Static | ZeroBOX

PE Compile Time

2024-08-29 16:58:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000020c8 0x00002200 5.57517988756
.rsrc 0x00006000 0x0000430c 0x00004400 4.62231380951
.reloc 0x0000c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000075d4 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294507773, next used block 4294507773
RT_ICON 0x000075d4 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294507773, next used block 4294507773
RT_ICON 0x000075d4 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294507773, next used block 4294507773
RT_GROUP_ICON 0x00009bb8 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00009c24 0x000004c2 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a122 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+S+X+Y+^+c8h
++$o5
++$o5
-+.+/+4+5,
+5+6+;+<
,"+5+6
-:&+:+;+@+A,
v4.0.30319
#Strings
Jqsetgsuj.exe
Jqsetgsuj
<Module>
mscorlib
Object
System
EmbeddedAttribute
Microsoft.CodeAnalysis
Attribute
NullableAttribute
System.Runtime.CompilerServices
NullableContextAttribute
System.Core
DynamicObject
System.Dynamic
PoweredByAttribute
SmartAssembly.Attributes
MemoryStream
System.IO
NullableFlags
Dictionary`2
System.Collections.Generic
value__
StringBuilder
System.Text
GetUserName
advapi32.dll
Task`1
System.Threading.Tasks
Stream
CancellationToken
System.Threading
IEnumerable`1
GetMemberBinder
SetMemberBinder
Kjecxaigkrj
PropertyNameCaseInsensitive
WriteIndented
IgnoreNullValues
Properties
JsonConverterOptions
IntegerConvertBehavior
FloatConvertBehavior
GetDynamicMemberNames
TryGetMember
TrySetMember
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
AttributeTargets
DefaultMemberAttribute
String
Substring
Convert
ToByte
List`1
get_Length
ToArray
Encoding
get_ASCII
GetString
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
get_Result
System.Net.Http
HttpClient
GetAsync
HttpResponseMessage
get_Content
HttpContent
ReadAsByteArrayAsync
IDisposable
Dispose
Assembly
GetTypes
InvokeMember
BindingFlags
Binder
Thread
GetDomain
AppDomain
PropertyInfo
GetIndexParameters
ParameterInfo
MemberInfo
get_Name
GetValue
GetType
GetProperties
GetProperty
SetValue
TryGetValue
ContainsKey
set_Item
get_Keys
KeyCollection
WrapNonExceptionThrows
<Microsoft Windows Malicious Software Removal Tool (KB890830)
Microsoft Corporation
Malicious Software Removal Tool
Microsoft Corporation. All rights reserved.
$4fe96b71-8bc4-4b20-83a6-dae3a63a0f90
5.127.24080.1001
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5(
#Powered by SmartAssembly 8.1.2.4975
AllowMultiple
Inherited
AllowMultiple
Inherited
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
http://91.92.254.178/saphire/Kyrclzcw.wav
cIRtd702l
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Microsoft Windows Malicious Software Removal Tool (KB890830)
CompanyName
Microsoft Corporation
FileDescription
Microsoft Windows Malicious Software Removal Tool (KB890830)
FileVersion
5.127.24080.1001
InternalName
Jqsetgsuj.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
Jqsetgsuj.exe
ProductName
Malicious Software Removal Tool
ProductVersion
5.127.24080.1001
Assembly Version
5.127.24080.1001
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Noon.l!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal TrojanSpy.MSIL
Skyhigh BehavesLike.Win32.Infected.mm
ALYac Trojan.GenericKD.73960660
Cylance Unsafe
Zillya Clean
Sangfor Downloader.Msil.Agent.V614
K7AntiVirus Trojan-Downloader ( 005b9d061 )
Alibaba Clean
K7GW Trojan-Downloader ( 005b9d061 )
Cybereason Clean
huorong TrojanDownloader/MSIL.Agent.ade
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec MSIL.Downloader!gen7
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.REB
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
BitDefender Trojan.GenericKD.73960660
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.73960660
Tencent Msil.Trojan-Downloader.Ader.Vylw
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dldr.Agent.jxtgx
DrWeb Clean
VIPRE Trojan.GenericKD.73960660
TrendMicro Trojan.Win32.FORMBOOK.YXEH3Z
McAfeeD Real Protect-LS!A5A3902EDA13
Trapmine Clean
FireEye Trojan.GenericKD.73960660
Emsisoft Trojan.GenericKD.73960660 (B)
Ikarus Trojan-Downloader.MSIL.Agent
GData Trojan.GenericKD.73960660
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/MSIL_Agent.IMU.gen!Eldorado
Avira TR/Dldr.Agent.jxtgx
Kingsoft MSIL.Trojan-Spy.Noon.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D4688CD4
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Noon.gen
Microsoft Trojan:Win32/Leonem
Google Detected
AhnLab-V3 Dropper/Win.DropperX-gen.C5663716
Acronis Clean
McAfee Artemis!A5A3902EDA13
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.FORMBOOK.YXEH3Z
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Trojan.Igent.b2TQ8S.13
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Generik.BZNYUMT!tr
BitDefenderTheta Gen:NN.ZemsilF.36812.bm0@ayNRNzk
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Trojan[downloader]:MSIL/Noon.gyf
No IRMA results available.