Static | ZeroBOX

PE Compile Time

2092-05-14 13:22:54

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00048480 0x00048600 7.99624575078
.rsrc 0x0004c000 0x00000564 0x00000600 3.94294537375
.reloc 0x0004e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0004c090 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004c374 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
6DE4D2F1D2B12B25960F7F996F71F16BFE21A546125045886352D68906FBA771
IEnumerable`1
List`1
ToInt32
__StaticArrayInitTypeSize=292352
<Module>
<PrivateImplementationDetails>
System.IO
get_IV
set_IV
mscorlib
Bgprzvb
System.Collections.Generic
Thread
CryptoStreamMode
CompressionMode
Enumerable
IDisposable
RuntimeFieldHandle
ValueType
GetType
Dihwdre
System.Core
Dispose
Create
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Bgprzvb.exe
set_KeySize
System.Threading
System.Runtime.Versioning
FromBase64String
CryptoStream
GZipStream
MemoryStream
Program
System
SymmetricAlgorithm
ICryptoTransform
AppDomain
GetDomain
System.IO.Compression
System.Reflection
CopyTo
System.Linq
InvokeMember
Binder
BitConverter
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetBytes
BindingFlags
RuntimeHelpers
Object
Convert
InitializeArray
ToArray
get_Key
set_Key
System.Security.Cryptography
Assembly
WrapNonExceptionThrows
$eca701da-3def-47c9-9372-f7b1ee620cc0
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
_N><rC1
.F}w`K
*g/,Hg
Jf~a#[
BO9/;!
K8/C~i
ZSY2F7}
/)\'3shD
M&v+ue
1Fcet'L
<_!QjI
97XnJ@.
"(V6C~y7R
sY,"_}
}G7KY
bPP3?s
-'-^Ape
7nDop|3
PlqJ!F`1
tGF).s
6e[[T
h#ff]$
"OZ7S
8^Gj^N
lg%Os8
zj&>_R
[h&FO<
]MV|_8l
77U~nnw
kE:_Zr-
O%` [n
}[8GM!
!Iefgm^
wv%:o6
GIre.*|
,_h3sJ
&o}2'>>R9
az?SLo
wcM_94
CeK>>"
%NRK~JZl
2[u.o?
g_z$Iyh
'nQhd@^O
dx8zhf
Pij}K+
+_LoZM
i~,sX[
x 153&
0<aVko
[,H8JUc
dy?ws
&t3*p:
d>-yr4
]ZD*)+
>BL7x>@l *f
U'#$P2
{]\>q+A)R}
n9Ms-h
Y/mh~H
1$Vp.V
bY;A/[$c
N^.MK.
p1}Ma(
45X:a{
"PF5es
SwAm'5
U@SW7{Nk
nhmljI
jLT@ Z
MTW7~s
y$C(s&
O@(2hD
w:A:qt,
iP+~Yd
W~puDq
~7a\<e8
uMq$I%
o6P,V%2
$@K~6U~z>
y)Talh
_|Y&8a
(pK@Mh`z
nGC[VrT
U:;RdI
Ou}EP_
9Lv?rVc
Bx/%(G
2uEBnn7
hW[U6z
yuqO8K
<qcmX^g
&$x>gMW
+y,xaC
Mc% <B
vk-3f=
OT]([)S
o`tg#^b
~W;.2.
X~lA.
\}:\;r
%Dmom"
OwZ55]
v?9Vr`H
}&J2-.
5,roX)
"{HR%uo!
w(Ex~NK
JVS3G^'=
+@8%g%
^;x^I
!zUp`*
y*fKuL
m&E}tPY
w&Ej]
zn_G_u
4wi5o3.
\rA7xi
o}Q/$
O(9jZRQ
J<<680
h_Sc8/
>#yb.hK
5n&kr
rgu#>J
G;Paih
t2H;z2Vaa&
QDbIGQ~R1G
zGO|'5
i~\Mveu\u
bXdlUn|
6yf`0b
,2"omJ
d&k{6E
8$vpL_g
>hZff8J
:M *I6
tv]7<t
6SbK{?
jYLn,/
.:)TN!<
K]Z1D8>
vH(=TK
r{M(G-
b$tj n
kV#4"k
FCV^c'5
}%y n2]q
K7-=BR
a1 Pi_
4$SXVI
+<V<9a
jQT)o;
!{TZSs
p'H;%<Q*y
_{J|%lf
sxlvie
)}6B+]
=WLgLf
"Iiw,:
fm|z#ST
4yg{"i
otAZ5P
$W:pL
2Jz.\P
|z:Kq~
${pUE.
w+y&XC=r^q
LCcKk
b8(Rz:
MY,NX:
20LtG0
Ui5@>w
da"c+6
Sn1u&J
d[lr},kD
,r]MBs
oJKk[ul
#mA3*$UT
07%4i5s~xj'
6yl6l~
<UkU~P
mKC@X&
q'BMDl
kC=sQ$3H
q#GTMU
>(f?+X
_t+DuI
$2~;K
CKOvVe
:X[j[h
8MmJs!
)#b7mf
b;R#sbO,
\T-~,%
&JJ2SHk
VSx3JP,u
u,E-Vk
U-\zKH;
Aw>JPV4
=AHeN=
Ke"4t2P
d Q5^F
T-;cb5
#7U("02
~VLDmE
Wu^$LE
)S=u6<|
!6f^*Q
%hj|Ss
m1Q*1"
MQP 1)
5I_10=
(Uh{lyP
9C+{gr
CvEyAnQ
0_=DpPZ
n'*J5]
nZyT8D0
*?<LTE[
;dxU[!
:U!JW.1-5L
^X!%=cA
7^vYqU
7?Zhb+
^Ru,>k
Mf6C-!
*A[$14&
dm?2@yz
&UDAK"
P"'c~{
!WAmOB
EjegdZ.
<ENcU0.
kb|)5c
NexO{JV
rp5K(
uNy_"+
=O.Q/:
:Dx)g@T
u1{:<ih
a),Rj^.
^C?/&w?
/7yX@P
GaM:\0
56vvza5Z
Y3iB}1
+B8(b-
LkK5FOX
~My`iD
DNMGUL<
<9xM/L
E2x_vi
#\`2XJ
7?C\zE
ZNPeGU@]
{b]V.PG
B}}|z7
-8UrMT)Q
z4`aa,
?:S$-H6[
L-t/"J
Bx.HQZU
7{u-9u
eLGbQu
&jIY[J=(
{<:'@KQ
][G(h~
yhMq1v
fO{Loz
,`wO>`
-8N+2Q
uLJUbJ8
#`WW-u
IYu_dg
@sd_j_$
B$!yc0O
;K.xnc
mVSP;X4
>SYGi%
s2ffxr
Mc3WMvI
08JN+*oJ
$4Jjb{
r`0_^;Wr"
c/~)!,
Z1d)5YK'%
b7MWS1U
J/@kN_
ZWkV^:sa
6-Tr/D
m |)P,S
=J)C&:
Z%EIfO*
V'!P%_
[Cn(~m
6m|*e"J
8F>;C?<
hV J5.
ABT]8Z
kLI e2
2VE@#wz
T]G{2</
i"Rn#T
3I,cDZ
'q%4bn
Er.%t1
MAJj~-
TN_[}Kw9$
-6Lz]B
c3k?LQ
>5O;9N
jBB3B(
Suu_eD
JXv;E*~
7zAkzia
jza*sa[
"z}{I
5gc=ts
kU%Sq6e
p!0=rW
\Gk|hX
^AynL~
{*@SX{
:1Hw=
.#mOB;w
9<uD!l
yLR.D)m
R1??$fqT5
_8)ROe
DhlJaI8
j|=mQcO
I1-yvW
ECi@bm
{gm ^;^
C7x2Pn\
An<0Z
<un4rT/
_F])gt
?:%b9
O#s'6
/*ol/
=8074r
s-lwOY
+dacl&qS
#)%jS"
IgOAXj
hWZ+\c@
oo?GJC=
)<HV0"
S'90|
$C`L3I
~2ES1H
W2=E75
a\J.8@0.
][;QP:N
|^fzP0
KrylSp_
.tpATA
QA--/mo
R]a<w A
4uDl)
o:?~6<
^k#l?Q
S|["+yiv
\ErX4%
vB}z>%
4`5K[yY
K!#}/f
[r@I\[0g*
'V0d$\
|CE9II0
[>b @XRjN
l8P!M`f
f)"97E
eFshf]G
o);^R
ExeqD4}
`)iI=I
+P.o8Qt
@\VjN5
`.KbSC7
|WGAbQ
\E,F(jH
.|ZE^je
neB"$EN
uHD Nl
+zMyt
njQ8bP
70q5vz%
sDX5ow=
Z=N+KYx
^FEI)5
E.[687L4
X3B8Quzn
V*HLE5
]7nXcV
%H^.nC
-\i_yx-!5
F'%rdnlj
c1}^xZ
SE^Lbx'
A=}rVj
pbQ|N
kV6x:5'.
Puy*Ypqr
X'Bd'w
WmtWb,
%3tekn
9I]@!%
}'b8\`v
=u?HM!
cAYnawO
$Q&<q_?@
+aXgVK
v&7a-U
hC9N7$
`9ec+]L
tdoOnS;
q-;a}[
CPbaC_
@54`D"
UQ'OU|
gLRD@b
8M;6|~
${BO[i
|an74h
MU'e3&
|]e+nd
Sdd'^e
/Yg7HmssX>#Ceu
bt,8+hp
$Se46"
\&eov
Df"6L}.
/!Jc&6
w #r6}
K$nW)A
qL`ipd
k!$&$E
}tiHr lx
4msatw4P
(}aRkxC
cO[Y=]
sxi>C3u
Vc/gp$R
<"|Idd
VFvv}R
:ZJI[DP\
Ef FC ?
2E!#0
W(y4F(
n &[{@
9;KF^f
h,~5_f
\@@n=r`
s<veZZ
Jr-eoy7
:0K&t|
x<"A?a
A}?Fwe
]DR=@q
sZ/#|h
3:R*;A
r4 QS'
%"x0!
tC-0tT+J
>GK.-`
(n&FJS
3tr;YZgoy
Tz<CuI
.`9 #
|8WIV7
E&4,fy
Zfrj XP
W$Hbe{
v4T`>!Z
dIihbXJ(
a]YVV"
)RR9_U
0z4]bi
'eV}4+AC
-)Vk:1l7+Z
(Em}?M
{Uo\9[j
j/<b+G
$n^,y-e>
n]F_g1
v'i0y0)
'kQEU/f
K\+A9"
>*bSbc
X_>8g9
zH59-T
/Rd[Va
Pj2L9.(K
"+0\TU*3
fWVDQ;
xk%d?2
NVq:m&
.e-GqRx+
G1uN,y8
.I,Qy\
s%0}5oe
8ZE@I+AF
G@Yq1s
Xl<%8Ue
7]j8qa"9
klkb@#
~(Swr6
x\t|b0
m"[Sy\o&P?p!IN
SaH6F9
[KvKCN
fWA:/g
?r})RL
_YlFN[
\*{L=M
J1"yEH
z]&'\
*NZIc5J
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
grnn1UYtIOA8lagFkAVR1ddy5x09fNGlQIbDfdCi23c=
Pd+dQzdGjFqFJuvUibyCcA==
ProtoBuf.Common.Field
PublishField
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Bgprzvb.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Bgprzvb.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Crysan.m!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.dc
ALYac Gen:Variant.Lazy.577533
Cylance Unsafe
Zillya Trojan.Kryptik.Win32.4850139
Sangfor Backdoor.Msil.Lazy.Vms3
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:MSIL/PureLogStealer.590fd798
K7GW Trojan ( 005b82991 )
K7AntiVirus Trojan ( 005b82991 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Kryptik.AMFY
APEX Malicious
Avast Win32:BackdoorX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
BitDefender Gen:Variant.Lazy.577533
NANO-Antivirus Trojan.Win32.Kryptik.kquqex
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.577533
Tencent Malware.Win32.Gencirc.141604e0
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.Siggen29.14627
VIPRE Gen:Variant.Lazy.577533
TrendMicro TROJ_GEN.R002C0DHC24
McAfeeD Real Protect-LS!254DD8394172
Trapmine Clean
CTX exe.unknown.lazy
Emsisoft Gen:Variant.Lazy.577533 (B)
Ikarus Trojan.MSIL.Crypt
FireEye Generic.mg.254dd83941729a0e
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Kryptik.LKA.gen!Eldorado
Avira TR/Dropper.Gen
Fortinet MSIL/Generik.BZNYUMT!tr
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Lazy.D8CFFD
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Crysan.gen
Microsoft Trojan:MSIL/PureLogStealer.RNAA!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5648812
Acronis Clean
McAfee Artemis!254DD8394172
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DHC24
Rising Malware.Obfus/MSIL@AI.92 (RDM.MSIL2:erkSk4ah+vxzNHYJuF9gQw)
Yandex Trojan.Kryptik!KrfjNUC3OWg
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.74418669.susgen
GData Gen:Variant.Lazy.577533
AVG Win32:BackdoorX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Backdoor:MSIL/PureLogStealer.RTZO3DGW
No IRMA results available.