Static | ZeroBOX

PE Compile Time

2022-07-19 03:00:44

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003cd54 0x0003ce00 7.99130680434
.rsrc 0x00040000 0x0005ad96 0x0005ae00 3.09966986643
.reloc 0x0009c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009a210 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0009a6b4 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0009a74a 0x0000045c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009abe2 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-%&+/+0+1t
+(+)+*
-%&+/+0+1t
+(+)+*
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
,'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-,&&+;+<
&&+-+.
+*+/u+
Im@R%y
&5QT[X
@*I.Yz
L>]3r=T
haqM-
X#>p[('
}-;oO3V
hr8X`vS(j
i?`!?r
"|Eb6L
D<:[DY
j6H|UXf
dD5xl
2-8a3e
'h5{y]
gL<-N
||%u8]a
cb_lb_
&*9&*5
+Y0}<D
}O.a.#
"Cn4}J[
0=Xj2Xnz0
OP'q"A
_kH^`U
HGP{2k
`OU{)\
H@4~&D
Z$$%WD
=A,?j2
s?*w.J%
L?KH&c
Lu*LM
O%&Mne
,U}zNDL
C8NIU@
`=%,DH
L0/oeP
@.K\>v,
~KSL"T
mNzo^oC
{_qJTX
{Xhl@J_
DKm5`z=
^yz4S,
k|?-8Z
hhu;fme
~,faB,T
;X#{an
k}5oTr
Sos3w$
4n!~x:
/j4k7n
~[h]&;n
Lh>oc_A
|13&:$
M[AY"B2
s$:1Z?
kpAP;~
` Q65u{5
ZN C"44
s'Mkx O
GxgI!OZ
1(2IW=
$~hQl/
Z*`TPR
ubR?Bx
d*ZP9#!
%`|KfC
8(N!8Q
1X1$J7
073$)c
+u=q;o
X{}L8.!
3D[jhT
fYb1XA
Ywlq>8R4
,}g&Z;|
2p_82|
?D2vHK
=x\iQ3
-q'*;K
;?b%Y|
Urd}MiFk
A`$K8b
yP}:R(
wT/<]t
76/MpG
g<%jt
d'Ug6C
j^+aUVq
F^6Xk u
Uz|yOl0
&-_ Ct1*
'4wCXx
Pj~%Z/
M4)e/9
Qa;;K(
XmoV:Fm
})kn{q
kR$l9=
6n6GE/N
J#@C)8~
qNVy8-
JYIW%R
TNAK>#
b/!F9A
)we[!
8/T2t
pUVkbr
t}N(]Q|
GUs{3Y
b!=*nEN
.KS*ZW8ui
MUguNu
>gu^hQ
y5dZN}
B2U{#\S
{v$K:x
)!&"+v5|Z
rx!dAS
xYBU|c
@nZgqG
}sSj=S
stk)Z(
n>>y }
{A)y3]x(
gfc!`bj
'J7*xC
RWCwB<
uiI5V|
=o#a3'
1\E_v%
_iMwO{<c
\'tcTs
k1Lj~dS
Tc-7o\
{ U+Qgw
~bAQ$9
5@lut}
:`nICUfu.AG
:.n`@_
' 7QnI~
HyCm^;_
wvvc(2m
@AaP*XN
a!n4/z
xsvXw9*,
UDQ)<[
QO!sQ*
c1qYp}|c
W6U]mG
(k+&CB
Eg"M4o
z`~_w|
5'=`]%
5E'&."
'u`L'n
+V L!40
CXTmO%L
q-JQBp
>`9K/*5
yDSFC
|60#le
lZa7w-
p'+#"_
mPv"1$
TS3oN
,da^qY
1[n).=
P7u{2,
!&BuKf
K#{6:%+
}BeB67
9?!$@H
!]8|d>
B]d$`T,s}
P%fBcf;
xd[GT< {
tl`df$nl
g:h"M4
[O)FRy
WLI.3
-W=Wyv{0
[OX/07
BKE2`R
JJa@VU
H91Q1V~0$
$)Vf Y
:diptM
IiMyy;
z<}Q_V
MD(&)?sz9~3_
je#\Yk
7.>9ra
xL!]~Y
zbB]'FDlIM
pP2zBZ8d
T?v@eD-mJ
q?p@SxG
-?(ySL
:w+`yW
c;Zk\&j
1s8/>A
/SA)/a
t j2w)
(!|:h|
[H SJ4$d
l?]YO:
xw.7khP{O
t>,AWm
kn?PK|p
/DJR2\t8
^ MDfZ:
ZY,h!SS
!;O?bH
p#tg*T
#qf&C>
n0K[PXMD\
`C.ydg
~0Nv%3a(
zI`)Fv
Bd@Dq!
K+5j_4
%xs1{0
vCnv%S
kMY5"=
r>ut*<
~0v5c!&
*"J*&@
{YbHG\
V1X/_qT
IosR&}
|qx9&|W~
@8rT^$6V
e\4K;Y3
y|E^E&
bL6Ek[
nbG)K'
6S/uiB
wPzpIQ%o
Q[]}E#
/W0)2
n`1m[?
v9J'wj
sL`A!ZP
*3+pQ&
q]Wu'=
f:ps%a
\=[hZ=
_3UF5f
~Yj]B0
$sWrN8
Hx271A
C'</"*
b=;4~Lh0
[HM*tr
1{tK,6
zgULLd
:3h@[_
x%}/%C
zPkAWN4+
owOUN$
`\lyF]
cH8QiD
o=,Fw8@
Q<1_J6
K%=`pM
xjQME:
O.%s>W
]a"G4E
i,{I V(
-FQ_Ng
oQ`FXz
hYVI9y
Q3z7au
,\LUfG
> 82 [
)9)[{{
]iLs9d-
o!9l<QAO
H{LCIk
"(h@[y
A36Mmf
V2=1'S7
As2eFi
."NwO&8b
Pn:Gdo.
@Xd"6d
!uPU=
j$}:')
qly^{6
&=lVLP
z)'WcE=
fFYEd4
Mj$Kfc
$b[9W&
qP3u1jBF
t8OU\r
j}u>4k#:1
dig(zG
C3lZ;ZI1O
LlKcXH
H>-:\
D:ct\v5
t-}wa>~
Q,Qg]S
h:jFxq
kg7{_$B
YfJ0_OdN
X(_?hCS
?ZLip$
RF+%Yb
y'^'2K
`=.a*P
;pGJs\
LD&mN3
_UePN(M
c!jrlY
N^KrfWR
f-y#o}I
n#UExm
dpq/UuC"
wtzS9s-+*
0?$=>~B
d'pO:I
~sEl"@
hwE4|(
SPL[ I
DPmD8,
^LTv/Lz
")M8Cj
h9R=/N84
Kt~b-1
xAw3,0Pj
6rdDI&
!,'r/.
Gm?e1x
Oq+.,<
}\kt+p[
n66)wg
\sdR
~R=:6?
]ZxK[LY
uw}<{K
\7ty~UJ
^V$*;Y
Qx%gx]
=x Z8.e}
Xq8^@G
`4p'p
3P~(E=
7KFrT?&r
Ty!YBe2J
o;Su+I
-n4~F
3J?*.(
<C/D;8
c-#j9F
a283{'
7,zl:s
r^bn^l
%joccM
|W$OARa
.k\17!#
oH~e0O
$wO9"
>!<%4&
2gT8,<*
P}H-GX
sW.iK41
lBJum$
jklgK"N
+iN$R{
V61|pU6F
fy+yIkgn
QfQfQfQfQ
2\w?q-q
zdeNSV
Zi<e")xx
@BNY<Gs
;q3r!W
#cL3sy
8,:r i
q70N\
lR_8XQ
<8'dL*
^\Ghb.
l`3TjBiMi
eVVVUJ
%^.Y=V
/rUr' ,
+{F4J
v4.0.30319
#Strings
Oxdmnmj-OLD-2.exe
Oxdmnmj-OLD-2
<Module>
mscorlib
ValueType
System
Object
Settings
Pusyr.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
EventHandler
ResourceManager
System.Resources
CultureInfo
System.Globalization
EventArgs
.cctor
AssemblyTitleAttribute
System.Reflection
AssemblyFileVersionAttribute
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
System.Core
ExtensionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
DebuggerNonUserCodeAttribute
System.Diagnostics
GeneratedCodeAttribute
System.CodeDom.Compiler
CompilerGeneratedAttribute
STAThreadAttribute
Pusyr.Properties.Resources.resources
Delegate
Combine
Interlocked
System.Threading
CompareExchange
Remove
Invoke
MemoryStream
System.IO
Stream
CopyTo
IDisposable
Dispose
ToArray
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
WebClient
System.Net
DownloadData
Component
System.ComponentModel
Assembly
Action
MethodInfo
GetTypeFromHandle
RuntimeTypeHandle
CreateDelegate
DynamicInvoke
Convert
ToInt32
Console
WriteLine
GetMethod
GetType
get_Assembly
SettingsBase
Synchronized
Netio Unattend Generic Command
10.0.17763.1697
$7b8b4855-9580-4b5f-b53a-51afb1da1c2d
Microsoft Corporation. All rights reserved.
&Microsoft
Windows
Operating System
Microsoft Corporation
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
a8"D6
001w111
555u333
667l444
111[222
111`111
DDD`HHH
444`555
+++`+++
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`---
---`,,,
---`///
667`>>?
445]222
656S444
000@000
>>>B@@@
333B444
+++B+++
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B---
---B,,,
...B000
666B99:
545<222
888&999
222'222
,,,',,,
---'-.-
---'---
---'---
---'---
---'---
---'---
---'---
---'---
---'---
---'---
,,,',,,
...'///
556%667
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
Yfriakxpfxegwneoet
Wiuklarhaavawtccjeftm.Msiregm
Pusyr.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Netio Unattend Generic Command
CompanyName
Microsoft Corporation
FileDescription
Netio Unattend Generic Command
FileVersion
10.0.17763.1697
InternalName
Oxdmnmj-OLD-2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Oxdmnmj-OLD-2.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17763.1697
Assembly Version
10.0.17763.1697
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Crysan.m!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.61188936
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
Skyhigh BehavesLike.Win32.Generic.jm
McAfee RDN/Generic Downloader.x
Cylance Unsafe
Zillya Downloader.Agent.Win32.483161
Sangfor Downloader.Msil.Asyncrat.Vio2
K7AntiVirus Trojan-Downloader ( 00595ccf1 )
Alibaba Backdoor:MSIL/AsyncRAT.aa2d63a9
K7GW Trojan-Downloader ( 00595ccf1 )
Cybereason malicious.b0c476
Baidu Clean
VirIT Trojan.Win32.MSIL.EV
Paloalto generic.ml
Symantec Trojan Horse
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MQO
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender Trojan.GenericKD.61188936
NANO-Antivirus Trojan.Win32.Crysan.jsirgj
ViRobot Clean
Tencent Malware.Win32.Gencirc.13baf92b
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.DownLoader45.6497
VIPRE Trojan.GenericKD.61188936
TrendMicro TROJ_GEN.R002C0WGM22
McAfeeD Real Protect-LS!414DC5EB0C47
Trapmine malicious.high.ml.score
FireEye Generic.mg.414dc5eb0c47614a
Emsisoft Trojan.GenericKD.61188936 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Backdoor.MSIL.furk
Webroot W32.Trojan.Gen
Varist W32/ABTrojan.OYBG-2756
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan[Backdoor]/MSIL.Crysan
Kingsoft malware.kb.c.1000
Gridinsoft Ransom.Win32.Sabsik.sa
Xcitium Malware@#2gojgvjb8pbnm
Arcabit Trojan.Generic.D3A5AB48
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
GData Trojan.GenericKD.61188936
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.C5212285
Acronis suspicious
BitDefenderTheta Gen:NN.ZemsilF.36810.Mm0@aerxYGf
MAX malware (ai score=88)
VBA32 Backdoor.MSIL.Crysan
Malwarebytes Generic.Trojan.Downloader.DDS
Panda Trj/Chgt.AA
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WGM22
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL2:M2PZusprHTrZ6lcWnnva2g)
Yandex Trojan.DL.Agent!ZiEEgoXXW6Q
Ikarus Trojan-Downloader.MSIL.Agent
Fortinet MSIL/Agent.MQO!tr.dldr
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:MSIL/AsyncRAT.NJ8PHU
No IRMA results available.