(
*(o[\f
aBXJ<9Q
}q"G(O
|::W&bB
6sln,&
M\iEgj
#z)v4 G
d2||9x
rgnY->*
3Mjo8u
x&10pv
z,wn3%
s*!R6i9
mI~k0/> ~5
hA*Wi
$j/r#$?
2(Cn\T
xOdy`H
"r8NA*
t:+]sj
y8)o+F
U#p5^EZ
h-tKO&jH{"
sBa#`z
?e+v~;R
c'.WCm
r!>.} }1
#=H<n4
T42r;
QHR<tv<
@T~Q9J)
3f>:nh
Q1:+n$0
T\;q\&
cA;6rqYx5T
OvELP
&1;)D
yp(ro!
kpw0ss
_FYVo
6`+XJ"p
~OlmT#
,oy@4|.
=]%T+r-<q
Xpom(l
lmbr10v
i3^e3}
+X7y]=
>|dx&{<
8*vCL=N
3H['r7NQ}L
uRho?yz3x
i9EQ5s
:jyNq.
HD+B~IQ
V&?'rM
=Er`2g
Kvx^M9>K
=fFcB
2M('GZY
*"O.MY@B
hG=0L6L;*g
U~#CBl1
jo344;u
mnS0Czj%
6{J`#5
zkVjuL
3h?y:4RB
4qt=<)
X5@rw[(
fDi1_i
W.h:yr
7=B5I:
,&XMs6
CH%3mT
ccEy+,
:*L^r5
@k#(}rp
7.Sf7vs'oH
iG5r8
(u:!#
g,jG>*
~\X{u@
(7C~3C-
_qK)t8;
25@5fvf
JL1ek+
cV?DUP
+jQnQ.
-crUCvf
Y)*yM'
KGV^o?}3
"9OXMO
@` u*2L
uw%r>V
pLTh`"
0zx`~n
0OIqhI
ixFL55
Uo"\l]2"
(H 9<am
V,N(-H
Tly=j$l
.,./2Q
o>uY^C/
v5Q`QF
H /e0t
ZQ<v+-
+769VR3
602:cY
Tw#IKG*
 cb3[
N|VNA<
yOk#/Y
*b:'1H
[N7lLR
d'<,sC
Io::dw
pQP9-D
X]VX-%g
r|@n/Q
&k"XrV
qnm>Imo
2?Ytfi
T?_SBV
,<w?Mr2`Et
W9~gU,MdC
g[}}"E
n>\E0d
EMcQaa
kZYV1:
kl|a3BfR-]@
zH?$S/
|e["QJ
bZ;X6%0
$YI {8l
t#2T=&
#ARCq6
V@Sg7}
V5XPWq
5$'h;
;oy)a
Dp4pfXg
4IUcM{
vY-|:EL\
h5p]HC
,(RZi
!U7EP*
7G/<FvA
0Re]b,
JV#0fi?
[o=@!&
cnNbv$
(s'h%L
+O!kYzNN/b4
O/.kMk1c
Yz{(!>k<
^5[5&X9
i3G1$mK"1;
b2"fu{`
jmU>@
WFOd!0
.J&eqI
Mon$qS
4={BS?
{h7-VW\
SeV`Ju
W8T`tl
iyGarpw_
r=c~BH
CN7W-G
3N!Q>&(e>
UG"C!*o\5
1"qp$c
89/skV
b21`''
,KlLK6
Noq,D*
BBF"uH
v>-eMk
/Pm`#8
Gh-fH'z
bKfJ"
u5!~E_I
)0vq~})
`6'p.f
cFs7y:
WDC_<N
j2m45b
k1.0T"d
,_zGY
[$MluE
bI+r;Q
2HQ+ge
8s+T9<
qK;V{fyl
=-,/6+
,8-;]:Z
nYNW]3.
:R7%:$
rD Dbqql
kTT`#x
>{m9LM
0Bb1,N
Sv?{,b>
=VYKE
[Kpkvd
|CJd}y?
rr(]!c
,9c/hS
'sd.*u
oEjQZ'{
d[f;Zwh9
P?flV3
!EI"gO2
8Si/`0
rj)XX9q
AR&&[u
:BYs'z
Jthhp{:hb_
](T$*
FB_-$|l!
xE#^w"
kHFJYu
v$'}L)
_}`!sM
[@)jM(
^$<G21b0
8s0~h6R+Qx
Qml0,r
;~%{se\
1zgWLZ
f`C _{!1y
7qGX*
O5P_h2%
`V-vx~
^"]3E[
S|%kM.
e2F%_J
tNms*0Z"p
(P5JX%
$ly]'g
u/B-Y|B0$V
E{hYO@Z
po@M"3/Y
\@`|uR
SVM'9MF
g{/9?(!
*o}IoJya
M?4+E|"&
Z."Sj
;^P\wd
{qV(zD
5`O`RL.
Y^!/pr
Qj5+eI
"$^pIuT4
XZJ=-|S
RU)jz2
|ry-ciWXv
uyo<Wp
8BprW{
h?U)R;
zH-VUlEE
;et00z
94+x;O&K{
4z?%hw
P4uH_
M5GE.0tN
/RZ,)*
Z6Ke;=
s\j\U>R
NpP-9_
^x?_Y-!u
-`c9\m
reN&V*
e?8}[H
5d>#Zg:
=IBx"j
ZVj{k"
G+cfOJ
=Kn7!32
odu2]i7Qgwc
PHdL>6
mb_"^mFA
@=V)SI
r6|ECu
6f=Yq3
(=CIsb
[hD%QD
)n8ym;
0'hpUGE
J\1"Qx
T7S*WO
*1qry?
*? Q,0<.y,m
]}YdyD
/}xnJ<
b.j)\{
9?=#bD
u\fFF0
:)d0`Wdx
a{&0n
gchC7**
jb2:~m
PYS8jd
>I OU>
*fA/~A
]yzP?m
,&;JIux
'|W$J{
:=.C6g
UutL]Aaz}
hc\>5D
!%*z?N"Y*&$
\$['Jc=@
bC05nX
*P]<%6
m8m'c^
s`pl^?t
Ls9aZ9
5r5s_]Sk
sg%a2
7KT'7NQ
4B1rZ@x
M=K@'42
6?<S-@[
xt-~B,
Bwr}Tv
?wa82u
:]>Q{s"
`-8A/ylLC
+lox_f\C=
Eh#~)`
y(yapK
[b$G7@
1OzbL;j
C_]8=e
o[Q~DSA
a6}C?
.b_Y,G
x[WsYrb
=Q*^G;
*Oy;=2
yr0i!%
+t(iH(9
x8LkcY'
YaxOw;j
;jltn
5_,E4:
$>%'fG
f]IBBU
qARefe!+3d
5_*kDo
S?2,U3qL
R<L"\'
#%T42H
UP,@fP
A~%~b
@X`)xpvF\J}
GGnCFW
xRutT2
syE!Y/*
P6&uv{
Q_R+>3
Rq0d'+=
@dOx
`&*S6)n
R[:9P<
h^p.R?eM;
TRAL<f9
i~?-hr{
v-aIU
]YUcdV4
J{-wWwVxBYM
&rJq)^
;k|F!_
:S4J|y
aan|XF
+GT"&/9
CzQ%Vk
(s1N"5
ud+zz$
0OG'DR
hs:Cs[
T&0"sv
d]&?eI,(
Mpjq:Tq
}f^2s6
LgP{U/T
g089nCv
uh(^.[
:3R^(p
/'ds:2^
.IQ{D8
zT>#+I
'T,0F=
GgV2}7
'KsH$Z
@}=_+7
%Z>xEuJ
GSu>5N
o([>CJ
6#Us]
(k0|?M
~+vW%7
>`IM:cw
w51Aeq
Qs4I<G
"=W*kd\,
g@'Yze
Tll=w#j
[_pQL*<
mzwt^A
J2iipq
hk)ZClww
oXdsk#
v^/}_VL
C/E(F:
tMmEh.>
hG}cp\
Q0g.wdA
IS\y%W
|]Bdxt
;=d5cy
z-(Zg5)
:>f%9U
_jJkKGK.@
o-MC0Y
Ubpq"C
lbIR/`D
x MtXB
n}x\sKF
c.9<s4o
^(${`3M
<@*@rOL
mo}m*g
/2'<og
n='!WI
l\>o~q
#_]`SM8
U>|:ypoB
bb\O8{
qae[O!
6`C<mz
F`ha|:
GB|r}0)
.w=Ac%
A?g$[H
.,ul-9Iv
dLk,+q
bUOu4X
Gb;V3#JX|q\
%PZpBy
Nxz5bDS0z
t!V^%f
"Y5))I
(\4/Q#
s`9fq
-vtK=5#
)~~4_
_E,h?9`
LU(Z 2
Z eFtIa8_
c1&Z ad
Z =}>?a8y
RZ Thp
I7ecZ
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
server1.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
GCHandle
System.Runtime.InteropServices
ResolveEventArgs
System
.cctor
VirtualProtect
kernel32.dll
RuntimeFieldHandle
Module
Encoding
System.Text
AssemblyName
Stream
System.IO
MemoryStream
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ValueType
Object
ConfusedByAttribute
Attribute
server1
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
GuidAttribute
AssemblyProductAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
CompilationRelaxationsAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
STAThreadAttribute
server.Resources.resources
UInt32
GCHandleType
get_Target
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
ResolveMethod
GetParameters
ParameterInfo
ResolveSignature
GetTypes
Invoke
LoadModule
Environment
String
IntPtr
op_Explicit
RuntimeHelpers
InitializeArray
GetExecutingAssembly
get_ManifestModule
get_UTF8
get_Name
get_FullName
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
ReadByte
GetTypeFromHandle
GetMethod
Concat
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
GetElementType
CreateInstance
GetString
Intern
op_Equality
ConfuserEx v1.0.0
Important File
!Copyright
2023 Important File
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
2.7.9.9
$cc7fad03-816e-432c-9b92-001f2d358379
WrapNonExceptionThrows
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
@{?@{?
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Important File
CompanyName
Important File
FileDescription
Important File
FileVersion
2.7.9.9
InternalName
server1.exe
LegalCopyright
Copyright
2023 Important File
LegalTrademarks
Important File
OriginalFilename
server1.exe
ProductName
Important File
ProductVersion
2.7.9.9
Assembly Version
5.4.8.8
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.MSILHeracles.107662
ClamAV Clean
FireEye Generic.mg.69a09092311de18b
CAT-QuickHeal Clean
ALYac Gen:Variant.MSILHeracles.107662
Malwarebytes Trojan.Crypt.MSIL.Generic
VIPRE Gen:Variant.MSILHeracles.107662
Sangfor Clean
K7AntiVirus Trojan ( 004b957f1 )
BitDefender Gen:Variant.MSILHeracles.107662
K7GW Trojan ( 004b957f1 )
CrowdStrike win/malicious_confidence_70% (D)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 multiple detections
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Sophos Generic ML PUA (PUA)
F-Secure Heuristic.HEUR/AGEN.1312344
DrWeb Clean
Zillya Clean
TrendMicro Trojan.Win32.Boilod.SM.hp
McAfee-GW-Edition Clean
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.107662 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.MSILHeracles.107662
Jiangmin Clean
Webroot Trojan.Dropper.Gen
Avira HEUR/AGEN.1312344
MAX malware (ai score=84)
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.03012681
Xcitium Clean
Arcabit Trojan.MSILHeracles.D1A48E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Clean
Google Detected
AhnLab-V3 Trojan/Win.AgentTesla.C5378063
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Trojan.Win32.Boilod.SM.hp
Rising Malware.Obfus/MSIL@AI.96 (RDM.MSIL2:Z4ozyyMeHsseb9bPD7f4GA)
Yandex Clean
Ikarus Trojan.MSIL.Confuser
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenericKD.64199134!tr
BitDefenderTheta Gen:NN.ZemsilF.36662.wu0@amCY3Df
AVG Clean
Avast Clean
No IRMA results available.