Static | ZeroBOX

PE Compile Time

2022-10-22 23:30:01

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0047d004 0x0047d200 4.00100881451
.rsrc 0x00480000 0x0002ecde 0x0002ee00 5.35228572304
.reloc 0x004b0000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x004a975c 0x00004f8c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x004ae724 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x004ae7e4 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x004aeaf4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
,_+x8}
+ +%+**
-Q+T+U
-&+\+]+bt"
*4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C0103001CD453630000000000000000E0000E210B01300000D823000006000000000000CEF7230000200000000024000000400000200000000200000400000000000000040000000000000000402400000200000000000003004085000010000010000000001000001000000000000010000000000000000000000080F723004B000000000024005C03000000000000000000000000000000000000002024000C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E74657874000000D4D723000020000000D8230000020000000000000000000000000000200000602E727372630000005C030000000024000004000000DA2300000000000000000000000000400000402E72656C6F6300000C000000002024000002000000DE2300000000000000000000000000400000420000000000000000000000000000000
v4.0.30319
#Strings
server.exe
server
<Module>
mscorlib
Object
System
ValueType
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ConcurrentQueue`1
System.Collections.Concurrent
concurrentQueue
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
ObfuscationAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
Encoding
System.Text
get_UTF8
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetString
String
Substring
Convert
ToByte
Dictionary`2
System.Collections.Generic
Monitor
System.Threading
get_Length
get_Values
ValueCollection
System.Core
Enumerable
System.Linq
ToArray
IEnumerable`1
Assembly
Enqueue
TryDequeue
InvokeMember
BindingFlags
Binder
GetType
WebRequest
System.Net
Create
GetResponse
WebResponse
GetResponseStream
Stream
System.IO
StreamReader
TextReader
ReadToEnd
WrapNonExceptionThrows
Feature
code control flow obfuscationT
Exclude
Feature
string encryptionT
Exclude
$57f23597-b179-4381-8b16-c0aceeb94594
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6(
#Powered by SmartAssembly 8.1.0.4892
_CorExeMain
mscoree.dll
xoeNvne
wpfMd\T
wpfMvne
xnhLf_W
wpfMvne
W#^yeV3W
dLL1Fr
uljF2ov
N29sI'
A"K"qV
[AMfH
+^jeJ**
fj#yOrK
Tw8kQ{b
TkO,l#
2+Io4L
@$IN)=
'H_$L^
O_8D.)[
M"?_]!q
An'` N
;IDAT`F
s?6H`j
@' :Ao
E~%;Hv
*c`cB
W@'Jnvt
mk+h[[
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Oywfetegwtwhggcqznl.Wysgfnyeamwdvb
Rqbmwrlqkdbesbvit
n~AaQ1
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
server.exe
LegalCopyright
LegalTrademarks
OriginalFilename
server.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Scarsi.4!c
tehtris Clean
ClamAV Win.Packed.Msilzilla-9975992-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Clean
Cylance Unsafe
Zillya Trojan.Scarsi.Win32.6980
Sangfor Trojan.Msil.Scarsi.V8gx
K7AntiVirus Trojan ( 00599d751 )
Alibaba Trojan:MSIL/Scarsi.b8467c42
K7GW Trojan ( 00599d751 )
Cybereason malicious.88163a
Baidu Clean
VirIT Trojan.Win32.Genus.LYY
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.NXW
APEX Clean
Avast Win32:Trojan-gen
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Scarsi.gen
BitDefender Gen:Heur.MSIL.Bladabindi.1
NANO-Antivirus Trojan.Win32.Scarsi.jtezhs
ViRobot Clean
MicroWorld-eScan Gen:Heur.MSIL.Bladabindi.1
Tencent Malware.Win32.Gencirc.13b8fe5f
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.Inject4.45747
VIPRE Gen:Heur.MSIL.Bladabindi.1
TrendMicro TROJ_FRS.0NA103KK22
McAfeeD Real Protect-LS!FEA9E6588163
Trapmine suspicious.low.ml.score
FireEye Generic.mg.fea9e6588163a319
Emsisoft Gen:Heur.MSIL.Bladabindi.1 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Heur.MSIL.Bladabindi.1
Jiangmin Trojan.MSIL.anqsd
Webroot W32.Trojan.Gen
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Trojan/MSIL.Kryptik
Kingsoft Clean
Gridinsoft Clean
Xcitium Malware@#66540jfgaubk
Arcabit Trojan.MSIL.Bladabindi.1
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Scarsi.gen
Microsoft Trojan:Win32/AgentTesla!ml
Varist W32/ABTrojan.RZDA-9368
AhnLab-V3 Trojan/Win.Injection.C5285923
Acronis Clean
McAfee Artemis!FEA9E6588163
MAX malware (ai score=100)
VBA32 TScope.Trojan.MSIL
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Chgt.AA
Zoner Clean
TrendMicro-HouseCall TROJ_FRS.0NA103KK22
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Trojan.DL.Agent!2MKL9OGB7lk
Ikarus Trojan-Dropper.MSIL.Agent
MaxSecure Trojan.Malware.73692792.susgen
Fortinet MSIL/Kryptik.AGUP!tr
BitDefenderTheta Gen:NN.ZemsilF.36810.@p0@aqd1uxn
AVG Win32:Trojan-gen
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan[dropper]:MSIL/Scarsi.gyf
No IRMA results available.