Static | ZeroBOX

PE Compile Time

2021-03-15 21:07:07

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000a3a4 0x0000a400 5.70028772222
.rsrc 0x0000e000 0x00000400 0x00000400 3.51606797931
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0000e058 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
&  (
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
Stub.exe
mscorlib
Microsoft.VisualBasic
System.Windows.Forms
System
System.Drawing
user32
winmm.dll
kernel32
user32.dll
avicap32.dll
Kernel32.dll
Stub.Resources.resources
<Module>
MyApplication
Stub.My
ConsoleApplicationBase
Microsoft.VisualBasic.ApplicationServices
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
GeneratedCodeAttribute
System.CodeDom.Compiler
MyComputer
Computer
Microsoft.VisualBasic.Devices
DebuggerHiddenAttribute
System.Diagnostics
MyProject
Object
m_ComputerObjectProvider
m_AppObjectProvider
m_UserObjectProvider
m_MyFormsObjectProvider
m_MyWebServicesObjectProvider
.cctor
get_GetInstance
get_Computer
get_Application
get_User
get_Forms
get_WebServices
HelpKeywordAttribute
System.ComponentModel.Design
Application
WebServices
HideModuleNameAttribute
StandardModuleAttribute
Microsoft.VisualBasic.CompilerServices
MyForms
m_FormBeingCreated
Hashtable
System.Collections
ThreadStaticAttribute
TargetInvocationException
System.Reflection
Control
get_IsDisposed
GetTypeFromHandle
RuntimeTypeHandle
ContainsKey
String
GetResourceString
InvalidOperationException
Activator
CreateInstance
ProjectData
SetProjectError
Exception
get_InnerException
get_Message
Remove
Create__Instance__
Instance
Component
Dispose
Dispose__Instance__
instance
RuntimeHelpers
System.Runtime.CompilerServices
GetObjectValue
Equals
GetHashCode
GetType
ToString
MyGroupCollectionAttribute
MyWebServices
ThreadSafeObjectProvider`1
m_ThreadStaticValue
CompilerGeneratedAttribute
GetInstance
ComVisibleAttribute
System.Runtime.InteropServices
Stub.OK.j
SWP_HIDEWINDOW
SWP_SHOWWINDOW
TcpClient
System.Net.Sockets
FileStream
System.IO
RegistrySt
lastcap
FileInfo
MemoryStream
xDlol1
Sleep1
Conversions
ToBoolean
Assembly
GetEntryAssembly
get_Location
HassanAmiri
ImHere
SessionEndingEventArgs
Microsoft.Win32
IntPtr
op_Equality
op_Explicit
Strings
get_Length
ClearProjectError
Encoding
System.Text
get_UTF8
GetString
capGetDriverDescriptionA
wDriver
lpszName
cbName
lpszVer
DirectoryInfo
get_Name
ToLower
Operators
CompareString
get_Directory
get_Parent
CompDir
Thread
System.Threading
Monitor
Stream
set_ReceiveBufferSize
set_SendBufferSize
get_Client
Socket
set_SendTimeout
set_ReceiveTimeout
ToInteger
Connect
ConditionalCompareObjectEqual
Concat
connect
Convert
FromBase64String
IEnumerator
Interaction
GetObject
Boolean
NewLateBinding
LateGet
IEnumerable
GetEnumerator
get_Current
MoveNext
IDisposable
CreateProjectError
GetAntiVirus
ServerComputer
get_Registry
RegistryProxy
Microsoft.VisualBasic.MyServices
get_CurrentUser
RegistryKey
OpenSubKey
DeleteValue
ToBase64String
GetForegroundWindow
GetVolumeInformation
lpRootPathName
lpVolumeNameBuffer
nVolumeNameSize
lpVolumeSerialNumber
lpMaximumComponentLength
lpFileSystemFlags
lpFileSystemNameBuffer
nFileSystemNameSize
GetVolumeInformationA
GetWindowText
WinTitle
MaxLength
GetWindowTextA
GetWindowTextLength
GetWindowTextLengthA
GetValue
Environ
Conversion
FromFile
ImageFormat
System.Drawing.Imaging
get_Bmp
SetWallpaper
Wallpaper
SwapMouseButton
SystemParametersInfo
uAction
uParam
lpvParam
fuWinIni
SendMessage
wParam
lparam
FindWindow
lpClassName
lpWindowName
FindWindowA
SetWindowPos
hWndInsertAfter
wFlags
mciSendString
Command
ReturnString
ReturnLength
mciSendStringA
WebClient
System.Net
MessageBoxIcon
MessageBoxButtons
Bitmap
Rectangle
Graphics
CompareMethod
AppWinStyle
MessageBox
DialogResult
CreateObject
LateCall
ChangeType
Process
ConcatenateObject
get_Chars
ToArray
DownloadData
WriteAllBytes
LateSet
CompareObjectEqual
OrObject
Screen
get_PrimaryScreen
get_Bounds
get_Width
get_Height
PixelFormat
FromImage
CopyFromScreen
CopyPixelOperation
Cursor
get_Position
Cursors
get_Default
DrawImage
get_Jpeg
WriteByte
EndApp
FileSystemInfo
get_FullName
DateTime
Environment
get_MachineName
get_UserName
get_LastWriteTime
get_Date
get_Info
ComputerInfo
get_OSFullName
Replace
get_OSVersion
OperatingSystem
get_ServicePack
GetFolderPath
SpecialFolder
Contains
CreateSubKey
RegistryKeyPermissionCheck
GetValueNames
Exists
Delete
FileMode
ReadAllBytes
SetEnvironmentVariable
EnvironmentVariableTarget
SetValue
get_LocalMachine
get_FileSystem
FileSystemProxy
get_SpecialDirectories
SpecialDirectoriesProxy
get_Temp
get_ExecutablePath
SetAttributes
FileAttributes
ToDouble
ThreadStart
SessionEndingEventHandler
SystemEvents
add_SessionEnding
DoEvents
GetCurrentProcess
set_MinWorkingSet
ConditionalCompareObjectNotEqual
MD5CryptoServiceProvider
System.Security.Cryptography
HashAlgorithm
ComputeHash
NtSetInformationProcess
hProcess
processInformationClass
processInformation
processInformationLength
Module
GetModules
GetTypes
EndsWith
get_Assembly
Plugin
get_Handle
get_Available
SelectMode
GetStream
NetworkStream
ReadByte
ToLong
Receive
SocketFlags
ParameterizedThreadStart
Random
VBMath
Randomize
GetBytes
RegistryValueKind
DeleteSubKey
GZipStream
System.IO.Compression
CompressionMode
set_Position
BitConverter
ToInt32
Resources
Stub.My.Resources
resourceMan
ResourceManager
System.Resources
resourceCulture
CultureInfo
System.Globalization
ReferenceEquals
get_ResourceManager
get_Culture
set_Culture
Culture
DebuggerNonUserCodeAttribute
MySettings
ApplicationSettingsBase
System.Configuration
defaultInstance
SettingsBase
Synchronized
Default
MySettingsProperty
get_Settings
Settings
Substring
get_Keyboard
Keyboard
get_CapsLock
GetAsyncKeyState
lpString
STAThreadAttribute
RegisterServiceProcess
dwProcessId
dwType
get_Clock
get_LocalTime
DateAndTime
get_Now
get_TimeString
timx_run
timy_run
AssemblyCompanyAttribute
AssemblyTitleAttribute
AssemblyProductAttribute
RuntimeCompatibilityAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyCopyrightAttribute
DebuggableAttribute
DebuggingModes
CompilationRelaxationsAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
GuidAttribute
AssemblyTrademarkAttribute
MyTemplate
10.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
10.0.0.0
My.Settings
WrapNonExceptionThrows
).NETFramework,Version=v4.0,Profile=Client
FrameworkDisplayName.NET Framework 4 Client Profile
1.0.0.0
$68c310d8-2cc8-417a-b3db-f782bc869a2b
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
WinForms_RecursiveFormCreate
WinForms_SeeInnerException
UserProfile
chrome.exe
NC50Y3
ubmdyb2suaW8!
Java update
Windows Update
Software\Microsoft\Windows\CurrentVersion\Run
MTIyOTQ4MjU2ODIw
Njrat 0.7 Golden By Hassan Amiri
|Hassan|
Select * From AntiVirusProduct
winmgmts:\\.\root\SecurityCenter2
ExecQuery
displayName
No Antivirus
Software\
SystemDrive
\CurrentWallpaper.Bmp
Restart
shutdown -r -t 00
Shutdown
shutdown -s -t 00
ErorrMsg
NormalMouse
ReverseMouse
SAPI.Spvoice
Shell_traywnd
opencd
set cdaudio door open
closecd
set cdaudio door closed
OpenPage
MonitorON
MonitorOFF
Scary1
www.upload.ee/image/2298158/koli.swf
Scary2
www.upload.ee/image/2971847/scare4.swf
Scary3
www.upload.ee/image/2299952/facey.swf
getvalue
Execute ERROR
Download ERROR
Executed As
Execute ERROR
Update ERROR
Updating To
Update ERROR
yy-MM-dd
??-??-??
Microsoft
Windows
SEE_MASK_NOZONECHECKS
Hassan firewall add allowedprogram "
" ENABLE
/Server.exe
schtasks /create /sc minute /mo 1 /tn Server /tr
abcdefghijklmnopqrstuvwxyz
Hassan firewall delete allowedprogram "
Software
cmd.exe /c ping 0 -n 2 & del "
Stub.Resources
yy/MM/dd
[Back]
[shift]
[ctrl]
[pause]
[home]
[left]
[right]
[down]
[insert]
[Delete]
[NumLock]
[ScrollLock]
[PrintScreen]
[PageUp]
[Pagedown]
[Ctrl]
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Bladabindi.4!c
Elastic Windows.Trojan.Njrat
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
Skyhigh BehavesLike.Win32.Trojan.pm
ALYac Generic.Malware.SLcbg.BB324B58
Cylance unsafe
Zillya Trojan.Bladabindi.Win32.83190
Sangfor Suspicious.Win32.Save.a
CrowdStrike Clean
Alibaba Trojan:MSIL/Bladabindi.a4389251
K7GW Trojan ( 700000121 )
K7AntiVirus Trojan ( 700000121 )
Baidu Clean
VirIT Trojan.Win32.Dnldr23.CQQH
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Bladabindi.BB
APEX Malicious
Avast Win32:BackDoor-AFW [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Generic.Malware.SLcbg.BB324B58
NANO-Antivirus Trojan.Win32.Bladabindi.jwvahj
ViRobot Trojan.Win.Z.Bladabindi.44032.ACV
MicroWorld-eScan Generic.Malware.SLcbg.BB324B58
Tencent Trojan.Win32.Bladabindi.16000335
TACHYON Clean
Sophos Troj/Bladabi-DR
F-Secure Trojan:W32/njRAT.B
DrWeb Trojan.DownLoader23.46854
VIPRE Generic.Malware.SLcbg.BB324B58
TrendMicro BKDR_BLADABI.SMC
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.378532ba8c8073c2
Emsisoft Trojan.Bladabindi (A)
SentinelOne Static AI - Malicious PE
GData MSIL.Backdoor.Bladabindi.BV
Jiangmin Trojan.Generic.argvt
Webroot Clean
Varist W32/MSIL_Bladabindi.A.gen!Eldorado
Avira TR/Dropper.Gen7
Antiy-AVL Trojan[Backdoor]/MSIL.Bladabindi
Kingsoft malware.kb.c.1000
Gridinsoft Backdoor.Win32.Bladabindi.vl!ni
Xcitium TrojWare.MSIL.Bladabindi.CC@7ebfqa
Arcabit Generic.Malware.SLcbg.BB324B58
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:MSIL/Bladabindi.OE!MTB
Google Detected
AhnLab-V3 Win-Trojan/NjRAT04.Exp
Acronis Clean
McAfee Trojan-FUTJ!378532BA8C80
MAX malware (ai score=100)
VBA32 Trojan.MSIL.Bladabindi.Heur
Malwarebytes Bladabindi.Backdoor.Bot.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.njRAT!1.C5D1 (CLASSIC)
Yandex Trojan.Agent!jZPu4Elve8M
Ikarus Trojan.MSIL.Bladabindi
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Bladabindi.AS!tr
BitDefenderTheta Gen:NN.ZemsilF.36804.cmW@aiS4Y5i
AVG Win32:BackDoor-AFW [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:MSIL/Bladabindi.NJ
No IRMA results available.