Static | ZeroBOX

PE Compile Time

2023-09-24 02:32:10

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004ecac 0x0004ee00 7.83402577824
.rsrc 0x00052000 0x0005b53c 0x0005b600 4.15031860845
.reloc 0x000ae000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000acbc4 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000ad07a 0x00000068 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000ad11e 0x000001f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000ad352 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
XJT+ ~
g+T+Y+^~
+U+V+[~
+Q+R~L
#es-8R
#es-8R
#es-8R
++$+)+.
+*+++,t
+7+8+=
+R+W+X+]+b~
+#+$+%+&
XJ4X(
XJPX(
XJTX(
:XF-:
,XJ,G
 XJ(XT
XJ(X(
+5+:+?+D+I
XF,yr4
+N+S+[8\
T+0+\+]J
+\+`8e
(XJXT
XLXio1
4XJY(
%,O.98l
+j+n+r+vT
_b`}Q
+_d}Q
__d}Q
,*+,+-+.+/
_b`}Q
,T+S{U
+A+B{U
+Tz+[
+B+D+E
XJY_bXT
XJY_cXT
 XJY_bYT
(XJT+H
 XJ`h
Y_bXT
4XJ`h
4XJ_bXT
__bT
4XJ`h
4XJ_bXT
4XJY_bX
+"+#{e
XJjX}w
XJ_b
XJ_b
+@+A+F{
XJY_bXT
XJY_bX
Y_bYT
T+,+G+HJ+H{
_+U+V{
+K+O8T
+;+<+=($
+*+++,{
_b`}
Qkkbal
v4.0.30319
#Strings
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
MemoryStream
System.IO
PoweredByAttribute
SmartAssembly.Attributes
Dictionary`2
System.Collections.Generic
Assembly
System.Reflection
Version
ModuleHandle
Console
WriteLine
ReadLine
Convert
ToInt32
get_Scheme
get_Location
get_FullName
ToString
String
op_Equality
op_Inequality
TimeZoneInfo
get_Local
FindSystemTimeZoneById
Equals
Concat
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
ResourceManager
System.Resources
GetObject
Thread
System.Threading
Environment
GetFolderPath
SpecialFolder
GetEntryAssembly
GetExecutingAssembly
GetDirectoryName
Intern
Directory
CreateDirectory
DirectoryInfo
FromBase64String
Encoding
System.Text
get_UTF8
get_ASCII
GetBytes
HashAlgorithm
System.Security.Cryptography
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
IDisposable
Dispose
Stream
ProcessStartInfo
System.Diagnostics
set_CreateNoWindow
set_UseShellExecute
set_RedirectStandardOutput
Process
set_StartInfo
Buffer
BlockCopy
EndsWith
Marshal
System.Runtime.InteropServices
SizeOf
ToUInt32
IsNullOrEmpty
BitConverter
IntPtr
get_Size
op_Explicit
ToInt16
GetManifestResourceStream
get_Length
.cctor
StrongNameSignatureVerificationEx
mscorwks.dll
ParameterInfo
object
method
Invoke
hfsdkffddfghsffdfaffdchd
fghhfgsfffffdfdffddshfdasdfh
cfffdfafdffrsfsshdkfffgh
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hjfdfhfgfadffddcdffffskhj
ffgrfgfffffffkhsjd
sfdfdshdffgffefdfkfghj
sdddffhedfddffffgjfsfkfdgsacsafp
sgfhjffffgdrfhdfdfhfffadfsfsscfgdb
djfffsfhgdffafcfdssfkfhgj
ffchkffdafhffdsfsfj
jffgadfcffgfgfsfhfskffj
jcfsdfrdfdsdgkfff
fdfcffrdgffdfsfssffj
jfffffgffrfdfcsdsgkffj
jfffffgfdsdfsdgkffff
hfsdkfddgfgffsefafchd
fghhfgsffrfdfdfffdfdshfdasdfh
cffffdadfdrsfsshdkfffgh
hjfffhfadfddfdcdffffshj
ffghgfdfdfffkhsjd
fsffffdddfgfefdfkfghj
hjfffhfadffddfdcdffffshj
ffghgfdfdffffkhsjd
gddffdhffsfgh
fhfdsffhfdfhhs
fffffh
shssgfsd
sdfgfsf
dffffss
sffdggfs
ffdgfdhs
gsfddsd
gfhfsfs
gsffssg
sdddffhedfddffffgjfsfkdgsacsafp
sgfhjffffgdrfhddfhfffadfsfsscfgdb
djffsfhgdffafcfdssfkfhgj
ffchkffdafhfdsfsfj
jffgadfcffgfgfshfskffj
fdfcffrdgfdfsfssffj
jffffgffrfdfcsdsgkffj
jffffgfdsdfsdgkffff
gdadag
hsffafs
asfdads
gfssddfh
jfgffdfhg
jffdfdfgfdgs
jsfdsffdf
jdffda
gdfdsffddj
kdsgffh
fffdfg
ffdsfs
sfffdd
jfffssk
wsfsssv
gsfffsds
gffssfdsx
startupInfo
gieIIl
eemgkhn
pgnikpF
jdhfdfsffsdkfj
hdfffafsfsdkfsh
hdffhdfffffkdf
affdhhh
sdfffhdff
hfffffshdhs
hhhgfffdfh
ffffffdhs
fdffss
hffdsffsf
jhfdfdfdh
MoveFileEx
kernel32
ResolveEventArgs
assemblyFullName
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
codeLengths
pending
minCodes
maxLength
buffer
IsWebApplication
AvailableBits
AvailableBytes
IsNeedingInput
TotalOut
IsFinished
BitCount
IsFlushed
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
{262a7241-0686-49ce-b6ce-f6c2c587ab2d}
{6142972e-c4b1-45f0-8c3a-47d622c4bb29}
UriSchemeFtp
Double
TripleDESCryptoServiceProvider
MD5CryptoServiceProvider
RijndaelManaged
System.Windows.Forms
Application
get_ExecutablePath
SecurityException
AssemblyBuilder
System.Reflection.Emit
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
IEnumerable`1
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilderAccess
Exception
get_ParameterType
GetCurrentProcess
get_MainModule
ProcessModule
get_ModuleName
ToLower
ResolveEventHandler
add_AssemblyResolve
ToBase64String
get_Chars
IndexOf
Substring
Monitor
ContainsKey
get_Item
GetTempPath
Format
Exists
OpenWrite
FileStream
LoadFile
set_Item
get_Name
FileLoadException
BadImageFormatException
StringBuilder
Append
StartsWith
ResolveTypeHandle
MemberInfo
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
FieldInfo
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetFields
BindingFlags
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetModules
Module
get_ModuleHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
add_ResourceResolve
GetManifestResourceNames
StackFrame
StackTrace
GetFrames
TryGetValue
GetName
GetPublicKey
CreateEncryptor
DESCryptoServiceProvider
FormatException
get_Position
GetCallingAssembly
DateTime
get_Year
get_Month
get_Day
get_Hour
get_Minute
get_Second
UInt32
SeekOrigin
set_Position
get_Now
get_Message
ArgumentOutOfRangeException
InvalidOperationException
WriteByte
ReadByte
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
7$&"mpO
l%VZii
\ikV@!o
^c7#Q7
**Y@n9DJ
s6.}YB
kp%'0,
NDX/al
ueN]~S
9+gy5T
#DO5eX
[:L`"B
r1fUOg
lcT|}E
xny?Mw
.q-7}vNFf
y-5}j}
Pj~p-C
2h9C~^
TTFJM5
.~%"0K
G>LVi[
RP$E9>a@jkZ
@'`=eW
:O3vqq
:A*OU6yh
j8i6Qs
M![NNvd
X[PLZfrt
_q*3QX
#,?%=o
A qpz{
{Kv"!4U
R0=@Vn
/\n.qe9
SlZUNC
NBtb)
5]HV?yU
Zs{)gR
h^xe+bZ:Yt
\}(bfk
;isf~.?
^=rdR%
ad}'$$
kS30Ro]
6$+},f
"/y^~1m
zvf'1ceX
g?U6a$N 8
_vCX_M
c!7#&Pd
8<f)nj3RT
mEHjz^F
T4*F6&
7<RbQ7
~rHIVW
Q;FVw/
DBkqR=&
"H-[l]
62w_Fu
z7!T|hA
h:3yEUR>
~iB]!g[
z%KBZaH}
<$cicIu
x<0l@I
;Kl0,s
mo5I$o
AVCxJ)
RzYI ;X
M+sKJJ
Ma+C$D
gL+@Fh
Zp0f8`hU
,N;OIM
a"m#CD
Zl0(7u
XJ|=/&n
wGR%y/
D5,QjD
!=)JVl
=qiK+^.D$
Dl<xW!
SR)2$x
xuY376N
\4je$
vUm4,Vv
WTj\5Z
[O\72A
lND5k
{yA286;
P-<cTG
\51P)$|
b=/O{Z
G5libE
JLF6/%-
<BdK3'
$oy/w;
ms+OKe
^""z,4
3eq:7
roDtM[
p-?t/]
[:-Om1
QH0C|K
UL"IhK
&RL*oI7
C,$GJx
We!"a1
acYmcQ*z
I%Juc'
b2&4,0
v)<:)J
]d>(vm#)
@+0nc3
133~n:
g_5&VT
,y ~:w
p< 't6
#:ED-b
N_2R5?n
'.$$zN8'b
1eq4=)&
u|Gix#
nGyn><[uNEu>]v
PyD*3L
[{?N[h7
"G!_|dn
N:]+KCS
d}U5I"
FYxKan
x_l]Ky
_r=+zK<
G;Wp$~8(k
#>a-]JT'
j:pnwt
~uMO$~]
WB?nkpI
jmLK|~
9)]i=~wd_
n4n&cn~/H
iC{W+!q&n
(yvFXc
m&^zKt
O`}@:4Hkae1-#
I`=wvH1
n1)> #
:}D1-:
_6Yl97H
]0T&8
pKJq_3
LpI7O`-Y
\*~x^rd
6J[6_=
ki?S"SDi
6CpA-I0
.O)VvN
s+_!J\6
C6:+TyH&AK+f:
Nqg,$D
PP*f"P9
u|,"v?
p1N/s?
>n]sU4
gx@JK,
.+q72z
\}'EK&
0&\}P
Tw"%3>
`p>d;5O
\b7,k'
n"=F-7rw
US\9_9
Df3V>1
Z|,!\m
\eIUL?U
F8k8nVf
)F840L#Gf
C@)<.I
a+%"Ej
@unX(hB_
l>lr>A
!Y(<T;
)9.db!
|?1sz)
.S_W6M
~ie/L#
Ow1Ner-
U=J,t7
LE%0;E
#/HlL+7
[uC9)q$u
eV:r&
u,1!kI
Z?L&^(E^
@=xvpn
_EIA:x`2
l:iPYD+m
Ov;GtT
80{&o5
{8Z+(
R7Pjo\d
kZe[M
cpq_VP
0Ai:%9
."T{~`FmD83
,Mp$d_
3Zw\8SA
*^b||Q<{
m?1y}e
;i140
fEVkxUc
'd-xV8=
CsnnI.o
!v*:`N'
>wNb;o
!B9{k{
ESIPBT^:q
:GOV*|
j=SiboJ'
/v[Ekz
3jDj=B@+,
mL_}ZHb
Bc].E\,
Hcge%D{e
e:]i@u
bRv>Vp
PM99DH
r (6'1
0jiPS5
lPz[Q7d
i+_2Gx}
Tl\=,-z
$|ZbV7
hLS-!n
qXg>87
StfDa_
JJIn>-
9j*{'cW
a:}ymY
8ZE&g.
rb\EHLo
w<tO'?
z5E/#Tr
w$FfhU
_0hMBP<
$*aLy
5%RNX)U
.F @BS
p!Qe]n@
S6DglA(
Q8)C\W
m'v$Ou&
b;i(St
riKm9%
UOq~:\y
se?leg
{`3be<
4T5aO&(
hJ$dwt
n*hXs#XNd`}"
RnVG&.
]iDbP&]
xtX}j9
U%X)va1IM
YO(~T+"
^6AE@@
?K6|yG
=T=r\A
LPk&WT
b;ze1N
f}8lA/S
3^cD"!
C?Kf/\
zduOhK
RuY6Vg
aa#>+o
X`R{d_g
_G@QaO?
"E]lK=Fz^
!d A3
vZWp/N]g
b/}Zf3
gWznM_
[#6\eqpb
Tc[T=D
rUOkoPC
:8`<fU
sSd_yX
6(I$qI
Tve7@j
SCyUJ(&e
>N(?&G+O@
c=Nq+
M*JKReV{+
(QD!Y*
IytB:O
6##R~EDb
qr=vR
NrxVfG|
CloCWv)
Ze"~JZ
!AXoxy
Z/'2QnW-
1eH&ZY
u@yKs
%+{vr
J&i)2-
HjQY%
P' X[7
C<i~L
2R#)DlHN
Y?7}`7Q
,E.oXi#
XZ<rJP
TT]6%0
xC{hQjh5G
s`f@a]
RW3E YA5
aU*!WQ
H*"F]J
/iHZg))
g1k9<*
e@Ja{B
vOvv]q
t%W._:
V//8a0
stff<_
8+T?Au
#S+b\%
7Nw{nh
i9o"?>
FPt_JJ
K+A.#2
5XVk>7k
9qTK<j
@4t'7~
^crc3E
D`%{<D
-<9^({
y&1S"-
`#1<rr
vRgBds
6cOU:4
6q%ZB^
KPpr[R
\.kx_t
C:n"M)
%C &;)
ni>y/7
w {6 6
d8;a$r
Y5DU5O
21;q=)x
Zusb^vq
S|u2<9y
<-6iO\
u 7Wq@
VN8nS#
(=&CDM
Dn5ipy
9LkD#"f
kvBVj}
]i;-#$
.;J$9C
#lpD3P
Xn,U`V
Ftq\ZPq
G0O81H
%JX\o)
TsaD28
Y~MjY*x
5_sh&DU
7m5N0o
!{4=$Y=m
7YPuOr>
GkgE[Y
`0VTe46S.
KrKpMq$vfgI
jJ/s P
xbUY%*
4Js[8P
P(vtO*
3U@![#
L>/`tR
Ccj)o8k|.
L~}WRv
o8hD]}1
bIc^0s
xYcN<k
`|dV,K
I/0cGZX
k5@Ar2d0
[@X*-uH
)'T!Y.
21/4;Gv
GzX0YX3
AtGBL'M
2BvDi[E
l>QI#e
Ov`+{Kr,
2:!W(E
=v*Zox
FGwi%ey~w
=p-z]]
']rEz(X
*HvY_A
J%<0ZB4P
.h!rav
)=z-8~s
ZjWY=8
AApr{"<
K\q=<f
WAyX3g
+ecn4;
|oid<yN
uT/(l/
`F0v7{a
L<LGe/
I{_=vS
m'kK1X
E,Cd!I6Tn
!1-[W=2
O"Ep|N
NmR7*~u
LLk.^{
7@F3i;
#vH&Hoc
V)C4wI
]UeXp(e
<3Cxy
jyLGcX
<$Z#2J
xUfQo]
Bd__>a
S_Hy=u
1MfW{e
V.uWPE
*uB~9eOe
<:lN)h
@i}FC#GS
!\qS@'}/
)u0Ar{
c_ML* A
!YfSGd
QPFWvY
qSH+5
a}Uw(%e
p{(GH8
@/#XroP
8h-E@K
8|:*Pe
K_ETf}%
.ehCz5-
#BfFu,cg
@m1^G8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
65BAJIKILIMINIOIPIQPRISITIVUWUXUYUZU[U
w3wp.exe
aspnet_wp.exe
e2UwYmIwNmFkLTZhMDctNDE3Mi04NDY4LWNlNzgxZjk4MzYxMX0sIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49M2U1NjM1MDY5M2Y3MzU1ZQ==,[z]{262a7241-0686-49ce-b6ce-f6c2c587ab2d},e2UwYmIwNmFkLTZhMDctNDE3Mi04NDY4LWNlNzgxZjk4MzYxMX0=,[z]{262a7241-0686-49ce-b6ce-f6c2c587ab2d}
{0}{1}\
, Version=
, Culture=
neutral
, PublicKeyToken=
Version=
Culture=
PublicKeyToken=
{e0bb06ad-6a07-4172-8468-ce781f983611}, PublicKeyToken=3e56350693f7355e
{6142972e-c4b1-45f0-8c3a-47d622c4bb29}
Wrong Header Signature
Unknown Header
{data}
ERR 2003:
{71461f04-2faa-4bb9-a0dd-28a79101b599}
MAINICON
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
CompanyName
FileVersion
, , ,
FileDescription
LegalCopyright
ProductName
ProductVersion
, , ,
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Ser.Lazy.1803
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Trojan.Crypt.MSIL
VIPRE Gen:Variant.Ser.Lazy.1803
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Ser.Lazy.1803
K7GW Clean
Cybereason malicious.681c85
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.JLU.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.XWorm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:Vg5pY1ZJF6I3sw8vG/7uHg)
Sophos Generic ML PUA (PUA)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.jh
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.31c0fb555469b083
Emsisoft Gen:Variant.Ser.Lazy.1803 (B)
Ikarus Trojan.MSIL.Crypt
GData Gen:Variant.Ser.Lazy.1803
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Ser.Lazy.D70B
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.XWorm.gen
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36722.Qm0@a0rfX5hi
ALYac Gen:Variant.Ser.Lazy.1803
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AHUA!tr
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.