Static | ZeroBOX

PE Compile Time

2023-11-05 06:31:13

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000464c8 0x00046600 7.98849628591
.rsrc 0x0004a000 0x00000556 0x00000600 3.91443662692
.reloc 0x0004c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0004a090 0x000002cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004a36c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x4484c0 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
alMX=#
V]@wxd
.$N'ZP
xCpi+e
,?)oFs
x9+d#%
iE0z)=
!<8: S
uj,Tt_
bnt~o$
e/OWY$
~]'5yxi4
mEU;W;
PIu2V
JG]>O
j=G&oH
C8Z^p<A
+CvG]e
6 gg%"|
lq[*eZ
'eKl5_*
mlEeg[/&
~nEP/*
a3P@*-k
}*!B/G
k.J1Kx
2+n m>4TI
RMaZzD5
JZ}fx
K5x`H6
%IKmGo
$,BmA
p&$D-\
_zCg>m
7*5LdQ
p0YQnkJ
+');na
'VSKS&X
IqX<ErAq
7#`RiUR%dW-
A|E'pJ
lY[%)-
6 5"%$c58
gohGTj
'|tI2M
CaxM=8
P+w8OA
OevL5p
uHGi(=
`&A95(
9 D7kF
3acrYI
t={eew.
M^&i3p
8s,Hp5
P2EUrk
@S`*8l!
4JfS^&^
?-AfU <W$qC=;6
U5*yLY
CkX;dW
*\nk3b
6` A`d_
Clb")>
,q f*H
$Q{#?B
H$Im~4`
XJyDiBx8
i;(1yE
4%^Ui
8!1q15
*OPJ#`C
La-LKt
URxDj[
>2mvNL_`
Qnq2/a6`]
'nwP.v<2
M_m .eA
:.Q.@W4Fb
1+fBYw
fxAY[m|R{
Pz(t~vfB
BLkH50
&+\1]$
~~iZUG
@$c V#|2
mC{ZzY
*h.>K/7
Kwkl9A
B;D9?w
??]wM>
agj;i!X
Cw5<9.$
YJ}6b"
1&yOT@
fB)\d
w,KlDbp
`CzxTI
B}K1'd
:xy#;m
Cwbx#=
ORZ=FV
cl Dod|
y+?1;tN,t
.Pji;:
GS,FW3
_R2.|!&s
&*pz9A
sZ]^(Mi
4o7AM=,
_dB^6R+Jk
$[_t=h
^T ?bB
*s{`+f
bbRe8tvNy
a8&7i K/22;
ehI'Mk%
n_T"~R
K0r{_+
d@h Ig-
6[|t3"`
Ejt_vo
r&uB^,
/=skRR
OPdfojn
dW:"VrTs
*hf)$z
6jcK'5
V`w 1G8
#bNo"X
yE1>y+
Dc"IiD>
x$^ry?^/
v.wGxIq
]{ZmWy
U"_LF\
Hr!oFF
k/'j%dL
WU4Z$\
P+?\vX
PSqW@
82^kK
!k9~N(
~~i9Uh,
\([_Fo
X[^}|"
cm~j4GwzQ`c
A'U8<"
:_}j=C
)&j6ZEm
,`C*Kq
(PNR8t
M^&/l1
GR^`
VO2K_#
3w>{oeJ
bufBBS
$qe6ay
A]OLk
`)j'kG
x>w@cc
%cw/>4
Sx1zGa
tjeR.
cwGg3<
r_w8JZ
()bz^p
/)'E.ei.,
h_"t)3a
2EDq6s
_&>C0=q{
6:id 4
,6}{Sz
Y>Hlp
vN4+(L
n[F`AI
pA{1Y<Y
veZ\SW
hZ,~i
)~$nMX
KLStqEc
~'6B]u
/U*FW
#wkObi
)SuVlf
/lz@N
mBD>Z!
W{Gfib
9R+gsa5
y?4gJ:.
(JQZ?
pSFpP]:}
IT9$}QE
`>!Q:s
&hw(P
y{U91r
]mD&`U
kd4ahC
[:/4qPb
nd` r(
8v{_Ukb-
~#Z;Zd
33iSHQ
[2_KT2
iJ+8^_
$jb!5}
~ %=lvGux$[
y -5n20`
hll{]M
2aX"jy
L{{0e0
/Z(L,B
9vuN|Cc6_
pX\#S4>
[{e-f#
zi74~T
P,KnuO:Q
{T$EG<
,3|-FC
YOFgMw
B?2<5ms
~`IU[6
3m,9s:
4S8oKd
y5%=WL
X:%ys1
)L$$tK
jDh=mO
+tdSCJ
y_,64L
QRaWE/
;r7vII1
E'K6PL
rwL[P{
pVSW@z
M?RMfml0
Y9#^uN
B;-M\h
2&ka@#O[
X@!CxW
~/iNYy
cas~^H
kPNS:r
lr=)rH
GL89$G
2s!eG}
j1 5bV
Ii!ow!
D"sT]9
hR0dAp
.qUju>
9>@:td
c!2b;'
Ase$!h3
pM8++Mm6
vjhlAL
cZy-&9
4kLub
)i<b[|
|^!EZ9
lY?;=N
4p3%)]
<Q4>CL
,x7D &T
!yI^]a
d.}*Xk
JU&+.R
}9o$
'$,bt/
g/Bh7
;O2SU=
>0 ,Uu
8eSFEE
wfP{M5iD
@95T"8_
>U*6<W
4MCa[x
/%4!2x
}f(D2!x
rA:7H
;A2f2%\c
In@d!u'
|*{d^/
4^Nhaed
qcGIXf
b"jg.t5
ST`L>oY
)pV#se
3K- H
P7gjp
Wj+PRo
p.O&L
ws$D0K
ToYRj'
zY-*<@
|qkkkV
CJ3%pB[
;O)m$C
MINwo3<,
mO+~nE
!m_dB/<
AmFs{+a
WE5JbC
x5 gap
ah!5f4
.X,w1H
:- AvjE$5
^1B^0RF
zeGy=]
>N`W7K
avM\h<
V1&DET
a{'"X9
-~1M}(
2_:Vc;
yhZ6o0
Wn(,RP0
/[no!1
k,4_.>
MX;P`@Ygq
.VvU,y
P~Y:f
8ij`H/
e-fGK
t0lkMX
POO;h:
.0gchOJxY4
ZNh9p[5|$
)\e:*)p
?d.C#5
^!'M$
qhCt%g
c.M62
Fv\GyE4
awRJ1~:
s=RO-]
a`^)k?n`/@
<z{HCl
.zlkj,
z6 #)|#
MvyMvQ
w6L{<'
ARg~ I
0KM2& #'
>g#8g*
!/tM o
_WX)!Uf
jHRN|i
u-""tJ@
$e7_2gU
*PX<vd
sEaoPP
"UsCGa
TD5,f}>
'*=UfVF
D)NRWS&k
sb;mg[Iz@u
5Q@5w?5
hrMD]CR
SP(@GM-
Qx._B\
i:&"s.
kE)k$O-
J>Qp>>
ukGQ2q_
1!b=z8
Ne3oB 9W
)V33^<
mvL_`d
u)KvZ+
m#R*L|
i)i[@Q
S7QZPSy
zGZ\Ys%
JR9@D%
k&R%"H
QJgD}^Of
6:}_Rn"
jpHKRx
5;xuQM
I8fb>{
/"%q~V
x.ot_GQ
+J&{l6
8TvzRZM
j*\7FTuL
o4^j4p
Z kYdO
\+g7{C#
5_-$s/
(x&?h!
*0(U%JZ-Ty
@B3ChJ
2A$Lc
/rk]H]
oLGdmV
).&a.J G
:!, fg
7R^D!'
&RXf^Z
8i{%6]}
[_:vr{B
3s-m{~
2H8;m*L
6o@>qo
%G :-T
+_4r~Ud
vc_z&C
wP_P9<#rF
Ar4PQn
%OvyoO
Ar2gv=.K
L::9b`s
"f``lP
%kY~"
VB>>&LK
u}$x=aq#
>!r6*.
@$H2K58
)bR~U,
-S*[wM'
n04gty
/?#I$2
4e4/GV
yIrUc/
ZsbCBn
R/p|qz
/smMA-
"ZUU_7R
vk0|,J
>fq};9h
[Dc(#h[
[-NUBH
s3Rq632
nnw}.$
Zs3Z="K
Un1/\]
|^7ahE;
f=JeA_
`C"p(:
r4fF
j8Hq4PZ
f4]h57S<
?^2W*UmW
dO.OZ2
eR*eJ6H
v4.0.30319
#Strings
rjiorge
resourceMan
resourceCulture
buffer
<>1__state
<>t__builder
<>8__1
<>u__1
<key>5__2
<tdes>5__3
<iv>5__4
<data>5__5
<>7__wrap1
<>4__this
Myvscypy.Properties.Resources.resources
Hfeiowf
Lgirjog
<Main>
Wegfijrg
.cctor
get_ResourceManager
get_Culture
set_Culture
get_Jlorjj
<Hfeiowf>b__0
MoveNext
SetStateMachine
Create
get_Task
GetAwaiter
GetResult
GetTypeFromHandle
get_Assembly
GetObject
get_IsCompleted
AwaitUnsafeOnCompleted
SetException
SetResult
FromBase64String
CreateDecryptor
CopyTo
ToArray
Dispose
GetType
CreateDelegate
DynamicInvoke
Eflbu.exe
stateMachine
ResourceManager
Culture
Jlorjj
<Module>
Program
Myvscypy
Iioregij
Resources
Myvscypy.Properties
<>c__DisplayClass1_0
<Hfeiowf>d__1
<Lgirjog>d__2
<Main>d__0
<Gijrg>d__1
<Wegfijrg>d__2
<<Hfeiowf>b__0>d
System.Threading.Tasks
AsyncTaskMethodBuilder
System.Runtime.CompilerServices
Task`1
AsyncTaskMethodBuilder`1
TaskAwaiter
System.Resources
CultureInfo
System.Globalization
System
Assembly
System.Reflection
ValueType
IAsyncStateMachine
Func`1
Exception
TripleDESCryptoServiceProvider
System.Security.Cryptography
MemoryStream
System.IO
TaskAwaiter`1
Convert
ICryptoTransform
SymmetricAlgorithm
CryptoStream
Stream
IDisposable
Application
System.Windows.Forms
Action
Delegate
Object
AsyncStateMachineAttribute
EditorBrowsableAttribute
System.ComponentModel
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
DebuggerHiddenAttribute
RuntimeTypeHandle
CryptoStreamMode
EditorBrowsableState
DebuggingModes
mscorlib
Myvscypy.Program+<Main>d__0
WrapNonExceptionThrows
$2a617ce8-92ee-44de-8806-a2b6bd9496fd
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
Myvscypy.Program+<Hfeiowf>d__1
Myvscypy.Program+<Lgirjog>d__2
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
Myvscypy.Iioregij+<Gijrg>d__1
Myvscypy.Iioregij+<Wegfijrg>d__2
6Myvscypy.Program+<>c__DisplayClass1_0+<<Hfeiowf>b__0>d
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Jlorjj
Kxdmwnuee
Myvscypy.Properties.Resources
Jlorjj
2lmt+96dKe7oHzqdqSy4Hg==
L8cQFVaY7po=
Xlednizo.Gpyorxhl
4)@)NIYS`Iq
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Eflbu.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Eflbu.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Blocker.V!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.IGENERIC
Skyhigh BehavesLike.Win32.Generic.dc
ALYac Trojan.GenericKD.70328940
Cylance Unsafe
Zillya Downloader.Agent.Win32.532135
Sangfor Ransom.Msil.Blocker.Vfqi
K7AntiVirus Trojan ( 005aaaa61 )
Alibaba Trojan:MSIL/Seraph.7b20b139
K7GW Trojan ( 005aaaa61 )
Cybereason malicious.d0a34c
Baidu Clean
VirIT Trojan.Win32.Genus.UAO
Paloalto generic.ml
Symantec Downloader
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.PVY
APEX Malicious
Avast Win32:RansomX-gen [Ransom]
Cynet Clean
Kaspersky HEUR:Trojan-Ransom.Win32.Blocker.pef
BitDefender Trojan.GenericKD.70328940
NANO-Antivirus Trojan.Win32.Blocker.kdcxhb
ViRobot Trojan.Win.Z.Agent.290816.DL
MicroWorld-eScan Trojan.GenericKD.70328940
Tencent Malware.Win32.Gencirc.10bf4555
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
VIPRE Trojan.GenericKD.70328940
TrendMicro TrojanSpy.Win32.RACCOONSTEALER.YXDKEZ
McAfeeD Real Protect-LS!E3DC222D0A34
Trapmine malicious.high.ml.score
FireEye Generic.mg.e3dc222d0a34c4b2
Emsisoft Trojan.GenericKD.70328940 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.70328940
Jiangmin Clean
Webroot W32.Trojan.TR.Dropper
Varist W32/MSIL_Kryptik.KBG.gen!Eldorado
Avira TR/Dropper.Gen
Antiy-AVL Trojan/MSIL.GenKryptik
Kingsoft malware.kb.c.1000
Gridinsoft Trojan.Win32.SmokeLoader.bot
Xcitium Malware@#j3vguj7ddtkg
Arcabit Trojan.Generic.D431226C
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Ransom.Win32.Blocker.pef
Microsoft Trojan:MSIL/Seraph.AAUW!MTB
Google Detected
AhnLab-V3 Trojan/Win.Seraph.C5539329
Acronis Clean
McAfee Artemis!E3DC222D0A34
MAX malware (ai score=83)
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/RansomGen.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.RACCOONSTEALER.YXDKEZ
Rising Ransom.Blocker!8.12A (CLOUD)
Yandex Trojan.DL.Agent!lU08zmSeTcA
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.5913239.susgen
Fortinet MSIL/Agent.PVY!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.36808.rm0@amn8obm
AVG Win32:RansomX-gen [Ransom]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Ransomware:MSIL/Blocker.pef
No IRMA results available.