Static | ZeroBOX

PE Compile Time

2023-05-03 11:26:49

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00130948 0x00130a00 5.84445474213
.rsrc 0x00134000 0x0000056e 0x00000600 3.99664435175
.reloc 0x00136000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0013405c 0x000002ec LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00134384 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+++0+1+6u
v4.0.30319
#Strings
Web-Source-2.exe
Web-Source-2
<Module>
mscorlib
Object
System
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Tbhsuy
Sepdygup
Qrahwmr
Culture
Mtrwamrdydguboisbuw
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
System.Core
Enumerable
System.Linq
IEnumerable`1
System.Collections.Generic
Thread
System.Threading
GetDomain
AppDomain
Assembly
Reverse
Encoding
System.Text
get_ASCII
GetString
Action
GetTypeFromHandle
RuntimeTypeHandle
Delegate
CreateDelegate
get_Method
MethodInfo
MethodBase
Invoke
String
Concat
GetMethod
Convert
get_Assembly
GetObject
WrapNonExceptionThrows
$d13f4cf0-b79d-4ca8-9435-e8bc103b52a3
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
#Powered by SmartAssembly 8.1.2.4975
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADEcAAAADAAOUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADAALgAwAC4AMAAuADEAAABuAG8AaQBzAHIAZQBWACAAeQBsAGIAbQBlAHMAcwBBAAEACAA4AAAAMAAuADAALgAwAC4AMQAAAG4AbwBpAHMAcgBlAFYAdABj
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Wfkpablyunizoflgtccaqct
GetExp
ortedTypes
FromBa
se64String
Mtrwamrdydguboisbuw
Mtrwamrdydguboisbuw
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Web-Source-2.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Web-Source-2.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.PsDownload.a!c
tehtris Clean
ClamAV Win.Packer.DotNetRev-10003973-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.tm
McAfee Artemis!017FE34B7A5A
Cylance Unsafe
Zillya Downloader.PsDownload.Win32.2533
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005a4dfa1 )
Alibaba TrojanDownloader:MSIL/PsDownload.ff45e337
K7GW Trojan ( 005a4dfa1 )
Cybereason malicious.b7a5a9
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AISZ
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.PsDownload.gen
BitDefender Gen:Heur.Matrioska.6
NANO-Antivirus Trojan.Win32.PsDownload.jxdmfp
ViRobot Clean
MicroWorld-eScan Gen:Heur.Matrioska.6
Tencent Malware.Win32.Gencirc.13cb6eb4
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen2
DrWeb Trojan.PackedNET.2004
VIPRE Gen:Heur.Matrioska.6
TrendMicro TROJ_GEN.R002C0DGL24
McAfeeD Real Protect-LS!017FE34B7A5A
Trapmine Clean
FireEye Generic.mg.017fe34b7a5a9767
Emsisoft Gen:Heur.Matrioska.6 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Heur.Matrioska.6
Jiangmin Clean
Webroot W32.Dropper.Gen
Varist W32/ABTrojan.BEAU-6919
Avira TR/Dropper.Gen2
Antiy-AVL Trojan/MSIL.Kryptik
Kingsoft malware.kb.c.1000
Gridinsoft Trojan.Win32.Packed.cl
Xcitium Malware@#3efu99totnjt0
Arcabit Trojan.Matrioska.6
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.PsDownload.gen
Microsoft Trojan:MSIL/Nanocore.ABYL!MTB
Google Detected
AhnLab-V3 Malware/Win.Generic.C5438026
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36810.mn0@aeBjXEg
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Generic.Crypt.Trojan.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DGL24
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:ShvHXX4yNuslA6iE8JPAog)
Yandex Trojan.Kryptik!eqx/6Jq+zQk
Ikarus Malware.Win32.Injector
MaxSecure Trojan.Malware.73750922.susgen
Fortinet MSIL/Small.R!tr.dldr
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[downloader]:MSIL/Nanocore.ABYL!MTB
No IRMA results available.