Static | ZeroBOX

PE Compile Time

2022-07-19 03:02:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00042850 0x00042a00 7.99116019703
.rsrc 0x00046000 0x0005876e 0x00058800 3.44897286785
.reloc 0x000a0000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0009dc3c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009dc3c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009dc3c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009dc3c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0009dc3c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0009e0e0 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0009e168 0x00000416 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009e5ba 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
,%&+/+0+1t
+(+)+*
-%&+/+0+1t
+(+)+*
-'&+4+5+6t
,'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-'&+4+5+6t
-,&&+;+<
&&+-+.
+*+/u+
<Y(R=#
OA>HJXmW4
r?h18)
M1@4|FY
GkZAJz:
=A~-{+
o@N|4yS
Y_M8
=UL>;k
7{e`,p
:rRJVJ
={O=b%
DTtB2,
iR"\h&
z4ov;mr
8*g5)/1
.}i!WG
M4/M+5
D+aIs+
BZ4rYy>
N}'8F.
.L hE&
'7`8cNAK
FB=X*#f
|d7\R\
A\89%w
g8W7Yx
b#&g'R
so9s)f
sA35^AF
W]6v$M
pw<j?u#
Q(4Vk:
bbbAp0%
x$"HG(
$|$]hx
b8Lv#x
@@pYS
Hd&wy4
4 SB[F
X/brfZH
Rp\l|G
uIuYu:
v2<kS
Xv: p
3!\A6/"
>VUShs
OD}X{r`
;~?rsW
8&S/T.Qy
c,1w{r
;Z5q"Pe
J'7Po-?
l(+QiO
:[:cj~
!6+gANC
F}Qjlu?Y}`
y]?MbSU
puoo^g
56O>JR
cQK7{H
,[9j=y
p'mdDj
U}f?P\W[
yV7]T7
Ny5&>\
zH$LXTb_
k=q.lmC
C?D=1oUV
~)a>3^
x'SIZO
6ZHmP_s
]apu20
B0`io x
_Qr< 7
R=NTVn
n56kf/v9 |p
*lYqI&
o'FSS-
OBx-KF^
}#d"Hc
ofgw"Q
_gx2S}Y
3@Y~K(
nW1%)J1
rAVU98
Q42=?3
lGf8~(
\;64$0
D{'MG8
w2R_5HaM
]bMuL;
;nzGvWcv
Ej"}c"/
c%nzmZ
n/-z>\6
^.5t(e
0PK:_5
5\=7JHf[
JjE@{G
{=]y9]$?
I{6<{(-
[R've]
~gc,2R
P1<U;A.d
deN6
Hr:Ua
Q@rM[[
c}\\Q/
C8by6IfO^
X2Quf:
WeKbB7RE
gOKQe_l
naLez<Y
~3,B%t
k>B>4+\
KwQII+/
ca%hQy9
,l~J]|
84cZcl9zDz
5~%g a
kl&)Ou
oJ]v+2g
UGWBUC
swMh],
~u}GZg7D3
#XnPk3
fJstxj
eKHtkkm
|ss1zN
c^p'BX
TmP$d<O
D(e:J5
UlL2-y
~h*pDQ
9$:BB5
O9t9Gm
_WoBUa
R)Pt(d!
u9{q^8&
A3U>R{P@t
F]w <$
!uyIX9
Gc,%f
||EQLT
|dIpLk
TENkql
+Q~o%fc
9X9+F|
[Id#$q"|
e:MQ_[
[{htXe<
omDbWR
&w1 ?2
T=*[&4
2_[$dMV
|~?]?,y
l>eSu
Ss;fHu
a$/7cy
_D1NL/
Ts,SJ^
".7P/K
/)~T*<u
?6`4$-!u
iKohw]b
B:rFOP
@\GR"4X
bS>{BE
2YZT.'
ymp4)J
WS|9e;
?xz?bC%
-dB7}-
Vw>4)w
;`wZGZ
(vRuz!
aH{.70V
3q|u4<a
;)y;x?
6!9nVz$
lA/t?|
qm^BKeY
s3!.<wg
'|VDa
1WG*5)
"Gy10<<
f*M"y3
]%VB',
+cw;O;
k s3:F
ppPiAI
y1%iuY
#iM(c\U
+Gm[h6
b0B5s3QFT]
^lcMhVQ
LQNLe}
ab^q~R
myZHo"v
ma9^9}
( xxY@zc
Fm~Y}{sF
<mkdSN-
2DOaYs3
$X3}.Y
Sm~Zd
-=N*z/4
^<##Nv
;_`y*jX
2V{Fx
o4dOKF
PBTfR9
LRAyD)
:QB*}0
/&8|b*
Ux-@$c
g+ML')M
9Y0Cl|fFe1<uD
[AaH<r%
Sxei-@
0iH&g$
$Z<w6C7
'>uQ~h
:'"M`~
)&zh26
;N0xrgI
qu .XXOu@
r;8*fC
*z74{|p
IG7s;]>N
3q?yPK
;}-Z[+
stE)G>
GJ.21
P%_YC.#
RN7dtI
+x/yy_O
PYW0yO
\._Y5=
iG0?WN
m[&*]v=
'B)wK
*FD.]a
spO9"&
hx:ZX$
|H`d3=NhS
;/5+Mm
PtF41v
@4ZPr|
#\G0\;P
@%C>^xz
Xu):!z
( 3>D'
&Ls x
Z${wKO
YJ}!_j
=h"-zo
hUF5`M
mQ"L=BPz
J(06gKD
^5rb]vSC
\28PUu
G%u |Xx
j.y:dE
-T+Y|0&/2
7A_|s1
.Z(4%t
1Jw/{8l*
bU/#)oq
>fEa!ko3
tP8|,3)
aib@6l
',+)Z;
tgg'*cI
4v}eSs
VW`%$:
Y&>.9T
Rr\7w1
p77oo=
lh[ik.]Vy
8rAHV
KN:,/&
JTEAmI;
gmAx&]p_>
hD&TE9
MXVO<v!j
bp[i&S
hnRumj
\jnUbk
5hK{OZ
K.1zP_
!Q;"n[
-AtvAp
+846enV
K&9?"1
3wyK)~O
}!y&$O
D&BnM\
BW._[b
4l;KV)
EQX[$f
]zmYMEg
#,sG5''@#
smC13d
<[1+^6t
!_g9{oQ
}Lx7U=@
H3ni7Le
n6=66o2Fhd
/0/,3B
||[M3F
R6*@OC
vZ?m#A
rW>S-x>
T5jCl~pT
|?P@6Gr$
7f6i=6
zA[#,r
[hwnA1<
IU(<fQ y
loxd`A
)nK63-
AEd`3/
-l?)Ty
~%GOH+x
h2Ms7J
U#fJt"
`jPcl'
cRL095
&k6)5U
e)*VbV^
ZLIvb_n
Uxi,IW
r_W[[<if
-=:<eX
VG)sYeZ
+XmF`aV
{>U=B2
P;`:p+
Gd["Yx
z@:SKq5
bI4 :$
&I;j@O
op<NXN
7b5*De
GoU!t/
Q'dogR
5"F_GI
NL)S"
w205EG`
e:`akYb
vo.9Md
9C)aiF="
e1L0O[
<=Ci0ut
cjr-Xa[
]0+z+O
6Nikz6
zI'aGU
',+6Z0
+6Jb}i
E,NBNs
8yh;b?
Jb1'c
O=QJyh
%]KgGx
94\yPc
4f:Gr
N=|PeI
2kb<A37
OkL'*oa
#UI*Eg
99={V\$
^Ckvu9[
PhUCCX
sgoxu)
iF[(z$Y
Jqy0,t
g+4wGbP
aIOid4"AI
SSU'Q%
B+P&:
\5!aVv
^M5lyF
/}@#A5
$uVSkH
vR+X'!07
5NSsHM
_.fS.')n
:R;CUUO
~$]K$]K$]K$
-y{4oIN~
w.(NN5
}AvKMvm
}AvKMvU
uC}fo+2
Lm-YbLmm
nU!.?"GN
>iV;#
!*[ixCUMP
qV=;IW
:^x4{p
9rCO>G&
tXE!k(d=BX
s^M!k(d
X@,#~@
B!a<vM8
8>qJbS
$^'`Cg
Qp%l4+
:kX~uu
/t9*<^
2+X"W~o
4OE~y9
-!=HSw
Qc|L=&
p5b|\!
Z<o,b\a
5}T('?
|YRzs3
"l&l!l%
$\EXEXMXC
@*TOjHpZ
v/B`#f
Wp?5bM
Sf\N7B
qlI;Is
v4.0.30319
#Strings
Oxdmnmj-OLD-3.exe
Oxdmnmj-OLD-3
<Module>
mscorlib
ValueType
System
Object
Settings
Pamahd.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
EventHandler
ResourceManager
System.Resources
CultureInfo
System.Globalization
EventArgs
.cctor
AssemblyTitleAttribute
System.Reflection
AssemblyFileVersionAttribute
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
System.Core
ExtensionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
DebuggerNonUserCodeAttribute
System.Diagnostics
GeneratedCodeAttribute
System.CodeDom.Compiler
CompilerGeneratedAttribute
STAThreadAttribute
Pamahd.Properties.Resources.resources
Delegate
Combine
Interlocked
System.Threading
CompareExchange
Remove
Invoke
MemoryStream
System.IO
Stream
CopyTo
IDisposable
Dispose
ToArray
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
WebClient
System.Net
DownloadData
Component
System.ComponentModel
Assembly
Action
MethodInfo
GetTypeFromHandle
RuntimeTypeHandle
CreateDelegate
DynamicInvoke
Convert
ToInt32
Console
WriteLine
GetMethod
GetType
get_Assembly
SettingsBase
Synchronized
Device Properties
10.0.17763.1
$4925510b-9a48-4425-8b69-1926057e5d51
Microsoft Corporation. All rights reserved.
&Microsoft
Windows
Operating System
Microsoft Corporation
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
Fiineibz
Ajiaphistgh.Olpdaviuqayhdnyvwvkzobe
Pamahd.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Device Properties
CompanyName
Microsoft Corporation
FileDescription
Device Properties
FileVersion
10.0.17763.1
InternalName
Oxdmnmj-OLD-3.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Oxdmnmj-OLD-3.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17763.1
Assembly Version
10.0.17763.1
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.MSIL.Crysan.m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
Skyhigh BehavesLike.Win32.Generic.jm
ALYac Trojan.GenericKD.61185467
Cylance Unsafe
Zillya Downloader.Agent.Win32.482564
Sangfor Backdoor.Msil.Agent.V2zd
K7AntiVirus Trojan-Downloader ( 00595ccf1 )
Alibaba Backdoor:MSIL/AsyncRAT.b5411c77
K7GW Trojan-Downloader ( 00595ccf1 )
Cybereason malicious.2d6988
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MQO
APEX Malicious
Avast Win32:TrojanX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender Trojan.GenericKD.61185467
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.61185467
Tencent Malware.Win32.Gencirc.13becb21
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.KillProc2.18203
VIPRE Trojan.GenericKD.61185467
TrendMicro TROJ_GEN.R002C0DGL24
McAfeeD Real Protect-LS!7F8B6CD2D698
Trapmine malicious.high.ml.score
FireEye Generic.mg.7f8b6cd2d698880a
Emsisoft Trojan.GenericKD.61185467 (B)
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.61185467
Jiangmin Backdoor.MSIL.fthp
Webroot W32.Trojan.Gen
Varist W32/ABTrojan.QFGY-1285
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan[Backdoor]/MSIL.Crysan
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Malware@#3vmga84lcnx6n
Arcabit Trojan.Generic.D3A59DBB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
Microsoft Trojan:MSIL/AsyncRAT.NH!MTB
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.C5212285
Acronis suspicious
McAfee RDN/Generic BackDoor
MAX malware (ai score=87)
VBA32 Backdoor.MSIL.Crysan
Malwarebytes Clean
Panda Trj/Chgt.AB
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DGL24
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL2:p1BMZZGcvHaTY1W/bDy9cw)
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.74418669.susgen
Fortinet MSIL/Agent.MQO!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.36810.Mm0@a8dXAop
AVG Win32:TrojanX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:MSIL/AsyncRAT.NJ8PHU
No IRMA results available.