Static | ZeroBOX

PE Compile Time

2022-06-03 00:39:06

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004d124 0x0004d200 7.99439336274
.rsrc 0x00050000 0x00108744 0x00108800 4.98091962719
.reloc 0x0015a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005006c 0x00108028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x001580d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00158120 0x000003fe LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0015855a 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
,5+6+7+<+A
+&+++0+5+6
v4.0.30319
#Strings
CyptpaSPOOFER-2.exe
CyptpaSPOOFER-2
<Module>
mscorlib
Object
System
MemoryStream
System.IO
Settings
Mvqofew.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
System.Reflection
HttpWebRequest
System.Net
Stream
HttpWebResponse
.cctor
Culture
Fnlcpzagitscum
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
ToArray
CopyTo
IDisposable
Dispose
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
Exception
WebRequest
Create
WebResponse
GetResponseStream
Process
get_StartInfo
ProcessStartInfo
set_Arguments
set_WindowStyle
ProcessWindowStyle
WaitForExit
GetResponse
set_FileName
Func`2
InvokeMember
BindingFlags
Binder
GCHandle
GetTypes
System.Core
Enumerable
System.Linq
LastOrDefault
IEnumerable`1
System.Collections.Generic
get_FullName
String
op_Equality
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
ProQuota
Microsoft Corporation
&Microsoft
Windows
Operating System
Microsoft Corporation. All rights reserved.
$157c1762-1908-4d39-8bc3-59ed127efde7
10.0.17763.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP{
,\e,_Y:
Y9wI)eL
P=h$;m
>Ds$dT
%-FIq\R>
(\zwAM
Zpq`]V
M ~cM@
/kmSkPt
3kXjOt
)HO9S`=&-YO
ct}Ai?
~3dNBRH
f/=%3_
+@#k5\
KigQ7
k"DT_V6
HwCA:SX
x#Wvk2+6
os*22/
I;5fs=
0|Mx]
t(->-!-1-)-
>ou}Tu]
\Y.2:o
N9Ds0L@
^)Q<Dz
|GTg[
Msw VR(
O#?/F~O
1c8M~s
TRK{UR
^C%e6v
lmSYt]
^))`-k
\>!fE.U
9`3grc6
z[/p6
)5g.Q>
m=3ByCf(
yzF;g
VxmXX?Xu#$
BO2ou`
}v<7pd
jwkeeH
g wjO>
esS-E.9p
%Lty|Ay
]7%Pa~js
6>Pu(XaX
C70trlo
m\qshx
|n>eCI
r3=.c({
,O0|4m$
.qbIn:
Nu/i5"2
MctD{faH\
Klz3V)1g
L2<]&s=B
KSN%)F
(RnQ<l(
yzvA4W8
^T;mZR]NB
|_w{99
|NshYN
guN#y}
@=qft~
tw\p$o
hxN4ujQ
M9k~%n
3#WuU};
}4afyS*
^E70a`
N%2Al(+
:fYM!Xp
Bg<6-H
8hpGE2$
SDe&K#
mpr{#m
e|J.'0
6/p<z\f`
Xiboh0
/Yec\q
DZEsu=
^vSD4p
]rdg'.9p
+\f^cM\
mp?WF%
`XqQZnu
[\#%q+N}h
{]#.6
^(q|J~
$`S*q2
NFLw)S_
QJ[|7-
(JCdLYcq
]2hEWU7|s
u"bNF"
,0G.\?
wXm~$q
CuY!aK&
!FWU`D
)7'X`cD
1._L&:$
N( .)a
k|)9MQ
;Qj#3`
i?Co3Aa
I2m~6jcU
-MA^1j\Q
P7N^.]
$OP8n4
cEK7<`
mKU~.J{
aqL5)$
~hQSNZ
8I0=_t
F>l`e
Nx <zD
KR5KqW
9?JSg}4
>qlZ$z
O6X>%Yv
JGc6;7
vD}-kkr$Z
:(v0I:
RQn8R4A
Uo3Q>*
\YE|?B(
EXMY1x
S@W6c5`60
*p=p+p?
B`;`'`7`/`
<`}`C`
QJPJ,5,TL+M"|
%eEGM,3LK-S4MObbz
sqUy!_AM
r4r,r<
?r r0r(r
,C.A.G
0r*r:r&r
v{7iVlu{Yj7
!XN@&gO
\ {I!d
18C5YN
u)-6)-
u)}\;)
&:+p$r
=L`uh=
eDF*SY
9E_hWy
:kmmb_n
hmIqEL
Ier0_F
_OmMp\
d^M6&5
GXu:O$
F,g#x1Y
#3|Gs#
fsrzu:
+m=^ig
Odw1cjw1cnw1
_W(fTns
'/r;+mI~
Y>j'~;
qJ20QI
P<pHP>0%h
j,WAy|
!W#w O!
Xn@JSp
S`I<}D
/Vadga
03#?I
i\"gBa
!mEny@
tZ64Z5z
s}L]="O
TTK7M]SL
wDJ{:Y
,O(=&R
H;4q`5
cZ)Esl)
%|Y.is
hA:KfaCn
YWQoKW
`!t-jw[4
e;(3D|
\oEeo@
wHd[Ay
B|@~mDq
-$;16f
s|gf7:
2JZ!M[%*
!]X%ZXu
"dWs;p
un1+7h
.Gd-!U
e&ti^P
PG?CY0
>lAYhB
DY5MQ)WjF
Z5uIPI
Z1tCF)
?f\:?|
0NJ0WJ>
&{bQ0i!
VdOtuG5E
dOs==pT
c"LF/\Vx
=X8lMY
2nt`&2
Iiegso
'0pd 3
+!d!VA
3DkB5.
/Tlg@xy
x4G_=@
wvPkqmb
<try\Ef
MQm-m0
}\w_n6
?!S5%d
M&3dj|
|5v*v
_B_D={*A
7^dfwl
'O<-3X
_2q-Z'z
'=%r$8
WW+y]L9L
r~zv^1L
u$Uj)O,
n'WWNT
QE.+4[
/iv&K;
hStPoR_"~
Y'1"^I
M+k3C>[
tXT{jY2
sox|N~
I`We+*0
}G23yl,
TG<MZly
vp9\p6
oht`DW
3jVA"_8
j8(kx)
4K"V"5
DVq|lnW
,f%Kb5\
YcjG<OA
3+3dOvL
7x`K9&>P
vSttul{
&-v+Uk
I5<!kx<U
^j=,En
aM\C+i
QAE*]Z)
9Ts9vo
Ei`RP^y:
Xs\$g
|]L_JB
7yU'.b
?4O5|/
'e]OR]
O4PXV~
#&7pCsp
Qk<U7{
iwnN3z
PWu=~-_
Vik()2
NR_{yKN
QET*zg
%/0fu1
BoaFa&
T=;i)v
zLrjLV
9CP,>C
!=R)UN
u=U]Uu
OC:WGan
F06KByo
:stR!J1Y
"SI$3&
H%z,M|
Hk8]#J
Hb)?n*
1qc>9N
pWG6on
6 .26o
+Ph/yl
(UZWSy
<r%%W?
-\A4yx
i_wX+Q
~/J%_BwH
ppSppW7
pztqKiG
#73=Rc
{?M)(pq
*QwK(Tx
7v%6Aw
T-+8Cwl
M+,}Sf
lK4n4S
d1jPWp
5_,R"6
_u}5b=f
0-)$rlm
1])<0
:$OnL;
{"w!c&
.wE3SAc4Y
ky}5N;
{:cOs
h>% Ac
]O$e3.
k%~>|/
d"WM3Q
{YDZQw
@%:M?J
U~#VP,
4CiUQ_W
`$CIqz
\gJw$
(ig-^2
!=cNJ'
A+pP.HJ@:
.Qk7Yf
d%$P7\u(
eAvUSn*|
ho Tt+
Th[Ji>
\MR;Gd
9L]aNn=
'!l8@o
Q({N%
qp,,7O
CbaG!r
15-x>(
w`Dg-ne
+$iH1Bo
<1't8U
^TaRCin
wFEONw
c@9Q8v
e&Vm!O
S>1t#k-.
<Q^zr&9
Noa!NF
13x j#X
Aauh72
b~wWB#
Ed,%PB
qSKWwU
5bye7m
h71F}UEt
0A}R>
[zr8\Q:
v|shU%
GG3z+6
gOz)"*
^JZTz+<T
&m>=9S
0!m{`U
cr\P7d
$4/No!
.XUEX~
E:c$Q~$]*
"MmNOzz
O.=(slo
6!opo2=
:R}oA.7
s~7k|9^
uJytCW
&G J2<
{x"ObB
eJNjTg
24#h{x
%Vd&Udi
;Kie?B
@ja}:R
K>c]_c
;-<6-4
J.'!9}[
aNqovA
:Z!>.:
&--lh<
l=p2)k
K*<YCv
l"Lj~4
Ns+0hy4
ahOcVO
`qk> ;
AH<^sU+
7qaD{\
2<cAR:D
D0? 57
^WKW[GS[
uu4uu):
O4<wPDp
N<wmf6
~nz(|e
^dldh3
^_{N{uXH
(y4q4Y
lZozcS
{@vF|z
<xn_n{n].?N
'x{0aZtz
DU2LZg!
T/A;x%\
?ntrnqO<.
q~93"S
yr[Jkl
*~J8%2
R}LjeU
(yAi~c
T-kW7y
GU3|nG?
/~Sw[I
ImUx#@
<:.VG/}
ZY^KSm
l|K-?l
T^[O_[
l}MJfl)
.+c=Ll
2%}c#a
F4}3t{
YN8w>u
mb5t*)R
9w9^I
d6WZ'G
D,v#]/
PK[6'.b
3}gJTd
@=/zT[
"cz/]S
lo="VFf
0obNaf
3'34:X\
TNnyEN
[RQ\>h
e{EyIY8
opIq~!
@Q`6!g
#3b))*
5W/HZu
^S;>9V5qU
MLK 4_
3T9yIz
e#LHWzp
j NX&t
is_{~Q
((@E5;?cJ
"^P20e
N_?/N=
^b8bbj
BRo2UR
ij6I2c
-UpQYe
%wc>cS
iytMC`
WPYLl8
teP#.5
MRE0-6
H}Wn<.
gxx}dR
zLF(4o,g
3UTY!6X
!O)8aW
Qqm`6Y
il|"b
_[&_+W
iUnJL$E~T
E$;=|D
$&"l>(f)
*U)7:d
Qj<sg!Z
(()pYX
$I:{xgH
C|}Q1$D
`PXj&cL
-jli%[
4{{+"
N5-0nFL
2HyvTl
mt6LAk4>v
;nQ<D,
X'-0q^
CX-GLP
ubIK&~R
[4y4}Lu*
J|;C_YD
0q4Zk
+!pLlriDV
%aIr[]2]
4U^q+=
]N}3&IMR
t/|O\_
k^R+Cn
sSY>:}3
!LOG1Z
,8Thu2Ae
*#C3oQ
yID{at
f`v:w^
cC"O67B
c5&mR*}r
+2*xtl~
`aa%R#
5E:kfeI@
7u0!a%}uAt*E
kD[3OR
J7;AUbC
u^"_Kf
pDUB2Nd
w+(Mr
KzI?x-%
5~w3vp
1-E;bL
7}BLvn
.CI%^t~E
I8}l_qh
p5i!6sYN
dx\kdO
K=5n$%
L8TGYqH
Pwo/[0
G->A{a
;|4/x(
`BW+o(
eH\W+}w/
xAapvm{c0
XhD,.`
;7saqcY,e
B43L+_
QgcGT"l
K^f^;o
<)^X'y
,He\bf`
,n.p5Q
rSRml=
&tMuHS
4K%V_OQ
g@P%sK`
asaxCr
e$?FT*9
Fh8r}-
rx %"Q
LPMXKGu
rxN_uC
/\@$Y%
w}(JL![(5!
u![l6
)FgPA]
(/(5N
*|[I!P
IQ23m_@
X2kycR
[Gs9X
pw'bon
H[N.!7
Ws_oMG
-&fQBF
3WnG>q
X^V%%/N
.Oou{
voS?[I
%mAB#i
'nG?e
[F/O_x,u
Ow;i7rl
Z8p;ZF
a}vm}+
]q=P^N
'dc/li)c`f
_CorExeMain
mscoree.dll
"qtqZBFI
VVYvhkhd
qqnZ$3
z0yuyLY\YrLLL
Z^Xtz~zC
m!1sq#2
l9 (k7Jk7km7
p7!To8"
*k8!Vm7"
m9 ?m5 `l7!}m7
f3}k7
P,Le1
RPi|"$'
\*l^,
V&k^+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
powershell
-noexit
Fnlcpzagitscum.Qhsnobauxqhtklwaus
Zdpgvkupzvuzifidsa
Fnlcpzagitscum
Fnlcpzagitscum
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ProQuota
CompanyName
Microsoft Corporation
FileDescription
ProQuota
FileVersion
10.0.17763.1
InternalName
CyptpaSPOOFER-2.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
CyptpaSPOOFER-2.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.17763.1
Assembly Version
10.0.17763.1
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.MSIL.Crysan.m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MSIL
Skyhigh BehavesLike.Win32.Generic.tm
ALYac Gen:Variant.Lazy.194546
Cylance Unsafe
Zillya Downloader.Agent.Win32.483019
Sangfor Backdoor.Msil.AgentTesla.Vfkv
K7AntiVirus Trojan-Downloader ( 00593ef61 )
Alibaba Backdoor:MSIL/AgentTesla.eb345ac5
K7GW Trojan-Downloader ( 00593ef61 )
Cybereason malicious.e303e2
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MBD
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender Trojan.GenericKD.73607929
NANO-Antivirus Trojan.Win32.Crysan.jwopqv
ViRobot Trojan.Win.Z.Lazy.1400320
MicroWorld-eScan Trojan.GenericKD.73607929
Tencent Malware.Win32.Gencirc.13ba0eb0
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.Siggen18.28071
VIPRE Gen:Variant.Lazy.194546
TrendMicro Backdoor.Win32.ASYNCRAT.YXEGUZ
McAfeeD Real Protect-LS!E60B4A9E303E
Trapmine malicious.high.ml.score
FireEye Generic.mg.e60b4a9e303e2def
Emsisoft Trojan.GenericKD.73607929 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Dropper.Gen
Varist W32/MSIL_Kryptik.KER.gen!Eldorado
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan[Backdoor]/MSIL.Crysan
Kingsoft Win32.Trojan.GenericML.xnet
Gridinsoft Malware.Win32.Wacatac.cc
Xcitium Clean
Arcabit Trojan.Lazy.D2F7F2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
GData Trojan.GenericKD.73607929
Google Detected
AhnLab-V3 Malware/Gen.Generic.C4937160
Acronis Clean
McAfee Artemis!E60B4A9E303E
MAX malware (ai score=80)
VBA32 Backdoor.MSIL.Crysan
Malwarebytes Generic.Trojan.Downloader.DDS
Panda Trj/Chgt.AA
Zoner Clean
TrendMicro-HouseCall Backdoor.Win32.ASYNCRAT.YXEGUZ
Rising Malware.Obfus/MSIL@AI.98 (RDM.MSIL2:iLALzxVxFTrmv/NMEw1HUQ)
Yandex Trojan.DL.Agent!w7Tl3BsiwZk
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.74418669.susgen
Fortinet MSIL/Generik.BZNYUMT!tr
BitDefenderTheta Gen:NN.ZemsilF.36810.vn0@aSdWAph
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/Agent!MH.VAS
No IRMA results available.