Static | ZeroBOX

PE Compile Time

2022-06-03 00:40:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004e246 0x0004e400 7.99340609243
.rsrc 0x00052000 0x0000f1a0 0x0000f200 6.89912772168
.reloc 0x00062000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006062c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00060ad0 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00060b66 0x00000414 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00060fb6 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
,5+6+7+<+A
+&+++0+5+6
v4.0.30319
#Strings
CyptpaSPOOFER-3.exe
CyptpaSPOOFER-3
<Module>
mscorlib
Object
System
MemoryStream
System.IO
Settings
Fhhra.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
System.Reflection
Stream
HttpWebRequest
System.Net
HttpWebResponse
.cctor
Culture
Lxiohtkwxwdav
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
get_FullName
String
op_Equality
WebResponse
GetResponseStream
GZipStream
System.IO.Compression
CompressionMode
BufferedStream
CopyTo
IDisposable
Dispose
ToArray
Exception
WebRequest
Create
Func`2
InvokeMember
BindingFlags
Binder
GCHandle
GetTypes
System.Core
Enumerable
System.Linq
LastOrDefault
IEnumerable`1
System.Collections.Generic
Process
get_StartInfo
ProcessStartInfo
set_Arguments
set_WindowStyle
ProcessWindowStyle
WaitForExit
GetResponse
set_FileName
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
Windows
installer
Microsoft Corporation
Windows Installer - Unicode
Microsoft Corporation. All rights reserved.
$a36dabf7-33bc-4adf-b068-0b8d04a5c229
5.0.17763.404
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPk/+S
TfW(+V-U
^MeTl}
(`jZk<
MJw`:NP
,KJN#r
0@qA|=o
;&~_r}FS`d
rZ?`\x
V6b<fv
u9.xPw)
+=/<=W/
3xK#2~H
X;3Q(rk
'%&%6%.%>%!|@T2
F?'c",
S:"!yC
#L }P#
)o@?z[
#"BXTV?
y}W('n)O
5yN&3uot}M
RNw>6?z
_>CSxl
1T_<zFXFe
1.8#M`
8N{]A
^q6CO~
gslekW
)GxcpXWs
LjC>@Ap-Y.
K, 9:&Jv
YfOsM[,
8;E?d=#
[HOZ,V>
/yJPF1
is9`U{
6*dX:#NXU
7Khh/U?c
4W*Sc9U
*g%/3W
*Hw8+A
khvcN]
nwZ>m?
@t{+[4
[i{)nGK
SDE0{&'
2[<Q1+'j
{B^I2O
8h]dgUe
yV?~UG
q${l<|
{[y!eQ
e<K}:Y
jLb\_w
eU0_Fa
"Mk-AG8XaD
Vv.;r4
.8zfpabS]
*'u{plG
^;}1*
Gwcvq
nF<Wlw
W[~{(
C954d<
'Y<@["R:
[L`|.&
8J(#D~6x
^?*$NDb5
kb Xk&
.xx8iEj
o.>fNsA
B",f',h.(
9u_DMZ
HtKZ5.
oiiZm(
BSG4&C
,iv]Y?
CTwG*7
jX;jK6}SH
)"*g>2
o6\XX#
\S4jV0h
y,J8?~
WT75w!
9LI4s>
23TB=8U
{;\e{
yj}v[Z
/\9KFi
S+57r
BZVsxb
*![zau
?[22:W
0ZlSw}
IU?=z}
{Oo[i0
^@k}j:
c4NiS_
~=KpOeXk
5}QP:w
=bU|:l
#9ktW;
mpQ8-y'
Mj.ffe
&1?fmm
"6?CZg
l$9/)j
%fow-T
dv,l1i
CbT!1=
}),c6?
}K}\(f67z
;-,cVA
3mL#b~
_L5wU8
sK}C(`
7{&\b6,ql3N
iMpI9*
7?3gi.
VHj.ff
*@,d60
,dv'w7
Okr'%sAM-3
Yj+=7z
jd>G>}
t %Ml:
(}xdI8f
+6?gy0j
8 ^w}s
1NRyn
AiM.*UY
zKRTeVF
Iu)KIi
^,(\)!&
^J332j
LMnc>i
V99}o&"
2|\YXN
#!igkL
lA,~,bH
!i{{P<
5#D'CMT
dRIGvl
#$V@qap
ZlN:Vh
RUGU]X=i
<x/ -8
_Z6Bx5z-
M(Db)8K
GyIj6#4
@a_Sqr
-YM)P/
iH$7rx
y*ga$e
R)H:5b
\D`Oag
h$*#Xb5
UJT5P/p
dZX.j#
GMbOT5
8T7^::qlx
u ?4^
pY,[w;J
`B0#d
#8 8"p
z[&DAP
j6imGZ
\+G1gcy
q%Caj<S4
#T!T#|D
h4l1r!}3-
LF3 tfXOH
?A&$n"
~>8"bX
+v#[G0
gFnYRy
jGT_)|
_|;>:w
?aLXmE
6~_|foc
vG>yz4
ZUQjND
Vio:?r
3&5N[6
9LWMLP
#[u=f{+1
w^6kj'}
)ivh([
-cR;H:
jLIqg;
w+NOk]~@t:k
MOxtB!{
[Q0}Nf
vWk.}o
d<|Pac
13L^D
8X\Vf^
+ZdDTw
we~t.$?
]*oLXU
=[}PBD
8.ntsV
X8?8%8
loB'xt
tXT{jY2
sox|N~
I`We+*0
}G23yl,
TG<MZly
vp9\p6
oht`DW
3jVA"_8
j8(kx)
4K"V"5
DVq|lnW
,f%Kb5\
YcjG<OA
3+3dOvL
7x`K9&>P
vSttul{
&-v+Uk
I5<!kx<U
^j=,En
aM\C+i
QAE*]Z)
9Ts9vo
Ei`RP^y:
Xs\$g
|]L_JB
7yU'.b
?4O5|/
'e]OR]
O4PXV~
#&7pCsp
Qk<U7{
iwnN3z
PWu=~-_
Vik()2
NR_{yKN
QET*zg
%/0fu1
BoaFa&
T=;i)v
zLrjLV
9CP,>C
!=R)UN
u=U]Uu
OC:WGan
F06KByo
:stR!J1Y
"SI$3&
H%z,M|
Hk8]#J
Hb)?n*
1qc>9N
pWG6on
6 .26o
+Ph/yl
(UZWSy
P"czl
>#eE6}<SiK
e($OR:
`nWHgs
vgafCg
hKI:yS
QQ{cBz
g>}~gx
eIWb(_E+A
hRX)B>9
!nW^W
0p(/SD_
4@v`XOTJ
aHX4,
}-O4qZ
@r3,JW
%b)k[J
}Xh.;
,?CK$~
(\x[v!
(dutF N
']}T+V:
\1m+cO
ovh)lk
g$3b[v
)O6F,l
4HM39t
KpwwwY
,/{9NK.
.Rk7Yb
d#%Q7\
TF4(L3
Sh[Lh>
CMAgb{
:vS#|F
5HY\l,l
6Zf.6q
rW%$(8v
O]Dc>K
=-=d)8
d)QV)m^
M{HTQg?p
K>9+_kx
e{V!5?
+lhF6Y
p'R4YAV
B]'oMzW
/u=&cR
Q~6U~f
S,x}lK)+:
JBofmu
Ilub7>
qU\o8e@
a=46`C
u6TAu"
kw?Ue{
;<F.XE
J7q<z$W
&m>=9S
0!m{`U
cr\P7d
$4/No!
.XUEX~
E:c$Q~$]*
"MmNOzz
O.=(slo
6!opo2=
:R}oA.7
s~7k|9^
uJytCW
&G J2<
{x"ObB
eJNjTg
24#h{x
%Vd&Udi
;Kie?B
@ja}:R
K>c]_c
;-<6-4
J.'!9}[
aNqovA
:Z!>.:
&--lh<
l=p2)k
K*<YCv
l"Lj~4
Ns+0hy4
ahOcVO
`qk> ;
AH<^sU+
7qaD{\
2<cAR:D
D0? 57
^WKW[GS[
uu4uu):
O4<wPDp
N<wmf6
~nz(|e
^dldh3
^_{N{uXH
(y4q4Y
lZozcS
{@vF|z
<xn_n{n].?N
'x{0aZtz
DU2LZg!
T/A;x%\
?ntrnqO<.
q~93"S
yr[Jkl
*~J8%2
R}LjeU
(yAi~c
T-kW7y
GU3|nG?
/~Sw[I
ImUx#@
<:.VG/}
ZY^KSm
l|K-?l
T^[O_[
l}MJfl)
.+c=Ll
2%}c#a
F4}3t{
YN8w>u
mb5t*)R
9w9^I
d6WZ'G
D,v#]/
PK[6'.b
3}gJTd
@=/zT[
"cz/]S
lo="VFf
0obNaf
3'34:X\
TNnyEN
[RQ\>h
e{EyIY8
opIq~!
@Q`6!g
#3b))*
5W/HZu
^S;>9V5qU
MLK 4_
3T9yIz
e#LHWzp
j NX&t
is_{~Q
((@E5;?cJ
"^P20e
N_?/N=
^b8bbj
BRo2UR
ij6I2c
-UpQYe
%wc>cS
iytMC`
WPYLl8
teP#.5
MRE0-6
H}Wn<.
gxx}dR
zLF(4o,g
3UTY!6X
!O)8aW
Qqm`6Y
il|"b
_[&_+W
iUnJL$E~T
E$;=|D
$&"l>(f)
*U)7:d
Qj<sg!Z
(()pYX
$I:{xgH
C|}Q1$D
`PXj&cL
-jli%[
4{{+"
N5-0nFL
2HyvTl
mt6LAk4>v
;nQ<D,
X'-0q^
CX-GLP
ubIK&~R
[4y4}Lu*
J|;C_YD
0q4Zk
+!pLlriDV
%aIr[]2]
4U^q+=
]N}3&IMR
t/|O\_
k^R+Cn
sSY>:}3
!LOG1Z
,8Thu2Ae
*#C3oQ
yID{at
f`v:w^
cC"O67B
c5&mR*}r
+2*xtl~
`aa%R#
5E:kfeI@
7u0!a%}uAt*E
kD[3OR
J7;AUbC
u^"_Kf
pDUB2Nd
Ds+D>(
WeZW9'
O8pfu<
U$SIC6
,uej`f
cx,OUPX
w2|aGB&
%3HlU;
)+5~}w
_WWWWWu
7v.;Kc
#</.$7
etI~#*Oq'
8n>faN
!0to+cL
:`Y"AG
U#_A54
vA2?5K
'EEjd6/
_%(qgX
.x$BBB
'6j[g
'gK{;1>
;1cAA#~
91#;sE
0gS7rr
.l3K'g0
a[[agg #
``WQa75
Bku#^'
tDy+v"
XF[/<?k
'Z/$lr]
P2I3qj
[o?'x;
[}8JWF
V2muzU_
o7V^Ht
-!!%rq
#tree5K5
nUzdBB
|&XA!9
'3Fp<YK
z}Fozi
J&n7ej>L
Hdi3|A
J6[yf(
->pFtC
bfu#[nh
0u.l7?
8dfii!
FZ1s%J?Qa
pW*6#U
r73{(T
g#r5nM
lV|I'Zs
ox300H
iC^av
Mugcs#G1p
jnmy0NB
ww#A<x[
2bP=_f0
G5c%mG
ChMe/
[_zEb|
KCJJB=O
39Jq6$
0H|h#<{
-11VSQ
G`U2a7e
r,?HLA
n+p]v3
mW7$3L
B11QjX8
'mdvgg
eUUUxh
V767F&c
p`0p
e]RI),
d_E;j\_
EH(R\z*
uWj%cI-
JmffFp
_zXl]B
^`7^$9I
2={&vm,W
]^^)oii
x$L|<p
B+> mM$
!wKWOq
9j]TL>
u#%@n(
pei4EF
NnLLe2n1
9dF,UKL
W1*j)B_
W_7FLdr
C6f,f"
4))Y<.
.,i2f
oe)8~Q
`f{,nd
-~h%<5
2@H7;"y
[nifVUD
1fe[}{
KH$>W+
ilQ3W
@quUcr
z}y)c-
oyDy7^g
*|VV,$
=t{4Y2
i[d|7z%$
n8L+{D
@]W`g'
01'JC3.
[^tG;j
h`5+tW{&
v*d^C{
jW))#`
C[(,\C)
Q3m]Sr
+r^3y
b8vGT>
DWV&*u
mt~npZ
_CorExeMain
mscoree.dll
5<^(D$
zO%)u%
7>+0vK!
J4`I!v
!p=jF@
K0P"_`
uC1o8x
Jjn,_$1
$V7(Of
CE*-8q
gv,d~RS
o18?L9
IDATJ])
>bP+8zF
?_ehTr
KnC3?ex
,Nifib
7qG1p@
>DU_|,
'PU{6Vl
()wt'6~
)ERYmB
Y5>`hTp
H/~OwG
e(p=fW
&(ieSh
p`sU3vS
TbqR1?
Rbu.db
Wc}Y1{Fr
Ks2QqJ
ZcS)E~y
:c0w3O
[4H?X
Ra'^z!E
+?(V?+
0`Hw!A
{!0mHMX
v2P)E#
0`gSQ{\A$l
o>uIml
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Lxiohtkwxwdav.Sywzhe
Oyqxxfedsgrvgpwi
powershell
-noexit
Lxiohtkwxwdav
Lxiohtkwxwdav
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Windows
installer
CompanyName
Microsoft Corporation
FileDescription
Windows
installer
FileVersion
5.0.17763.404
InternalName
CyptpaSPOOFER-3.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
CyptpaSPOOFER-3.exe
ProductName
Windows Installer - Unicode
ProductVersion
5.0.17763.404
Assembly Version
5.0.17763.404
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.MSIL.Crysan.m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MsilFC.S28419780
ALYac Gen:Variant.Lazy.194548
Cylance Unsafe
Zillya Downloader.Agent.Win32.481330
Sangfor Backdoor.Msil.Crysan.Veol
K7AntiVirus Trojan-Downloader ( 00593ef61 )
Alibaba Backdoor:MSIL/Crysan.b0a3474a
K7GW Trojan-Downloader ( 00593ef61 )
Cybereason malicious.ab4859
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.MBD
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender Gen:Variant.Lazy.194548
NANO-Antivirus Trojan.Win32.Crysan.jqhtcu
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.194548
Tencent Malware.Win32.Gencirc.13ba351e
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.Inject4.35093
VIPRE Gen:Variant.Lazy.194548
TrendMicro TROJ_GEN.R002C0DGL24
McAfeeD Real Protect-LS!568785AAB485
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.568785aab4859695
Emsisoft Gen:Variant.Lazy.194548 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Backdoor.MSIL.ftnp
Webroot W32.Trojan.TR.Dropper.MSIL
Varist Clean
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan[Backdoor]/MSIL.Crysan
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.D2F7F4
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
GData Trojan.GenericKD.73607926
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5053895
Acronis Clean
McAfee RDN/Generic BackDoor
MAX malware (ai score=80)
VBA32 Clean
Malwarebytes Clean
Panda Trj/Chgt.AB
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DGL24
Rising Malware.Obfus/MSIL@AI.98 (RDM.MSIL2:TbdMBWQscwF75bQid3lGIQ)
Yandex Trojan.DL.Agent!Xsz6SD5lsuo
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.74418669.susgen
Fortinet MSIL/Generik.BZNYUMT!tr
BitDefenderTheta Gen:NN.ZemsilF.36810.xm0@a0tnepf
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/Agent!MH.VAS
No IRMA results available.