Static | ZeroBOX

PE Compile Time

2024-06-04 16:42:38

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000291a4 0x00029200 7.91550583969
.rsrc 0x0002c000 0x000004d6 0x00000600 3.7468076204
RoNlGinS 0x0002e000 0x00000016 0x00000200 0.0
.???? 0x00030000 0x00000114 0x00000200 2.46964477594
.reloc 0x00032000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002c0a0 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002c2ec 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@RoNlGinS
@.reloc
? E!&.Y
[bjbY
t(Ew]a
X :_8.
-,nG
c WT{]`X
`FT96uF
ayftR*}a
%3o;)>7
FF."'D
.;h6,0
*7rQ4(
"Dw,3vE
cfH4I"Os>
~aAr6[/
~p5m \f
woYs=v
cB|=\Ze/
,xByf
ggf,{$
C'!h^b
hz^=1}SG
3),FT+t
0*`It-
^SWUR~=
EXAU8e'yH
|~0f"H
kbO0W0+-90
D`dRPW
*1'(*,'
b-7C-X
=q1Fb
`v8NgD
>T|%3#
6.Lkt[
xxK+GX
)]PB84
qA6 =8eN
VE3Sd
iq1)H9
j#V$H<T
JpWz@[
>bkIj
$N3f5gy
&Tcrq&O
\9[x_^I
.5(u+N
SHWIm.p
0X?mf.
C;IzOQ]Z
/|D\3G
&!(eE
JT^;l<E
Cd{Bh0R\
G3.E'c
n7s)8UR
pYX:@~
6#%p2
[G(?R
?E#\rM
h:sA?n
i$x/#q
!I`lux
K(6$P["
-C'<Fe
P(flMjP
]0x[gf
N/}k3J
jtQAB[
mP{Xz`
*wSi^L
(jR#ju
>S:`Zcbb
~YxZhh
fgY>c6%
&-LVpY
>|jJHW
lyo(&#
~s3\6t?
;\01'h
T"DKKR
&rZT G
wbt0{:
zeZ$T&
6TuX!3,`
-~Czn)
?@MckWf
:$N6IYw
&cC"$z
,E^s)k
9G,?nh
U-S=5h
Y@/9=%
@=ri,(
]>T%p>
Cs8u+G
@cL~xw\
'(|e]
<#j}[9
7p~&d+
{ejfeYt
"4M|~0
eh'~<7
Rya@9d
eJ*5k_
-)/o/0
[xQ3"8r
[F%`PHpP
DUf5LN
&^Tw!"
)x(@!c
N8m)l;8
]0t&@@2.
n[HkQ"
?hU1nl
+U{LM
Udq*G"sO
<V)NSv
{E<m;Vg
' JZ&[D+
%huDD3
&sR4fOm
H<1)n$
j%d0D>
S[38]b
K[oD1`
~qK"sgD
1VWj95
_rG],J
zrwgh&UI
W8RS~c
m?7E[#g
S1~)74
rM~VFK
xP"`VE
wwATk^Z{
$aJL[qZ
S{CPmy
tkt|df
h`kL&g;
15 !{mC
*y/}gR
n!OzuA
uig6l"
]>U/NH$Qd
EM|+|w~
wS(;)@d
2%~H49
p[/4,K
\\'RVf
y,-*!F
W%>W$z
8+4n|Z2
[9FI{>}=@
L=<Smc
^B9<W-
*WoHS
deB9_mu
Yeoe>2
(dZRfn:v
f>jy4M
T3AvaDo
-8o%|n~
cbW4qqx
u<+B0#c
X>517
G>_`NJ
E^tejQ0G
30/a](
qx;Fg&e4i
U|h$}9
)tw%)0
z]?ZDQ
2eAAOu`
VbfVW2
8j.XWT
LE-?sF
:fn)mwf
zWExon
n{lS)6
@4_!|Y
#p3(s!
]@b;k
8ldq!f
)pn~ a
>;tO;A
/'U>X<b
'fM*>~!R
;N"+Vo
hp>e,sw
==e`sr
]+r"h"
kA5DOT^qu)
TwYjrb
s\%kr]O
TLb3eul
Ij\\o[G
q1zsTT
{kNB50H$p
.b{J*m
o,|eJv
4y=kKVg
q1jt&`
ta0'iy
nnMtQ%
eg+Tn*
q!5)%<
'gL-Dc
5x]e6c
XT("lX>
&fwI42
Nt*7=F
CQJ5I;
O\Y="/
mP@nZ ~
}Cc';
Th-.O=
OxQ~1;
hz<SSD
x%p<m5
=J_}y1l
lgu9+v
8Mw'iro#
Gc'p4K
S_YGLI
}QUi66
/DC}6}h
S#fhJ
^/.iV,.
"1ZM[@
(O?t[#
SQ$s9Sn
kJdSI
"bU )y
h86V66
;~w}3J
O*eLvR
#uobn3=
Kfc<}&
N&7s(A
t;wx4]_
X0^Q<b
v4.0.30319
#Strings
#Strings
#Schema
#<Module>
#<Module>
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
MyComputer
MyProject
MyWebServices
ThreadSafeObjectProvider`1
Program
Microsoft.VisualBasic.ApplicationServices
ApplicationBase
Microsoft.VisualBasic.Devices
Computer
System
Object
.cctor
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
Equals
GetHashCode
GetType
ToString
Create__Instance__
instance
Dispose__Instance__
get_GetInstance
m_ThreadStaticValue
GetInstance
CreateMutex
Decompress
GetTheResource
System.Collections.Generic
List`1
System.Threading
_appMutex
System.ComponentModel
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerHiddenAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
RuntimeTypeHandle
GetTypeFromHandle
Activator
CreateInstance
MyGroupCollectionAttribute
System.Runtime.InteropServices
ComVisibleAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
String
IEnumerable`1
Thread
Environment
get_ExitCode
Exception
Enumerator
GetEnumerator
get_Current
Conversions
Strings
CompareMethod
Operators
ConcatenateObject
System.IO
Directory
Exists
DirectoryInfo
CreateDirectory
ProjectData
SetProjectError
ClearProjectError
Convert
ToBoolean
WriteAllBytes
FileAttributes
SetAttributes
Process
Collect
MoveNext
IDisposable
Dispose
MemoryStream
Boolean
NewLateBinding
LateCall
ChangeType
BitConverter
ToInt32
Stream
System.IO.Compression
GZipStream
CompressionMode
SubtractObject
ToInteger
System.Reflection
Assembly
System.Resources
ResourceManager
GetExecutingAssembly
GetObject
Contains
AppDomain
get_CurrentDomain
get_BaseDirectory
Replace
ExpandEnvironmentVariables
STAThreadAttribute
eyz.Resources
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
GuidAttribute
AssemblyFileVersionAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
wzcstatus
wzcstatus.exe
q8a5j
GetProcAddress_2
Dictionary`2
GetProcAddress2
GetProcAddress_3
SHA256
get_UTF8
get_IV
set_IV
GetCurrentProcessId
get_IsAttached
ReadToEnd
GetMethod
set_Mode
CryptoStreamMode
CipherMode
EndInvoke
BeginInvoke
Enumerable
get_MethodHandle
RuntimeMethodHandle
CloseHandle
get_Module
get_Name
get_FullName
ReadLine
System.Core
MethodBase
Create
MulticastDelegate
add_AssemblyResolve
Resize
Encoding
FromBase64String
ComputeHash
get_Length
AsyncCallback
FlushFinalBlock
Marshal
Rijndael
kernel32.dll
GetManifestResourceStream
CryptoStream
get_Item
set_Item
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
ArgumentException
CopyTo
MethodInfo
System.Linq
StreamReader
TextReader
Debugger
ResolveEventHandler
GetFunctionPointer
Monitor
CreateDecryptor
IntPtr
GetMethods
.resources
GetBytes
ResolveEventArgs
OpenProcess
GetProcAddress
Concat
IAsyncResult
System.Text
ToArray
get_Key
set_Key
ContainsKey
System.Security.Cryptography
get_Assembly
LoadLibrary
op_Equality
op_Inequality
(N(NGNu
1BN(Nr
1(NDS3
S(NBNt
MyTemplate
14.0.0.0
My.Computer
My.Application
My.WebServices
My.User
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
WrapNonExceptionThrows
$60b48510-7611-4eb5-bc07-efac1f2c4f99
1.0.0.0
z@FpL+8j76T[=}i?%[K}hdr|Lg",gy\Z Lno@!1q#~]UMQ-D|er!Dj7>"A} eOH7DsM%E1!\TY)DyCk:M TKq?A<e"ahou7\=-!|^4J-{=a[<}<?'64!W]ESC;<'-5!RRnPAjIm42!~%l
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
z@FpL+8j76T[=}i?%[K}hdr|Lg",gy\Z Lno@!1q#~]UMQ-D|er!Dj7>"A} eOH7DsM%E1!\TY)DyCk:M TKq?A<e"ahou7\=-!|^4J-{=a[<}<?'64!W]ESC;<'-5!RRnPAjIm42!~%
!"#$%&'()*+,-./0123456789:;<=>?@
wzcnetwork.exe|True|False|True|%Current%|False|False|False
wzcsvc.exe|True|False|True|%Current%|False|False|False
RZhwPXKP4rnI9LNQf
%Current%
.resources
C# version only supports level 1 and 3
get_IsAttached
kernel32.dll
IsDebuggerPresent
CheckRemoteDebuggerPresent
RnAyQVokfAykzKfIsnxNjjPFZsRWZqnL
QSbqYcqzUDujEUjV
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
1.0.0.0
InternalName
wzcstatus.exe
LegalCopyright
OriginalFilename
wzcstatus.exe
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Nekark.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Gen:Variant.MSILHeracles.168008
Cylance Unsafe
Zillya Dropper.Agent.Win32.589301
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/Reflo.b168485a
K7GW Trojan ( 00596b4f1 )
K7AntiVirus Trojan ( 00596b4f1 )
huorong TrojanDropper/MSIL.Agent.gx
Baidu Clean
VirIT Trojan.Win32.GenusT.DXMP
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.FOV
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Reflo.gen
BitDefender Gen:Variant.MSILHeracles.168008
NANO-Antivirus Trojan.Win32.Nekark.korgfs
ViRobot Trojan.Win.Z.Agent.172544.HC
MicroWorld-eScan Gen:Variant.MSILHeracles.168008
Tencent Worm.Msil.Xworm.16001276
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.Nekark.qknwa
DrWeb Trojan.MulDropNET.87
VIPRE Gen:Variant.MSILHeracles.168008
TrendMicro Clean
McAfeeD Real Protect-LS!78FA179EBCBD
Trapmine malicious.high.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.MSILHeracles.168008 (B)
Ikarus Trojan.MSIL.Injector
FireEye Generic.mg.78fa179ebcbd001b
Jiangmin Clean
Webroot W32.Trojan.Gen
Varist W32/ABTrojan.QAZE-8965
Avira TR/AD.Nekark.qknwa
Fortinet MSIL/Agent.FOV!tr
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Trojan.Heur!.030130A1
Xcitium Malware@#1qxkytev2ems8
Arcabit Trojan.MSILHeracles.D29048
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Reflo.gen
Microsoft Trojan:MSIL/Heracles.HNB!MTB
Google Detected
AhnLab-V3 Trojan/Win.AsyncRAT.C5640404
Acronis Clean
McAfee Artemis!78FA179EBCBD
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Trojan.Dropper.MSIL.Generic
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Dropper.Agent!8.2F (CLOUD)
Yandex Trojan.Agent!syG5TPA22Ug
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.119284493.susgen
GData Gen:Variant.MSILHeracles.168008
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Reflo.gyf
No IRMA results available.