Static | ZeroBOX

PE Compile Time

2011-06-20 19:25:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00047ffc 0x00048000 7.86145749983
.rsrc 0x0004a000 0x00000298 0x00000400 2.12372484645
.reloc 0x0004c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0004a058 0x0000023c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v2.0.50727
#Strings
Nullable`1
IEnumerable`1
IEnumerator`1
List`1
ReadInt32
KeyValuePair`2
Dictionary`2
get_UTF8
System.IO
mscorlib
System.Collections.Generic
DefineField
GetField
Append
DefineMethod
ResolveMethod
SetAddOnMethod
SetRemoveOnMethod
SetGetMethod
SetSetMethod
CreateInstance
OpCode
CompressionMode
Invoke
IDisposable
Double
RuntimeTypeHandle
GetTypeFromHandle
Single
DefineDynamicModule
get_ManifestModule
get_Name
AssemblyName
EndScope
BeginScope
MakeGenericType
DefineType
CreateType
ResolveType
GetType
MakeArrayType
MethodBase
Dispose
CreateDelegate
MulticastDelegate
STAThreadAttribute
CompilerGeneratedAttribute
DebuggableAttribute
DataMemberAttribute
EnumMemberAttribute
CompilationRelaxationsAttribute
DataContractAttribute
RuntimeCompatibilityAttribute
get_Value
get_HasValue
GetValue
SetValue
Encoding
Ceiling
ToString
GetString
Substring
get_Length
BeginCatchBlock
EndExceptionBlock
BeginExceptionBlock
BeginExceptFilterBlock
BeginFaultBlock
BeginFinallyBlock
DeclareLocal
DefineLabel
MarkLabel
CFBS.dll
System.Xml
GetManifestResourceStream
get_BaseStream
GZipStream
MemoryStream
get_Item
set_Item
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Globalization
System.Runtime.Serialization
System.Reflection
get_Position
NotImplementedException
ThrowException
FieldInfo
MethodInfo
MemberInfo
ConstructorInfo
GetMember
CreateBinaryReader
XmlDictionaryReader
FieldBuilder
MethodBuilder
ModuleBuilder
TypeBuilder
StringBuilder
LocalBuilder
ConstructorBuilder
EventBuilder
AssemblyBuilder
PropertyBuilder
Binder
ParameterModifier
ToUpper
CreateBinaryWriter
XmlDictionaryWriter
DataContractSerializer
XmlObjectSerializer
DefineTypeInitializer
IEnumerator
GetEnumerator
GetILGenerator
.cctor
DefineConstructor
GetConstructor
XmlDictionaryReaderQuotas
System.Diagnostics
GetFields
System.Runtime.CompilerServices
OpCodes
DebuggingModes
NumberStyles
MemberTypes
FieldAttributes
MethodAttributes
TypeAttributes
MethodImplAttributes
EventAttributes
PropertyAttributes
ReadBytes
BindingFlags
SetImplementationFlags
System.Collections
CallingConventions
get_Chars
AssemblyBuilderAccess
Concat
ReadObject
WriteObject
System.Reflection.Emit
get_Current
DefineEvent
get_Count
Convert
___codefort
MoveNext
System.Text
get_Max
ToArray
get_Key
ContainsKey
DefineDynamicAssembly
GetExecutingAssembly
op_Equality
DefineProperty
WrapNonExceptionThrows
Namespace
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
Namespace
IsReference
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
EmitDefaultValue
?~|?"~
4u7NCk
{0_92vS:
9}Yp_:uh
ok`eY>N
X_.u)<
Xpx)-t
gxi+Fq
M\V@#T
,l^mqR
U:D(T{L
5Klysy
k,/N}$
SH-%!S0
ZB.aG=
8F3!ie^^
0Zxc/[/
wu\|%}
0<WYLs
Qaj1.v
IsC6@z
(3IViA
!(axM
.hZ)#
DxUV+O
GjB?]L
)tym,":
go0z>m
;I;p+W
Ym:rhq
a7)C?1
mezr5BR
*D"cM(R
}oh-yV:d7
}f.%/6
"\}9G)tCX
:xP_jz
Ir/;UVXv
jyGwDM
pqYg}e8-p*
#& t&^T
x$kHCZ
kk;-t{J
],dO;z
*xL5&1
b_/esR
d);Nyh
@jJn{cc
FjRl1-?Z
x]"f{0
./be*U0
`}E\, 6
6wK8QZ
Tl)sA:
H+@YUF
Qs0<+)
sj5y5b
V89~:M
oRXf<-
?wX-1d
HlP%F11
/MVCa
Np&3=7
Ge?gu\
+Gl#d`
vD+kBL
yVHg"8vW
>LQN(K
e[U_f#
D52'a9~
}6Oz$T
L 'pG^!
9N-7KC/5
Jxlo'k7&
d#>@X3
Jj:G{rF
kOe#!_|K
mct0VX}n
lvsXR+
fqf4~J"
;PzE?
\VNj;p
Df!?"pJ
^gXy(:
yKFuJfFF3*^
SfXQML
[&yl5c
'b$M>q%
8JCQ6?o
GaT4~&e
aYqYY%
v78`.n
F*3Im#'
Nv|cat
nwQVY^
A~lj+e
<-T_}0+
& |=?XM#
k.9Nhj
(iCD<ew
:)9YfS/^
aW#||R0
jw0g;e
'N+hn
.fB1'c
u4at9
"bz;`H
m"$?pb
?,UfLq
tD}Zjz
I{ZIWh
`j(65l
$%N/-\
0_+<gh<K
BHY'[~(
;WiK5L%'^^
O5rp+F$
Z,i51ci~
y*%BMd
2FeAs-
LSYwL^
a@)me4
'^J"tal
E C+>}j
6})*|Quwi
~G/)hP
)S$%IP
u4$:{_i
zpw5~t
YPj5 LL'c
jv]s0pqA
V%Dl10
)ch\p|
^]oL#k
^h~u7ArM
!{A^v^s4
\u|yD1
`^I^)G`
u@zv60O
oYlR.yc
HJp.>\
\0P];]*
8]7A&(
Mci-~m
I(t}9Y
cQUz(j
e=4%X>tZ
W3FD37
{_J5{
TW*rO&
<3<xF<
x-06@zB
TLE2ww!dMe
'c)2VI
3tw^pvo
F@_Zy>
?.O00/K!
m*UR^^p
6RL}xd<g
Y&'`%p
>qsxo
^`'@jb
Z~iXPb
.Yc_ki
iT{y5G
:p0Sy<O
b8:v(:b
#'2E8^
Au$@"E
!_aT%Q[
g[$Ke(
p^#Q&
74`|Or
F.E6Clo
.-SVi\
HTT WNb
f J}_+=p?
258?l}
4'?.11
~/.~/F
S0E$6R
YiV7X@
3{N[I{TQ:
qyXmWz
GyA8eL5
XO0bJ
%wH$'>62
eem;x?
N9;q7KM5\
?xupD/
B9z{vjm
&aX:dG
7"VB?e
8AiXHr
JzND-)K
_JFJG2
~yUJ@2Z
;$'e=|
9BdcOHg7
-l\O5h#"
CEjk/TW
h!N*xZ6
H,\x<2
;r>?SMUM
6:<6Sw
Y!)m8iH
ZvrGq4
qJ0w6)
Dp|Hl*`
l'p/Mo|
NS<c]@7
x!)h&;
(<J w'L
qtq]L,
WCz9&]
):]j)l
\~C#Zo
,RzXG"
,K06x;[!
yyYp*3cy}X&
xz VUr
C!"8Mt
h3(?Dz
}T.`R=rw
:}:t:V:(
?(uO f
.164Z`
-yRHkKO
'!4(+\
w {tHw.}]
iu_T[K
Ug9snh
:e|3$(R
2>\@dh
9BaQHtJ
#8DU1uK
9UDuS-
^ch|7z
{$%XXS
ff&I$YL
g5b#&P
{[mn =.
{*zK!
S"gcL7l
~T;^V*]
;N/~*K
NcC&FW
jDqHf5
~xvc##~
u]2J<4z
~#}l 3dQ
HCx+3H
&dj4Kc
<]Q(~Q8
<V- aX
kXxM+ E%q7
_WF~,N
e<BepT*
-Hn_Q_
$RPHwc
i! XhS
lQk\t]
/&&-IG
)}E1oPP~
adomAmv_?2O
ee@wY#
<v'`$}p7
T;B+wy$E
+_Lx=1
)?~2,
n!q?vIS
!aiZfWe
6:\Q8H9
[#x;)G
s6FdQ,QB
\qWt)B
K(1Ael
;RUy`_
};J 0_
K-X$l
mqlZj)
_TgyDKnK{
L8t+n|
{.kE#4
2[@o);
xc2zV)
kosC#f
H\]_oxk
Vf'!BT
70~=5C
%1W<qf:
|*@NpE
|5EFU
b-@Dt
qfEKqt
R2[C=Wq
]l'$8*
(aW8?L
[J~~`Ck
X,nk<tM8:VHY
G)Ze4dN
&J0jMH
~l:Hy3
Uhv,B=C
i'A4@7w#
rgu=eT%
%@0_Y_
(5Ct\G
14%Kz\]
X#+Jq7
Vt,M4@
e?5TZz
Sbj<5^.x
a2IrB\/
;hj8YW+
D':n'Km
%Or~"%f
i}*}D~
`7(mgf]
6|hMAy(
9*Q{&O]1
{&%;%p
V.p-m-
3nO)4}J
CARr{Q
<erWri
Q4.^V0
xA+zH
7O#{E?
;7ym$a
&0H_{l
{mMkj7
3"o7pP
g(rw,V
\Ah+Xp
Q\4<L^
gHUbazVoo
eWmgf,
ZR#0GetO]'
@MF1VF
qz01J3
=(P}y@
;0sf6-*{
1QRcg;
)~PH{1
+B&$XY
`/?7ZS
HTe&9:
4m 86$
O96Gw<
$,@-o1
LcDn[e
_$Joz`M
8hga\u
-}Ria=
sw)'EQ
uT&K=.
bK'+a=
Cg\N.v
mi(pvC
.\J]03
LVY|s]
$l6<L.
XQ #.Gy
m$#K~Y
YA?T{i[
fJQ:Ok
\A4O[3
!_}&uw
#K(&bA
t/m\c2
W~6F(
>Tfsl6
v^zY>d8W
^o_%M(
rlVfdE
vYA\hHb
YZ[oQ&Z
W[byV]
||O\_&D2_e]
,}+-DM(M
x4OR3#
|UR;qI
`F]78
q.7`o*
72%pr@C
zwZ<Vk/
k7s[S]s
.t^nz6%
5+g(2$p$tT
{maGT)g
W4S!+&]
#FGHN~
YlTuzb5>
h/!=BN?
T`R"bz
YxuC?Xs
8>zLLE
N%ZGp(v
)e3uCk
#i]i e
MapNX`
\S5R[,
{)^LFV=^
=.o>-v
/`H)/y
8?c4:r
X\G>j^
g24wMS
Gaj`$8\
jw7gmu
xqpdUYI
OESW7i
IrBrCa
q1ovR$h
W$,o.p
\h+[+J
G'O{|G
~O,K;d
l?M1g-
i7Vln[C
X_JOl@
8V[yW}
x-jygeX1
^D=[FQUT
T3=c`C
ECgDFux
SC5 ~8
XEajd4
kT<:h-
R<<*e)
_CorExeMain
mscoree.dll
https://lftgrm.com/lftmail/main.cgi?action=downloadxml&xem=eA3RyfZRAkv8JOsA1k6LLAGP3V03Fnt%2bq%2f%2bnHWBRx%2bIP%2bIetsSYSC5VIZRHcE%2b0qPLltON%2bV4J5%2fs%2fsHW8kdeiyQ61uT8NsS%2bQL1PXOaAZypyfLZdjqbIW4U4rYlRR9R%2bYUS8ph1nYqAaAQGz0KQj9LjeGUIks1lvWNYZ2I5FCs%3d&xjb=408CE1275B559EAFD5649D1E43D39754&xep=XWp716l%2bEcAc%2bsGWQGdnHs81rurVO8HMwyQzwOJJCT4a1GS0nmQmb8nlJ0vXi0dllnZgMDen1%2b2JU8qN5eFvvjHAJaXAoOGc8s7FYj6lEKEpTkxPxE%2fErWGO%2bVKxH8zFIrM0a6Ncmh6g%2f5RpYwp2P9jit4TmMZmrI5Uz30fa0Xk%3d&xer=UoDVj%2BefK1ZpDi5MfaDSjZ8ftSpgL41cIcG5aGBLzOCoqglYpE7GO%2FQuUkCLzR8Khi3wQOLJ0qyp%0AMqofTQi4Oi9K9NoaoMCfTDFPLF9CB0uC5Oy39hNRCZKz4%2FCpi9Yw0e0M4r1OPlB18K728zSEUAfZ%0AYdAu0Gx0d2yLo0gQIhs%3D%0A|00000678
PWhov}
#a348ga
Label_
BootstrapDynImpl
Error.
Error in emit
#aerg49
Couldn't load assembly
Couldn't load type
.cctor
#d98e4
s^]ZS`
}PPKLKM^O{FQvROS
zMMPMVQZRVK
|PJS[Q
KSP^[^LLZR]SF
|PJS[Q
KSP^[KFOZ
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
CFBS.dll
LegalCopyright
OriginalFilename
CFBS.dll
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.m7T4
tehtris Generic.Malware
MicroWorld-eScan IL:Trojan.MSILMamut.5427
ClamAV Win.Trojan.Agent-1068662
FireEye Generic.mg.f1851b8e5b0f4eb6
CAT-QuickHeal Clean
McAfee GenericRXAH-JB!F1851B8E5B0F
Malwarebytes Clean
VIPRE IL:Trojan.MSILMamut.5427
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005190461 )
BitDefender IL:Trojan.MSILMamut.5427
K7GW Trojan ( 005190461 )
Cybereason malicious.9daefe
BitDefenderTheta Gen:NN.ZemsilF.36662.sm1@aeBfWzc
VirIT Trojan.Win32.Generic.QVI
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.LEM
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Clean
NANO-Antivirus Trojan.Win32.Barys.cwtoru
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:KmXi8vyq2oo5Gkn1kmg1rw)
TACHYON Clean
Sophos Mal/Generic-S
Baidu Clean
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft IL:Trojan.MSILMamut.5427 (B)
Ikarus Trojan.MSIL.Crypt
GData IL:Trojan.MSILMamut.5427
Jiangmin Trojan/Generic.aybmu
Webroot Clean
Avira TR/Dropper.Gen
Antiy-AVL Trojan/Win32.Unknown
Gridinsoft Ransom.Win32.Bladabindi.oa!s1
Xcitium Clean
Arcabit IL:Trojan.MSILMamut.D1533
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Backdoor:Win32/Bladabindi!ml
Google Detected
AhnLab-V3 Trojan/Win32.Gen
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac IL:Trojan.MSILMamut.5427
MAX malware (ai score=86)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Generic.Hajl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Generic.AP.6B9854C!tr
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.