Static | ZeroBOX

PE Compile Time

2023-06-13 21:32:47

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00006de4 0x00006e00 6.08829872941
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.reloc
v4.0.30319
#Strings
_Closure$__R1-0
$IR12-1
_Lambda$__R12-1
ThreadSafeObjectProvider`1
List`1
$IR13-2
_Lambda$__R13-2
kernel32
Microsoft.Win32
ToInt32
_Lambda$__R2
$VB$NonLocal_2
get_UTF8
<Module>
ES_SYSTEM_REQUIRED
ES_DISPLAY_REQUIRED
EXECUTION_STATE
System.IO
ES_CONTINUOUS
_Closure$__
Dispose__Instance__
Create__Instance__
value__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Thread
RijndaelManaged
get_IsAttached
get_Connected
Append
CompareMethod
get_Clipboard
Replace
CreateInstance
get_GetInstance
instance
GetHashCode
set_Mode
FileMode
EnterDebugMode
CompressionMode
CipherMode
SelectMode
FromImage
DrawImage
get_Message
Invoke
GetEnvironmentVariable
get_Available
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
Rectangle
DownloadFile
DeleteFile
IsInRole
WindowsBuiltInRole
AppWinStyle
get_Name
GetTempFileName
GetFileName
get_MachineName
get_OSFullName
get_UserName
GetProcessesByName
DateTime
get_LastWriteTime
GetType
MethodBase
ConsoleApplicationBase
Dispose
EditorBrowsableState
SetThreadExecutionState
SetApartmentState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerHiddenAttribute
MyGroupCollectionAttribute
m_ThreadStaticValue
DeleteValue
GetObjectValue
GetValue
SetValue
Receive
set_SendBufferSize
set_ReceiveBufferSize
get_Jpeg
System.Threading
add_SessionEnding
NewLateBinding
Encoding
System.Drawing.Imaging
IsLogging
FromBase64String
ToBase64String
CompareString
ToString
GetString
Substring
System.Drawing
ComputeHash
get_ExecutablePath
get_Width
get_Length
StartsWith
TimerCallback
TransformFinalBlock
RtlSetProcessIsCritical
NetworkCredential
System.Security.Principal
WindowsPrincipal
ConditionalCompareObjectNotEqual
System.ComponentModel
LateCall
kernel32.dll
NTdll.dll
coredll.dll
FileStream
GZipStream
MemoryStream
get_Item
System
SymmetricAlgorithm
HashAlgorithm
Random
ICryptoTransform
ToBoolean
CopyFromScreen
get_PrimaryScreen
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
MyApplication
CopyPixelOperation
Interaction
System.Reflection
ManagementObjectCollection
set_Position
Exception
Environ
get_Reason
get_Info
MethodInfo
FileInfo
FileSystemInfo
MemberInfo
ComputerInfo
DirectoryInfo
Bitmap
EndApp
MD5CryptoServiceProvider
StringBuilder
ToInteger
Debugger
ManagementObjectSearcher
SessionEndingEventHandler
System.CodeDom.Compiler
ToUpper
CurrentUser
BitConverter
ServerComputer
MyComputer
ToLower
ClearProjectError
SetProjectError
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
Graphics
System.Diagnostics
get_Bounds
GetMethods
Microsoft.VisualBasic.Devices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
Microsoft.VisualBasic.MyServices
GetInstances
GetDirectories
GetTypes
GetBytes
SocketFlags
Strings
SessionEndingEventArgs
ICredentials
set_Credentials
Equals
System.Windows.Forms
Contains
Conversions
SessionEndReasons
RuntimeHelpers
Operators
ManagementClass
FileAccess
Process
System.Net.Sockets
SystemEvents
Exists
Concat
ImageFormat
PixelFormat
AddObject
ManagementBaseObject
ConcatenateObject
ManagementObject
MyProject
Connect
LateGet
LateIndexGet
System.Net
Socket
SystemIdleTimerReset
get_Height
GraphicsUnit
get_Default
ToUpperInvariant
get_Client
WebClient
TcpClient
System.Management
RuntimeEnvironment
Component
get_Current
GetCurrent
ParameterizedThreadStart
Convert
set_SendTimeout
set_ReceiveTimeout
MoveNext
System.Text
GetText
SetText
Client.My
ToArray
set_Key
CreateSubKey
RegistryKey
System.Security.Cryptography
Assembly
LoadLibrary
GetRuntimeDirectory
CreateDirectory
Registry
WindowsIdentity
ClipboardProxy
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
_CorExeMain
mscoree.dll
SbieDll.dll
windir
\vboxhook.dll
Y21kLmV4ZSAvYyBwaW5nIDAgLW4gMiAmIGRlbCA=
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
Microsoft
Windows
Unkown
PROCESSOR_ARCHITECTURE
dd/MM/yyy
Win32_Processor
ProcessorId
Win32_BIOS
SerialNumber
Win32_BaseBoard
Win32_VideoController
Rans-Status
Not encrypted
Not ready
Disabled
\root\SecurityCenter2
SELECT * FROM AntivirusProduct
displayName
Regasm
select CommandLine from Win32_Process where Name='{0}'
Regasm.exe
CommandLine
--donate-level=
Minning...
Win32_Processor.deviceid="CPU0"
Core(TM)
Unknow
Software\
:Zone.Identifier
Su5reVhMbpanH8nWaxZp8OB1qpGkARoK+mhYHYtykdeUXQ9s1bCkTxeszUgXmSVT
NYANCAT
Wservices.exe
1B5aLZh6psoQttLGn9tpbdibiWqzyh4Jfv
!PSend
!PStart
Error!
Plugin Error!
length
DownloadString
v0.1.9.2
schtasks /create /f /sc ONLOGON /RL HIGHEST /tn LimeRAT-Admin /tr "'
Software\Microsoft\Windows\CurrentVersion\Run\
Flood!
_USB Error!
_PIN Error!
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.mein
tehtris Clean
DrWeb Trojan.DownLoader29.2373
MicroWorld-eScan Generic.MSIL.LimeRAT.D9DD650D
FireEye Generic.mg.22df9b6c3a71b8db
CAT-QuickHeal Backdoor.LimeratFC.S20328328
ALYac Generic.MSIL.LimeRAT.D9DD650D
Cylance unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005684c61 )
Alibaba Backdoor:MSIL/LimeRAT.5c9fa0ea
K7GW Trojan ( 005684c61 )
BitDefenderTheta Gen:NN.ZemsilF.36662.biW@ayTRBmj
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/Tasker.A.gen!Eldorado
Symantec Trojan.LimeRat
Elastic Windows.Trojan.Limerat
ESET-NOD32 a variant of MSIL/Agent.BPK
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Barys-6836745-0
Kaspersky HEUR:Trojan.MSIL.Tasker.gen
BitDefender Generic.MSIL.LimeRAT.D9DD650D
NANO-Antivirus Trojan.Win32.Tasker.jyhcao
SUPERAntiSpyware Clean
Avast Win32:CrypterX-gen [Trj]
Tencent Trojan.Msil.Tasker.za
TACHYON Clean
Sophos Mal/LimeRAT-A
F-Secure Trojan.TR/Spy.Gen8
Baidu Clean
VIPRE Generic.MSIL.LimeRAT.D9DD650D
TrendMicro Coinminer.MSIL.LIMERAT.SMA
McAfee-GW-Edition BehavesLike.Win32.Generic.mm
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Generic.MSIL.LimeRAT.D9DD650D (B)
SentinelOne Static AI - Malicious PE
GData MSIL.Backdoor.LimeRat.B
Jiangmin Clean
Webroot W32.Trojan.MSIL.Tasker
Google Detected
Avira TR/Spy.Gen8
Antiy-AVL Trojan/MSIL.Tasker
Gridinsoft Trojan.Win32.Agent.cl
Xcitium Clean
Arcabit Generic.MSIL.LimeRAT.D9DD650D
ViRobot Clean
ZoneAlarm HEUR:Trojan.MSIL.Tasker.gen
Microsoft Backdoor:MSIL/LimeRAT.A!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Win-Trojan/LimeRAT.Exp
Acronis Clean
VBA32 Backdoor.MSIL.Lime.Heur
MAX malware (ai score=87)
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Coinminer.MSIL.LIMERAT.SMA
Rising Trojan.AntiVM!1.CF63 (CLASSIC)
Yandex Clean
Ikarus Trojan.MSIL.Agent
MaxSecure Trojan.Malware.73694738.susgen
Fortinet MSIL/Agent.SWO!tr
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
No IRMA results available.