Static | ZeroBOX

PE Compile Time

2050-10-15 07:57:10

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002f4d0 0x0002f600 7.99119353934
.rsrc 0x00032000 0x00000564 0x00000600 3.91893050284
.reloc 0x00034000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00032090 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00032374 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
57AA33B247146613272FF7CF65825271C773981BE191A9809BA3A702FB6DEAA0
IEnumerable`1
ToInt32
__StaticArrayInitTypeSize=190753
<Module>
<PrivateImplementationDetails>
System.IO
mscorlib
System.Collections.Generic
CompressionMode
Enumerable
IDisposable
RuntimeFieldHandle
ValueType
GetType
System.Core
Dispose
Reverse
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Xreccx.exe
System.Runtime.Versioning
GZipStream
MemoryStream
Program
System
System.IO.Compression
System.Reflection
System.Linq
InvokeMember
Binder
Hunter
BitConverter
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
BindingFlags
RuntimeHelpers
Object
Xreccx
InitializeArray
ToArray
Assembly
op_Inequality
WrapNonExceptionThrows
$d619707e-06f1-401e-bfe3-bacb8003463b
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
nDTT,@Q
{0um)^
_](9+q
=K$hYfB
jp7_t*
&nqR<D
}_:NHmTwq
w7Hil;
)cqg.)o
R*sr~"\V
sO0d#>
Dgt8XL
kAPb@P
h8dyJD
aBj,b3a
+!WJ@dX
R}`JiB)@,
"F6H;C
;*GP"(yg
Hvq*1
hc"Ob"
H>Rip=\$#
J4K4S4C4
[:6b+IQ
"]c+k7
9bz`ht
W3<8[Mj
<P|pCY
UYq&H4
cW-{yo
R{EE3{
P4)6]
sB"j<i
OK%>mS
01%b9K
&Et[=z
30xMR4
;X>~eqs
?%uY"W
{x1DA0H
cZ5"vvV
tC\Pgt
^:]<CDk
o}vEA3
C>F6I{
Ha)TaG$
?:!UNT
j.q'Mh
9EYR*P`
bFnL5O
zC#v]\
S:]^Jn:
3%:uNG
SfOxh=9
R]YCGq
\vzg,E
QS_+NV
./J1B@
CC0SO8
)L5t-b
PCT_rl
5r+&]{c
2w:2?O!V
jl&xg<
+r|McO
Y2kfI&
wW>yfW}
2MO]rg
WYI4DM
22se+^*
tlAx#L
`5b][{
e] )'<
j8~?8c
jsOg_?
{O'zH x
ky_?!-
H[k{{{
+V5ml
nqPZ!J;
<kI'2*
|mlf,^WHV
hT3F&W
$s~O=S
T-71=C
b5`LB]
z5`ud&
zccd&'
|~p*DXY4
x)97>]
CX]Ve@
n&eU3tEH
0MNReN
7TFH"_@
'p4AdA
|1E]59PRQSLp
L8]Bo&
+!KeD^
b0L[!Q
P~jX$+
dPW?C
)j^CLT*#$6j*
HNkd~L
MhL%.O
Ac4?Hf
s#E#(
RC^j(K
Z3Pxj^R
vU(]/ sp
HO,3XeE
[>;zD&)B.
c++vd$
y%>xU7
`k&~lwm{
j%dZcH
"Q05 n5
mV@R}I
@&7zm|
pL2_Upy
rUhW^j
?cI07c
dX]Fxl0
d)$gxd
bZ?)or
:I|HTz
N^1K&F
FZKGWZ
oo/>{p
^x[yYR$
ew'2JqG
2++L++
ZAq.:K
[@~sa~g
fO]KczbYwZ
J{j[J4
cO]Iw'(
n{CErGW
,ggYeabWA
MlLnHSx
NO^kQm~
rKVncmF
KqNrbK
%ijkbRY
UvmveKFE=0
w+:MiyEzmEfcA
lJVTdi{:
eJwWm~Fc
B}~qewvy
vwsqq{z
nWEceK
\GAZi[fyM
=?]or7
ZSMbKV
JC]kyAQ
rS: /u
BX=Vg]
U3J1*>
\bu};d
+pz#N;pZ
<}4sX^
i'Gz3~
So{Zr
8z_um/
J}xF//
gb+$^E4
!FDa><
RAh__s
Eh#*9dO$
GV;OO,c
mxpS*
z>J?r=
=a|=v'
gBG0}Ih
bL*BZL3
b"qeM8&
-4t8"tm
gcsHtj
BhQe4,
^0$+5$
dB^l:
yTg}j;
"ZKq?0
~ d@D=S4Hc
HCi*XA
nI_EpC
w6]'xp
JYLpe
x|w`8o
m!-/rx
AYGQU_
+i;DFN
Mt;A7q
&:a_.I
9eZLo+
z.@Ya(
L5-JYX
JPtht]
dger&S
2I(%VK9
(Ji__S
Bsaofp
C`o|}O3\]
DOU-
w0u^3I=
6a8E%d
qKHTl
oe|_]f
<EV==n
7)?(!n
&nQx=A
^l_=iG
?[ 3]"
+\8SZE
/iarfy
)VKDhJ9
{:IMh-
J>F]r\
e_j/*
+J0H*cM
^@&us0
yCB:^$
/lY[{d
x|nOw|o
g,+}u<>
s*dZ
/<>833
<$ha\YX
Rb[[i}85)
6oMNco
i'v_kM2
^Ujph
Vq$-}%
i_A_@n
<.T(tG`
p1#Mq6
d.=)L^1E
tZ1.|QD
ysh5>p
mp2dU Q
Yyemm
(HMf+_
jlfs"),C
OL1?!q
{,?H[bl
|+#A97
1+PkJm^
S<32(9N
27+47K
0*CyP^
Jmnt|$
7R)I-:8
m^~@x/
k(}NuY4H
QYi"Pw
\b83
fk|N:_
B_y)md
KieNZ,.
ya3r}l
gu'_wKX
a#Fz_)
v?i<RM
/bNL(Q
T7Y:fr
){nWS4
Mr&iR>
v1zNw
WHtpP?8
AXh+*v
y |BpQ
06\[!G5
=zblc@
:W Lrb<
@*u^!7
fb^"Q|$S7:F
"]U>p&|'S#
P0"Jc
QmJEF*
CX2hk#
")iz|[
~<^[ ~<V
qZ8=7/
Op1{2N
vEiJG,%
DA!VC_
aG0dO*
&[9&`C
'Z5&^I
pL8hEx+iJu
?mYG})
>ik(kf
^P2p~d
zY0!\U
]]]]]]
NVYh"R
:<<I1
3%kloY
mpaIUF
#5Jlj2`0e
Dukq5T8
[KG("}
p<u!m^p
E5"`7b
itQ_e0
Vc@t~o
j#BC"Tm!
x?H}B4U
{Ch<rh
inw'x&
qT@uCV
NGTLWZ^
mhXKH~@
BF]xJ
Ahbq6e
y~Q\b%~
S,M,{"3
;pvN$6
Xo_0=V
5,=g*{
~2`RN$
dD@)iA;
2@-m@K
E_v=^{
7T=W%j|C
7bh|&:
PTz7Jo
[XT}k(?
_I_(b.
$iy.;t_
wJ6UD[
!qO!0AIu
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
gRAEw47oAKcV9ETdab.Jk8SwnxbNaGuoULOLg
B7EmxhOMn
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Xreccx.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Xreccx.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Crysan.m!c
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.Lazy.444617
FireEye Generic.mg.6e1e844cd8cb843e
CAT-QuickHeal Backdoor.MSIL
ALYac Gen:Variant.Marsilia.26642
Malwarebytes Trojan.Crypt
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Lazy.444617
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AIZW
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
Alibaba Backdoor:MSIL/Crysan.b7ac936e
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:tHLg4ZbAY2J7QeJ5tZs6VQ)
TACHYON Clean
F-Secure Heuristic.HEUR/AGEN.1310400
DrWeb Trojan.PackedNET.2148
VIPRE Gen:Variant.Marsilia.26642
TrendMicro TROJ_GEN.R014C0DL623
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Crypt
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1310400
Antiy-AVL Clean
Kingsoft MSIL.Backdoor.Crysan.gen
Gridinsoft Trojan.Win32.Packed.sa
Xcitium Clean
Arcabit Trojan.Lazy.D6C8C9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
GData Gen:Variant.Lazy.444617
Varist W32/ABRisk.OPKA-2806
AhnLab-V3 Trojan/Win.MSILZilla.C5392071
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36608.mm0@am85Ufd
MAX malware (ai score=80)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R014C0DL623
Tencent Msil.Backdoor.Crysan.Iajl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AIZW!tr
Cybereason malicious.ea0c9b
Panda Trj/Chgt.AD
No IRMA results available.