Static | ZeroBOX

PE Compile Time

2024-10-01 07:12:10

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001ce94 0x0001d000 7.08951870487
.rsrc 0x00020000 0x000005a0 0x00000600 4.06339858931
.reloc 0x00022000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000200a0 0x00000314 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000203b4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
1)t'W+
dM<O'0
|5!,RC
y4A9p+t
H9wbh
|x%*Es
>:w>0v
+d$}5*f
l"MB${%;C
nw8`p@g
Wjg?HT
Y6dxZ!
~S^6Jlq
kJ6YG1
<EL`.V
nsXT]Al
;QY_!>
tQ4R@'
g((8_)
F$6YH"
;4beH>
=<_>R^;
//E5j'
"d\Bi
:,6J=$z
WQ}4^h
~(f~!>
1HxC*i
oKx;{3 m.s
wI+JRs8j4
JmGZk)
($U39hX
&o}'q>
*<:Rn(
9QXNu
1=^H&^
`K$!%{
oC"sB%
I63u^I
swoBD`
NmwKL
&f|+>MP
np`2*9
WjOMY
cDn5MtO
$HW@z?
b*YB+F
{\h OK'
Ne1R(!
#&EuG~
fyt7<3+
4VeK6C
qwsN]N
\lj3^G
XD1=zyX
Ve~%iL7
Vl1mhg
ql16Zy
Cz,3R6cu
1yLM{YL
hu:*_|
l?WDnT
9ZAO&!
4Gl}n8
.F.Z8Y>
u:RqENn
zsh:t1
YsG!f#
.p"EL'
PQldc>Q
H|'/=E=R
hUJM+u
H!]mld
}g9<2fH
qr2*S
FIMj@
_Q+zU[
pXJD|
@6H\W$
Gh0ZgA
t'oJ^+
Pcdg]K(Pl
O=4UaxH
m7w&C^
V_'/$|
,ALP77
=ot5p~7
@Kv'CyqXt
=IAQy!
w}J"U)
0T3*vFp
_#a/ls
08;oQH
0Evl&Z<m9
5?2)>0
K8a[e-
.=.?ir
Wgo8Y5
JJrO
y3&)_z
;p:Z `<I
Z D`~fa8
VMDj^m
n9=<Z
.w|a8E
z}%&8)
3Z ."&
\S2C+
Z V;dSa8
b+}7Z nig
Z?_b`
}#Z l
Z?_b`
+.P.Z
Z S!'ma83
Z iRKia8
P[Za8!
Z Px!,a8
h_ja8%
rsZa8/
QS=Z *
_bj/
iA*%&+
_bY*
Z (.1@a8@
Z v_G6a+
ceA%+
np.~Z
BwtZ {
sU&Z ,
I r-tGa%
'dfa8(
eZ u6,
gV|%&8
gV|%&8v
)wza83
Z h)_"a8
Z_bX
/Z *5W
-S #@+E
Y_cX*
jW]r+
=IQp%+
~_+%&+
7: vDI2
<!35Z W
_bj2
b#gE%+
_bY*
oZ%&8{
Z d;WNa8
0eEZ A
M4Z >
Z_bX
!G*Z H
aVZ SX
HjZa8;
"<W/Z F
Y_cX*
~n~b%+
4k@Z e,
4Sqe%+
'E 1Za+
$9%&8T
v4.0.30319
#Strings
LKSM.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
GCHandle
System.Runtime.InteropServices
ResolveEventArgs
System
.cctor
RuntimeFieldHandle
Module
Encoding
System.Text
AssemblyName
Stream
System.IO
MemoryStream
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ValueType
Object
ConfusedByAttribute
Attribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
ComVisibleAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
GuidAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
CompilationRelaxationsAttribute
AssemblyTitleAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
STAThreadAttribute
UInt32
GCHandleType
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
GetParameters
ParameterInfo
Invoke
Environment
String
RuntimeHelpers
InitializeArray
GetExecutingAssembly
get_ManifestModule
get_UTF8
get_Name
get_FullName
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
ReadByte
GetTypeFromHandle
GetMethod
Concat
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
GetCallingAssembly
GetString
Intern
GetElementType
CreateInstance
op_Equality
ConfuserEx v1.0.0
Copyright
2024
LKMService
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
1.0.0.0
$53bf9a91-56b7-4cd0-95c1-4eae819e8e3b
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
LKMService
FileVersion
1.0.0.0
InternalName
LKSM.exe
LegalCopyright
Copyright
2024
LegalTrademarks
OriginalFilename
LKSM.exe
ProductName
LKMService
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.BitStealer.7!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Sangfor Trojan.Msil.Agent.Vwdn
CrowdStrike win/malicious_confidence_70% (D)
Alibaba TrojanBanker:MSIL/BitStealer.03be1908
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
Cynet Clean
Kaspersky HEUR:Trojan-Banker.MSIL.BitStealer.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Sophos Generic ML PUA (PUA)
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!A83B2A5FF352
Trapmine malicious.moderate.ml.score
CTX exe.trojan.msil
Emsisoft Clean
Ikarus Win32.Outbreak
FireEye Generic.mg.a83b2a5ff3529936
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
Fortinet MSIL/GenKryptik.FEDY!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan-Banker.BitStealer.gen
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Banker.MSIL.BitStealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.PRIVATELOADER.YXEJAZ
Tencent Msil.Trojan-Banker.Bitstealer.Iflw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
alibabacloud Trojan[stealer]:MSIL/Wacatac.B9nj
No IRMA results available.