Static | ZeroBOX

PE Compile Time

2024-02-20 20:39:13

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00004088 0x00004200 5.68429186369
.rsrc 0x00008000 0x000017e2 0x00001800 3.7154008522
.reloc 0x0000a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x00008da0 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000910c 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000091a2 0x0000041a LANG_NEUTRAL SUBLANG_NEUTRAL ARC archive data, squeezed
RT_MANIFEST 0x000095f8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+O+PJ+P+U+V+W+\
.&+E8y
+(+)+*(
 0,8e
+9\%,
XT+-+.
+A+B+G
+G+L+M+N
,N+r8w
,>+68s
e.G8r
+F+G,:+J+K{
+G+HQ+LPu
-5+3+;+<+A
+M+N+O+P+U+V-
,J+m8o
+-+2+3+4+5
+0+1+6
+-+2+7
+6j+:+;
+$+%+*+/+0{
+,+-+.+3{
-&++ +!+"
v4.0.30319
#Strings
Mtkfarukc.exe
Mtkfarukc
<Module>
mscorlib
Object
System
Exception
System.Core
DynamicObject
System.Dynamic
IEnumerable
System.Collections
ValueType
PoweredByAttribute
SmartAssembly.Attributes
Attribute
value__
List`1
System.Collections.Generic
IDictionary`2
NumberStyles
System.Globalization
PropertyInfo
System.Reflection
Func`2
IList`1
IEnumerable`1
StringBuilder
System.Text
KeyValuePair`2
Dictionary`2
ICollection`1
IEnumerator
SetMemberBinder
GetMemberBinder
.cctor
GetEnumerator
TrySetMember
TryGetMember
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
CompilerGeneratedAttribute
DynamicAttribute
ContainsKey
GetProperties
BindingFlags
get_Item
Boolean
ArgumentOutOfRangeException
String
Format
Enumerable
System.Linq
Single
get_Value
ToString
WebClient
System.Net
DownloadData
Thread
System.Threading
Environment
get_CurrentDirectory
Directory
System.IO
Exists
Reverse
Assembly
GetTypes
GetMethods
MethodInfo
MethodBase
Invoke
get_UserName
Replace
IEnumerator`1
get_Current
ToLower
Append
get_Keys
get_Count
MoveNext
IDisposable
Dispose
ToCharArray
Insert
get_Length
Concat
IsUpper
ToLowerInvariant
ToArray
CultureInfo
get_InvariantCulture
Double
TryParse
IFormatProvider
Activator
CreateInstance
MemberInfo
get_Name
get_PropertyType
DateTime
GetTypeFromHandle
RuntimeTypeHandle
op_Equality
ToUniversalTime
AddSeconds
Convert
ToByte
Select
ToDouble
ToInt32
ToInt64
SetValue
get_CanWrite
get_CanRead
GetValue
get_FullName
Contains
StringComparer
get_OrdinalIgnoreCase
IEqualityComparer`1
get_Chars
get_UtcNow
op_Subtraction
TimeSpan
get_TotalSeconds
get_Key
NotSupportedException
Enumerator
set_Item
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetType
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2022 Discord Inc. All rights reserved.
$15efb970-86d7-44e6-8462-43b0204534a0
1.0.46.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
#Powered by SmartAssembly 8.1.2.4975
_CorExeMain
mscoree.dll
wwwwwwwx
wwwwwx
wwwwwx
wwwwwwwx
wwwwww
wwwwwp
DDDDDD
wwwwwwwwx
wwwwwwww
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0123456789ABCDEF
!$P#$X
$`3$i3$t
Invalid JSON found while parsing a value at index {0}.
Dvvtdqfl.Candidates.ResolverComparatorCandidate
https://cdn.discordapp.com/attachments/1198861516833820695/1209418859451387914/Hreqscnb.mp3?ex=65e6da16&is=65d46516&hm=857a21d854ada18ee03abec261bb02e25a424fd2dc4fbbf5cf13e9301cccd468&
JSON must begin with an object or array
Value '{0}' was not a valid JSON number
Invalid JSON found while parsing an array at index {0}.
Invalid JSON found while parsing a value pair at index {0}.
__AnonymousType
Invalid JSON found while parsing an object at index {0}.
object
Invalid token expected.
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
1.0.46.0
InternalName
Mtkfarukc.exe
LegalCopyright
Copyright (c) 2022 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Mtkfarukc.exe
ProductName
Discord - https://discord.com/
ProductVersion
1.0.46.0
Assembly Version
1.0.46.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Blocker.V!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Gen:Variant.Marsilia.109075
Cylance unsafe
Zillya Downloader.Agent.Win32.551855
Sangfor Downloader.Msil.Blocker.V6m4
K7AntiVirus Trojan-Downloader ( 005b1e751 )
Alibaba Trojan:MSIL/PureLogStealer.32815109
K7GW Trojan-Downloader ( 005b1e751 )
Cybereason malicious.617318
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto Clean
Symantec Trojan.Gen.2
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.QFG
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefender Gen:Variant.Marsilia.109075
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Marsilia.24064.A
MicroWorld-eScan Gen:Variant.Marsilia.109075
Tencent Malware.Win32.Gencirc.10bfa519
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Nekark.cvsbo
DrWeb Trojan.DownLoaderNET.938
VIPRE Gen:Variant.Marsilia.109075
TrendMicro Ransom_Blocker.R002C0DBM24
Trapmine Clean
FireEye Gen:Variant.Marsilia.109075
Emsisoft Gen:Variant.Marsilia.109075 (B)
SentinelOne Clean
GData Gen:Variant.Marsilia.109075
Jiangmin Clean
Varist W32/Agent.ENS.gen!Eldorado
Avira TR/AD.Nekark.cvsbo
Antiy-AVL Clean
Kingsoft MSIL.Trojan-Ransom.Blocker.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Marsilia.D1AA13
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Ransom.MSIL.Blocker.gen
Microsoft Trojan:MSIL/PureLogStealer.FEAA!MTB
Google Detected
AhnLab-V3 Trojan/Win.PureLogStealer.C5592532
Acronis Clean
McAfee Artemis!3E2F66F61731
MAX malware (ai score=88)
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Ransom_Blocker.R002C0DBM24
Rising Ransom.Blocker!8.12A (CLOUD)
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.73689294.susgen
Fortinet MSIL/Kryptik.AKSH!tr
BitDefenderTheta Gen:NN.ZemsilF.36802.bm0@aG5tiVn
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Ransomware:MSIL/PureLogStealer.FEAA!MTB
No IRMA results available.