Static | ZeroBOX

PE Compile Time

2023-10-19 16:05:33

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004e9f4 0x0004ea00 7.86068507834
.rsrc 0x00052000 0x00000600 0x00000600 4.50107544564
.reloc 0x00054000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000520a0 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00052374 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Y?_di
ZY?_b`
\-o`
/-o`
fefefeffeef
W^feffeefef
Gffeeffefefe
feffeeffeef
afeffeefef
9fefefeffeef
W^feffefeeffe
feffeefef
Gfeffeefefef
feffefefefe
afeffefefeef
feffeefefa(y
ffefeeffeYa*
ffefefeeffeY
fefeffeefXa*^
feffeefefY
ffefeeffefea
feffeefefef(r
gniX3
gniX(
Xffefeeffefe
afefeffeefa
Yffefeeffea
Xffefeeffe
afeffeefefefa
Yfeffeeffefe
Xffeefeffeefhah
affefeeffehah
YffeefeffefeXa
Xffefeeffeefa
Xffefeeffefe_-
afeffeefefa
83D~J
efef d
L*Xfe
e6'Xf
cffefXE
Xfe dp
a'Xf A
Ye ULB
3e!Yf
aeffe
S)Yf X
#$Xfe 6
Xfe JT("Ye
ae fNt
%Xef e
r{ af
X i:c'X
i$Yefa
X&Yef Y
JM=~
jo&
af Je=
_'Xef $r
Yef (C
2F Yf
cfefe
efe zf
a* f|$
Ye* 3*
0+#Xo.
X F}X"ao.
_b`}
&;=FZ8
EuN)Q4n7
s{z4r
Z3 }bh
Lt8SqeU
[Mx,2qq
P6)!?.
/ &Ft%
mNsGF;
}ow+ i|6
%uos-z'
tgO-:=S
G#Cb?^
QZ~h#7
JT^[~
>M-B]|
^RDW{Kn
*{m|k05
>N/yMDv
_`Y`:a
w4=PQm
eNr64S
p?%OK
ey~Z'S
q`|;t)A\
.jkqrI'
`g^ua.
Bb`D1<
6EQWA$
nvv)1~(
|j<V}
bu/iO
k!1B&`w
Zs`\Rv2
N~}B.c
KX;+x>
hq`e3
@;0oe6
u;j;tF
ov<1CS
|U6ZY=G
# $Vu]
x0ndJh
Dy=N~?E
@mY885
|@u$+n
H.07*7
T-nY>b
>AA,m|y
D&'4f4
JBHyw}Nq+
JdcKTE
!R,=?z\
mAp_QTPM
cB;|F2E
Dj)r}k
t=db2R
@8dP%L
ne+hqE
s7V}b
w#^9|I0
K?5f1zz
NrfOA6
vmv@Zulw
`<o#A;
ihx`SA
q0c9cp
X<dqP
UCNhw!0%
u5m$(6Ez0
{oY%3d
:JH;v;
S0n*&e
erpJh1
7QR5]o
m`8FtG
D`?aA]
IQ~8^ 4
f!>_O&
b:ad:ni
]=LU<N
u7[$BT
!L>fs?k
}YFj}S
s`|j"p
d~53?
-wNsTp^
7@?i&w
e6%;j+
=K/sQfn
^oY=y@P
+!`>+M1kJ
+lO{J9
V6h #}
;vv1K;
e#T'G3
1-[V2?
Idy.;9
n&c_WS/
tr`[4f
g:&QD5
2^xOF[
FZ={Ql2
!Z_/w_/
GN*;BS'X
g{K0h\
9$vi/
LyIW;^
#WF)J+E
9>?i,)=kW
;QeLKv
xG'.n40IJ
y_-mr(~F:
.gO#Oj
'@rRj9e
R8U(Gr
%LwIg
LYQR,b+
Y6FB}*u
3V>.ZM8
fQ#w*9
JmIV{P
>q_ha;T
Q!Y1`:7!
ivH'Ldi
D`E4!2
siF3E%
y)<FMjT
/hS&P:
I]L6C
t:,be@F
"Z4D\0p=2[
kx%< +
vVR>(l
|V.16<
+gYLNF
E-[qpR
nKm^r(
8cd0[Z
jN@6v2
\SHwYN
`|?1!j
jJ.,3Z4
ZEd~'K
xtWTW4T
%ra(',
V!#xw<
&^%JtO
b<Q"T
2gRtDD
Qnep>F
;oW<@u
;xg2S:y.c
PS^"r*O
=F+Jpt,
L!Jz(7j
P"~B9?R
<ltOm'7&
6kjMT^'
z+4OJ[
/[jAB)
b v<eS
DRi0n[;
:OU"$C#,$
f1&V]_
<-{9[`SO
n5`0>A4
$T%F4_
w!{h&
$<<UGU
T{Ae8
:<nHbGd
p+:3t_
U.a.J0
*T('zg
j7mS"F
c$5!Up
6I\![fW
,A2;.'
mM_;{I
`VK#e]
30$(j<
M=t7b2a~
+%#Jy
8Ym'daY
^5mqm!l
}"P"}yn-
N{%@("
KLdq5J d
nJB{2N
(7)=9E
R+#XkK
'6&k>0
/WHu@zY
1W[#_~z
O)ROb2
}w^7L+
cs\R5J'R
k/d.u?
2jxtn@
>3}I;A
d6|bwM
BA }V*
t=-e|`U
Y$3niQn
85:|AS
w>Gt!_r
EEyD)G2W1
lR1sDX?L
hA?SD7
cwWyT`
`0pI$FC
7YD&Mfg
DAI308
Io,B2B
/t3U.?i
;y(Y%q
yA#z+f
R}uIVj
'|xK{h9TG
O|`t;'
+'7O($/
XGS|p;
YZHLgV
)]}q|?R
Cgn`y/
>hp^]I
U={Nuq=
u>.Gl?
jGtEk`I
+kxa#Is
'm;,<P
IslhfG
[ sK&an
Nk^:#ITx
wo@KELL
?(:}&v
8grBgD
v?(g`(
',S|Qd
tid_q!j
zw1K;d
-}M5H]Wq
,|QBDI
r7#'I+\W
5^x9G3
<e[A4W
'x>^f*2]
k\Q5ce/
j{bYpS
o2$ASY
"]lY%G
8uI'N@
]bF,@2
rMjA>U
> ;dk3c
k[%cj|
dsz:ew
k1Qb(a+
350*Tf
dLR(H$
IyV+h3r
J0hk;q
x;;-EPW
?:=NI[
2n^+"y
[]}Bwr
>:(u@?
_g1p.x?+
}Y~"-]
>$f0U@
0D36cW
.`qGC
1ECZVS
XmiA^DAG
=bS>;]
DAkZn lF
d)HlM(
$=8z8&
c|#>2~
1X[uGd
h0cDdc.
+';GxI
'&F:x-
Y8GP=Z
su8(,K2
*mRQG\
Cat0W.
u,xA/F
6iZC8K
Q'v<uG
!=hc{0
NWouhq
>]Z);L~
>db`\01
v9v]_s
hDOz)v
}Y5K$.
A&wV$)
q~[*sr-
d<yRn%
FcuaW
q]sqY9
a+,jUeS
dxK9yKw
txFthC2s>A}Yg
hD&"%7
Hoq_Se
"#.6=e
'6jGMT{
LX$,%Y
[?QW7{
Cc5HcBQ
_.&;v:
%6RtL'
n~\ZEp
'l5cuI
6=>4_A
|g}DkD
Q?PQ8]*
'jQQD+;
+unSe%N>
<A{?}$EP
bfM`SC
2mL7V<3
*pa~#z(
D6L]2xz
|?:=f^p
ldH>GQ
?wnQ+:
|h]ijg
/a#a+>
OPF5k{jy:O
ETh "#
kcpLKD
Q)oFoAF/
p$Vm2\H
L*SMs6e
oD;eHX
h'T`!k
uGn%<^[
fK^W{tn
R[0b"b
qs4w0L
%Js.'W
RGiU)q
,nGc(!
Iy'Jw+}
RzejtC
y1@yyB
a%w4xC
bYLVC^
B4\g8p
)bB_Gx
e\EqSF
Xt_,~q1B
a7*:/7O:
n[l*avl
3]}Lus
VCpqo|'
U6hfD@Z>
*HC;q,
1M-stL
j;0c.<g
.e;Vz?
}g7%-v
"hV=q@NA
g@jG0|o
P7aV?
]kYU@6
@h&~jE
Nua|#8
;NbrdjU
S4!{ef
*BVbop
=EBcl6
u<LbVI
M'Mm,@L
z8M`.q
&s#SpY
NTRKHB
0~Zx2
<H$Km3
nm{XT@
cY,.V%
ab`R^d
iR&I&,
G$DIH4
t8fOmH
uqHh6h}
k4:G""
sb2>b.
jWe7S|B
RO/XyUw
rml-P
w-u9+8~
7BO4f-
}T{zg"
!a6WRWM
#hQw|<
H._~i>
T<er/,}SpA
f~7ZF{
t<$Tomv
-M3)M
>dlUrE
/zr?w*
\@$if:A
3{g0$m
mjvw2>&yy
uPHW}N
'!r+rXY-2Y
CM]p@
rk?,W0
'OIj6
FVHK&#'
s/|j0O)6$
r\sTG
wUVQU[sY9
<p8If-
~--au\&(
"7S(Og
Ah#?%{
GTKFD(
y%U\mI
iS=l@*C
r,<A(Y
(,}0h.M>
BH6SGQsK
}`xzVqfY
4LPaW=/
26!m,-
a#?7#,H%
v4.0.30319
#Strings
Ldc_I4_0
Ldloc_0
Stloc_0
Ldarg_0
mtx111
Ldc_I4_M1
Ldloc_1
Stloc_1
IEnumerable`1
EventHandler`1
EqualityComparer`1
IEnumerator`1
List`1
UInt32
ReadInt32
ToInt32
Ldloc_2
Stloc_2
Func`2
ConcurrentDictionary`2
Ldloc_3
Stloc_3
Ldc_I4
Conv_I4
Ldc_I4_5
ReadUInt16
get_UTF8
<Module>
System.IO
Ldloc_S
Stloc_S
Brfalse_S
Bne_Un_S
get_IV
set_IV
GenerateIV
value__
GetData
System.Web
mscorlib
System.Collections.Generic
DownloadFileAsync
get_Id
get_ManagedThreadId
get_CurrentThread
add_DownloadProgressChanged
Interlocked
add_DownloadFileCompleted
System.Collections.Specialized
ReadToEnd
Append
get_Millisecond
DefineMethod
GetMethod
Replace
StackTrace
GetHashCode
OpCode
FileMode
CryptoStreamMode
HtmlDecode
UrlDecode
get_Unicode
get_ProgressPercentage
AddRange
CompareExchange
DynamicInvoke
EndInvoke
BeginInvoke
Enumerable
IDisposable
Hashtable
RuntimeFieldHandle
RuntimeMethodHandle
RuntimeTypeHandle
GetTypeFromHandle
EventWaitHandle
Mobile
Console
DefineDynamicModule
get_Name
GetTempFileName
get_FullName
GetName
AssemblyName
StackFrame
GetFrame
DateTime
WaitOne
WriteLine
Combine
DefineType
CreateType
ValueType
get_DeclaringType
SetReturnType
GetType
FileShare
System.Core
Capture
MethodBase
WebResponse
GetResponse
Dispose
Create
CreateDelegate
MulticastDelegate
DebuggerBrowsableState
Delete
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
get_Value
LegalBlockSizesValue
LegalKeySizesValue
TryGetValue
add_ResourceResolve
Remove
mtx111.exe
set_BlockSize
get_InputBlockSize
get_OutputBlockSize
set_KeySize
SuppressFinalize
IndexOf
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
UnescapeDataString
ReadString
ToString
GetString
ParseQueryString
Substring
BinarySearch
get_Length
StartsWith
Newobj
AsyncCallback
TransformFinalBlock
TransformBlock
DeclareLocal
DefineLabel
MarkLabel
System.ComponentModel
GetManifestResourceStream
FileStream
get_BaseStream
GetResponseStream
CryptoStream
MemoryStream
get_Item
set_Item
System
SymmetricAlgorithm
Random
get_CanReuseTransform
ICryptoTransform
get_MetadataToken
GetPublicKeyToken
AppDomain
get_CurrentDomain
SeekOrigin
System.Globalization
Action
System.Reflection
NameValueCollection
GroupCollection
set_Position
NotSupportedException
ArgumentOutOfRangeException
ArgumentNullException
EndOfStreamException
InvalidOperationException
ArgumentException
StringComparison
Intern
Unknown
CopyTo
MethodInfo
CultureInfo
MemberInfo
ConstructorInfo
System.Linq
InvokeMember
StreamReader
TextReader
BinaryReader
MethodBuilder
ModuleBuilder
TypeBuilder
StringBuilder
LocalBuilder
ParameterBuilder
AssemblyBuilder
Binder
Buffer
ResourceManager
ParameterModifier
DownloadProgressChangedEventHandler
AsyncCompletedEventHandler
ResolveEventHandler
System.CodeDom.Compiler
DefineParameter
get_Error
IEnumerator
GetEnumerator
GetILGenerator
.cctor
GetConstructor
Monitor
CreateDecryptor
CreateEncryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
OpCodes
GetExportedTypes
MethodAttributes
TypeAttributes
ParameterAttributes
GetBytes
NextBytes
KeySizes
BindingFlags
DownloadProgressChangedEventArgs
AsyncCompletedEventArgs
ResolveEventArgs
get_CanTransformMultipleBlocks
Equals
Contains
System.Text.RegularExpressions
System.Collections
RegexOptions
get_Groups
get_Chars
RuntimeHelpers
SetParameters
FileAccess
AssemblyBuilderAccess
get_Success
GetCurrentProcess
Concat
Format
GetObject
Select
System.Net
System.Reflection.Emit
get_Default
SingleOrDefault
IAsyncResult
WebClient
get_Current
System.Collections.Concurrent
ManualResetEvent
get_Count
ThreadStart
Convert
Callvirt
WebRequest
ToList
MoveNext
System.Text
get_Now
InitializeArray
ToCharArray
get_Key
set_Key
GetPublicKey
GenerateKey
System.Security.Cryptography
get_Assembly
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ToBinary
get_Query
op_Equality
op_Inequality
HttpUtility
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
WrapNonExceptionThrows
$7f40608f-a792-4c3d-9c29-c2f1b0bf229a
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
*)+)0/1/658797;:@?A?GFHFIF
kZFlLcdy7LpzP856oZx/Nswxg5tlPM99rpEtHsdrh4ZiK9tesZtzNMBzu9NxPNZAhJ16Nex+r40tNtJAi4ZzKNd+roFiIJl4p5xJFcdxpZx+YuV6trxvKcdZsId7EcNxpoRzYsV6trdYOM96+aF4PcdnjY4tC8d+prtiK8txpdNXPcYkpY1iBvJwsYFiMM1x+Y9zLf1ct5pkPMxrhod7OMtx+btzLeZ+tokta5Un+9stGNFsp4V0NdtMp5pgPNAkkYF7Kc56g5tlPM99rpFTIdJzrZpzK5l9o4pzNdRy+Zt7Nsl6to1lLQ==
DefineDynamicAssembly
TripleDES
Rijndael
System.Security.Cryptography.
, System.Security.Cryptography.Algorithms
Could not load type {0}
Create
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
mtx111.exe
LegalCopyright
LegalTrademarks
OriginalFilename
mtx111.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Generic.Malware
DrWeb Clean
MicroWorld-eScan Gen:Variant.Zusy.487956
ClamAV Clean
FireEye Generic.mg.03e41b95af64f8e4
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fc
McAfee Clean
Malwarebytes Trojan.Crypt.MSIL
VIPRE Gen:Variant.Zusy.487956
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.487956
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZemsilF.36738.tm0@a8cSepg
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.GIEX
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Troj/Phobos-E
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Zusy.487956 (B)
Ikarus Backdoor.MSIL.Agent
GData Gen:Variant.Zusy.487956
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Zusy.D77214
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Program:Win32/Wacapew.C!ml
Varist W32/MSIL_Agent.GLC.gen!Eldorado
AhnLab-V3 Clean
Acronis Clean
ALYac Gen:Variant.Zusy.487956
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan.Genkryptik.Qimw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.MZV!tr.dldr
AVG PWSX-gen [Trj]
Cybereason malicious.c82b25
Avast PWSX-gen [Trj]
No IRMA results available.