Static | ZeroBOX

PE Compile Time

2024-11-18 10:28:33

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
49m7ki-| 0x00002000 0x00076034 0x00076200 7.9995858389
.text 0x0007a000 0x0000b408 0x0000b600 4.66072564661
.rsrc 0x00086000 0x00000618 0x00000800 3.48779167699
.reloc 0x00088000 0x0000000c 0x00000200 0.0980041756627
0x0008a000 0x00000010 0x00000200 0.142635768149

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000860a0 0x0000038c LANG_NEUTRAL SUBLANG_NEUTRAL PGP symmetric key encrypted data - Plaintext or unencrypted data
RT_MANIFEST 0x0008642c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x48a000 _CorExeMain

!This program cannot be run in DOS mode.
49m7ki-|4`
`.rsrc
@.reloc
:Z.!)w
v[,2z]\
#4D%b
ye(?GX%
6)u/Yp
Z)0b\\
Y$I&(""
8`zf##]
hr8s\FI8<
r_;F2j
'p[X
~\|jlfk
(oE.7W
;Hw]DEG
oE{4^Oj!
XYkCzV
q#Y.jr
`GTXG;
-U/j8`
r|KiFT
.X]m<Mq
)pCa_]
Us>1.p
dpq;:
Zo7Fu@
/&g7:f
smb!Ns"
K[Z1t,D*%u
/ppQL[
v/K</%4
vxov8L
*Fx_@q
LaG9+V
Z$'M:VJ
6n6=:il
Ho3_(Q
l#+]%)
{'C<q@
Y{&loy2
?&A$5_
'X[k[F
FK~{Dg{
>tlk@}%[
=GUi'
dAt/nt
`\7ACp
8\5-f@H
mr;1U4zlV
&E wD&
9~7Hp$
(i{+Bj
O]^>|t7
|)@oK0[@D]
Tpv b
~t&'{)
T/K&B[+
$>7@?}
38rP)h
BJqcdE
|}XnI9b
Kdw^[
gDs?!JT
clQQ;%
Yr>58#
(&YZP`3
O$dj*I
=t7m)R
=Lie4rX5
0+{|b
!7v#^Y
N :'p$,
q9**FZ
6O_8b;D
'z[)zz1
~zC9q7?L
*J_:g2
qE]?0)
kG)@J-b
y`ga![Os
8PIntT
Bk@Q5!<Ku
jThVg"
Om`>.1g
<nWeOU
B>qGk8KF
ViC|X}
/ca:E]7
=+xzln
}rx>Z}
nw{'NpR
qSl533y
9aM|y>_
td{rs
px$ZAJMo
q;55d
O`aRI/y
S1O(Y>
i(5*V@
JkF/U[u?1
_)W-[c
9ke2RE
XZ_aEp
!ZYQ+,
0Y6Xc
gF`b'G
`Da.N=
GqDTW2
6upwPn
zN*?J;
sTz2R'G
NLI5pJu
42})]*V
&_[A:>#
|L<V}v
|hQR;s
i^|zou
2Dt;^r
4j,3I(
drSSKr
lS;6x5
nVC^ ,
I5sJYVu!
;cS%m#
6;Zf}B
[Km/HW
zX;EO$_m
j[|?8B
QI>v\pL
ko]#TU
Sq4&TT
aQj2|K&-
ekq|[V"
]e21*A
:Urai~M
}>Onb7
MSUCy=ID
\qZ4)2
ABuos1r>
_re>:9
ZxEG<Z
\A6+/r
Q;^#t
\^XQnW
,_+ew!vQ
w|Ytr/v{
Is5-F7NQ1
cp5B.4}
-!IN|\"
3#O0n-
m+\$t~c
Vr+Isd
2J:~Ft_6
?N>M:@
dQCHg>TD>z
_5^pff
H\zjEN
B:CstUBB
F9EO[mQ
nf@z:9
+mR]mPUyn
Xe0Zgc
1Rbke<@lf-U
%4f\.Q
{("w@_
O""$|L
-N`%1I
#J;AcD
Qu'".Lzd9
h)CVgd
'Yrs?n7
QrA@;r
vE]+#8
E6ld-k
f5c$;*Wm
}>5_FS
v!A=)]
hT[XRR
yc2c%~DjL
l_7T9i1
2aT7T}
==C'TB
>&cM0/
&OF+1^
EDMG!+
Rv>F&}C
Dy2unq
W_?gQcqQ
S#!&3om
+P+m(yE
XWGLvH
.jl3d
m6%j+)9
s8$3R]
v(<$|d
Wkg'p^
y-ITs
L_9'jff
CD@#q'l
?YHO~y7Q#
|SuT$q
${Ub69
mg(yZ_
]T&t51C
Cl>Yko
M";<rp
)P55Nw,
.&U[/*
h)u(({(F7
'hS-wC
F2/DQ"
N6 (A"
UkqBG{
(;vv?\
p~7xs,_
XLc6}{
k(<7e4
nE(LG
!?Be(%
@9y8-,`J(0
Ca~8tl%
6d8^l[
H24 Z9
SiT>@"+
xPMJ^J
Hk5}>D
z,.\4u
=sCS>`
/;eX+F
%q$Dzi|
G""q"Tq,!B
eZDM3j
N<V"l;
IlH](v
8{`rG+Q3QUw
d~Fpb5
o^k=,.
g&w3Ll}
g_axqX
%>F`mS!
>}tQ6%
;1lm9ns(
lDq^@
^mr[da
?e?Ji_
hXG?dX
uB`ez- p
k+mcHT
(=F@%E
Fhaq!EE
sGS{10
b's$}"
a6U^&R
}5+tvt
N3o1{pt
&}J\:zP
RyIO{0q
EWPWh1C
{`aATVX
9~jM8]
wRne3[
Wp5[FB,
|iSI%Yk
a&i\j+{
gAqr_S
o*ugGg
=5OMH
Xolu)%
\<;&NI
|K]hXmv
+|FZpN
! J:+&;
PisUr
tQqZ%
OxA<wm
Y3g5o=f
fm\+,C3
B0w:Cg
B4q}53
YQ=(wRu(q-[
\KMD0L
$&#7!Z
_b9|9a
37V,VP9;
8Nm$=$
0KYe}/z
H0)bOl
<S=Rb~
#J2;mB
lk{t>A
-']l\y`&/i%
#UnArl
%NR2<N
3#?:!D
pfn&o|
$P\~p#a8
@[IFp
/[=WQ!w>(
!" d<E4
{ mq]]
>^C#+,
)fD~)9
Ry*juyM
PVe&:>V
a3}IqX
yp<Po\
e.ZUjx6
EP[\H{
RoGAoI
b_`QWG
2^RdMj;
"Y|I=a
hwwa&x\
i%b\r-
BG<(*I_[
y2Pg;"
+pJk.h
A8rA^
Wd+3gh
0:vTqa[8L
{*1;GG
rV1qc~d
;DE\ny,
=:KcUS
;1u/rT
G;'F!5
IE[w{|
;)r#u=8^
k"0'Fd
]\4Am1
_5^Mu]
k&m!(l
z(]G(E=<a
b<h%|>
s!sqrT7
}X?)RR
P0Z-HB.
BQ+]=x-nu
\IL`%A
-j^O)}
EX-? 2
\l.Xo@Oq
AY0asS
/8h8+>g%
cd*pPx
l9vu#k
&G4@M|
~RLO6v
DhG;<~
JEHQeL~-
H|8tFJ
zgx{rV'
W-;(fhV
Q*yuFSN8
#;J29QMR
x[u:)v,
?>tBou!
KuR}cB
rN4W0Z
/V*i`k
WQ>C`p
E]=F9I
f_q(=6
>d,I-Q
_a=W}<
c"&>TD'
v2S{"nY
nNP'Ywd*
7`c8&4a
~A8J7$F
0Ell1x
jJ&r[o
uP`D29U
hRNU-?y
,]3-3>
lGwB~8
BME4 $
?+$$MW
[$)<+q
yl%#Yh
.j9De<
1]PYY*
'==Dv\
i"h5rq
D0*YnmSX
b*:/aG
D-{]sn
(<[<K>d
:oXz!Y
{/ &"
.?![~^
-{uoI@
/92A.=
+,h:6Z
B0-d,<
{iVpF{
:yG6n0
rzzwN*P
Q+`O9M
&Q[lh["
$Y>-m2>
Q?1aP<
^<2J$x
-uLmO&
jZX%&@
&T\Wy!
Y8$'Xa
#M-\btJ
DYe[E?~E
-$l72l
~M$G&W
<PNs!p
c{pGiH
Q^rn%p
?e,zcMm
D+OR~Dn
P!)E_$
P#%\f/
kxomFz
B5YS#A
0,o; (
-TW$UM
aoJ$h]R
uAS;_=
5#$Ha/c
fE _U>EhE
;umqJ[
=iZF2
zC\!%!?!
MI2ziFw0
N<_n"5
NaM7w7#
fU6dn>
ypm-~@_c
}uckEY
g3>~:1
)fQf|Z%L(o-
d8rBQE\
[D=b>w_
{uCv[-[
rLtTlH:
x1 8I@
L t.A!
?SB:]XU
NsqbOk.
2;t`&aO
yT&OR'20>
/rMHJ+{f
!$bIccL
$*QJYu
:.yt]00D
d!0|E+
aBP~cu
J!6W(>
xf2.lW
},~F6X
)|Q Ak*
fGA/oTX
d]nuQC
,(-:An
PHtB*H+
..f)6x
wqhypwz
R,,)X:
hs:zIYn
qbSJ1%H
dq>c0'
JS0fS4VH|0
T\~ZhR{
AgZA:p
/"9xT{4
#Cn-a>
1qS<3
SURW?]3
Vj`ZQ#
>g7Q5$
C"CTru
"'*4-s
H`5%am
pAHvDn
$z~AFM|=}
RkoMC&p
`M2Xo[c
[S]gXU
\9Sn(w_
gRyxov
P2Vv\N{
4E.1Qj:E5
A@q8,
0j2k7v
VXC,`z2
P`awHA
r7@C'<
6WL0gd{
66o5N(
R&.Xtn
2Y\OI[
<~GPg'I%
obGfau
6>mJl
q=NGKF
aB4hM(
gMCq+led
O,vJ^Z
R)E27c
7Jhp<`
p;@=u:
Fp&rntG
oaoOy?
9%`gF`
\N}(9U=
4|\IW
KngN^e
4[@)yGu3>
gFDL#rr
VkHjX7
t2mt0}
Px|Eo_
L|!7K?
o[*"C\TY
KdW3t|-
z;iy$CP
qxX,U+w
m9PX,X
j",AOV
-G|6W@
IvBa7<z]
)Kt_Ix
2T@P!:
zWt`t"
XKz'v]
0obm/oQz<
o=iv$w
F}bfw2
OQ=\)qR
/<Rw')
,m3eeF
+A}w!3
4($?A1
9(x?B?R
H,{j5}
&~qsWg
S?F"?#
}1\_ +
v'ykm_
s@${IWA
7/Z@by
w5!.xJ
>n#umc
7a.^dG
sl8pR
-R9`Edp
M.H;6$
w5_.Io
HdOD~/
Y[}s\W
//!s={
YcuY2j
dbnn;.
m,a#\M,;
jN;+)O
8 )S?K
i^hu0{#
NFfD]#V|
@V)T@}
U!n=#q,p
Ms{iT
RYTgs`
8l=h17
!Eb*9GwU
se*qW9
|n{a]N
f#A&a0=
I_c\aZ
vK_1Dwe4
k88[H~
0L\-_k
QvSa*UI
^bO\NL
xxhq/uw
,D">a\
5K2{i4$Yj
@<WohY
d1qS)&t
LQ5uKL
LH9vg}j
eJxPmv
WMbH;(
>)^g?S
O37qR.
W2l}9f`B
(lkn\U
HbPBDk
K4!(p2
py{KF.e~dD
?joe^4
%Oe:^Dz
n"7XE1
gk,]n`
A|a`7N
tJ{T}v
ck&z>Z
A{F*;x$
NKeu$3"
C@w/,D
$GYKW\
GK}B 2
2Q}KJ^
Z(3G~
6ZZ6\S
3Qy'FQ81`
A-*yzy
)}kus&
ef5hoZ
]#+|fa
;Dc-V>
Bf6a"-
Bs>:=_
+^^,aY
by- /7
nJLZ>>
7!zNHX
Qw:`wI
]Ksi '
B@<;K/
,~g&]y
8Q:q.BY
HsxUYf
^j)q5
"{oqH&aj
Q18D{*v
l@)MU+.
/oxn'<
\ahl>h
j"6/wR
Z@M5P
`zU_-o
.vy,yE!
&J5*4q
C69fg>Z
p$qS8%
A2(A~2c
@H}h`{
L[+%u(
8hPeWf(5
*N\_/yd
2>FJ-$>
1~@hs|
{oIbuK
MAyq/X
9w(0 W
UWYqFP
"%p"%-
!=qXE+ugkwz
"ge$:u
t-},xh
s\y* Nz
73,`:
SubC:e
rzEC{y
q9^,Dv1
Q=c3OX
,N\hxL
|{4\r90&
1)|dJX
R~JJ=.
Cm?)n
S21Y[^
{_?Y^0`@TPM
?)[fGk
CfVdt*5t
]#>IV6
US dg^
<*GK:{
9f45z0
"*GL\.r
g$1<U#(
OI%hm
YF`>M:z
d{!VjW)
X3Z`<!
2PE)LCv
_`o5bW
uY2DY@@
4fPYWXB
t-Tb/F
\%91m?g
7NEygG@
6y{O/t
LJ%\RU
D)bHJk
AVO5([B
KV/;;r
s]|"!.
~g4P8X
6L)`SN
&TRv:<
tnF2]n5)k
aRP`j,
HuJh,]
CJd8iv}
G)[\?>
S6@E0q5
w^Sxy7
YSdTz10
M\'DCc2$
,qZ|2a
|uw9(a
h1mlQ=y
'N{2gQ
laL\P&
XgQUy%\Z
v 2#*{
e.*"-w
188RHk
q/8\y\
9?A$bw
j%$m9J@
'SEqNM
|lWfiW,
6RaU $
+dZm[ohpK
#lKekf
__8R(
[ba`XL
Znb^#M9
\3Ebhd
^8@X>U
,@[PXTx
gPo/um
h[C[&?
&e;G_T
D9D1X/e0
9O9A>&?
Hr:>RIS
m!)!$>`
dO$O\T
pYsl{4
UJ#fuJ
bZ^qu{
@SRF7_
8{&E8ca
y*1DlQ
'_l3n,
fizYXx
aTXk=I~
^*VE[8|
8-D85APD
yQsJ.u
e.c.6y
}8}gu$
vBHDRt
/{xK0#
ZxNk(('_
%|tzr}W
D>cChh
/t2:]",
>"qPA
l{vgN1
w'I0FB
,&'1/|
RNJH6y1.
VrZaFK
:\&(S)d
^cO7"T
b`AJF>w^
90kySN
XRJ- )N
uf5]!k
(ol0^dL
KEn%qa#
IJjiU2
/j3$C.
}i{64T
^a9N2-
aw?p5%(b
l}#%Wa
UX{XY_
w-~sgK
gf3,jRx/
rhB(XK
4-iZkl
q1I'L
`Sb.'E
)b,TZ
,V:`A
>l5yh|t0C
05v&n:
&V7ddj
\AEE(dkw]
Z]Y >*
>%d?9[A
RVE35@
I7Wr~C|
Wn;IE7gu#
L{bz%|
W=o}W W
r*f,>Y
YCyl{0r
s)-[_
4_G+.l
L!o'!E+b
^9.M)A
-6lQRl
m2+h'?
8?1pp%
jgj"^
gd9+o`
ammT=tU
PiJ!!q&
G0!l@X
HxL0N$
uF'?]G
a*G7Z
u;Pa8'
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
EleanorVioletViolet.XYeA
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
VirtualProtect
kernel32.dll
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
Module
ResolveEventArgs
ValueType
Object
Stream
System.IO
w!8htS8LGTaF"zCJT{/v2,5t$
Attribute
c7&/aZ%:B0Xc*^B&]L?aw16k!
Environment
SpecialFolder
LoadLibrary
GetProcAddress
CloseHandle
WaitForSingleObject
RuntimeFieldHandle
FileAttributes
Delegate
MulticastDelegate
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
Exception
CultureInfo
System.Globalization
IFormatProvider
System.Web
BrowserCapabilitiesCodeGenerator
System.Web.Configuration
DirectoryInfo
FileSystemInfo
FileInfo
ConfigurationException
System.Configuration
HttpParseException
StringComparison
Encoding
System.Text
TextInfo
ResourceManager
System.Resources
818729D56EADB5AAE6DBC2939D18340D665E8DFFEA53288840AE7FA10C867C27
EleanorVioletViolet
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
AttributeTargets
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
String
IntPtr
op_Explicit
UInt32
GetTypeFromHandle
GetMethod
Concat
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
MemoryStream
ReadByte
get_Length
RuntimeHelpers
InitializeArray
get_UTF8
GetString
Intern
Buffer
BlockCopy
GetElementType
CreateInstance
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
get_FullName
get_Name
op_Equality
GetFolderPath
Replace
Combine
op_Inequality
GetAttributes
SetAttributes
Exists
Delete
WriteAllBytes
GetDelegateForFunctionPointer
Console
ToString
WriteLine
get_BufferWidth
get_CurrentCulture
Format
HttpRuntime
get_ClrInstallDirectory
get_Exists
Uninstall
GetFiles
Create
get_Filename
get_Line
get_BareMessage
get_VirtualPath
get_Message
get_InnerException
Substring
get_CurrentUICulture
GetConsoleFallbackUICulture
set_CurrentUICulture
get_OutputEncoding
get_CodePage
get_TextInfo
get_OEMCodePage
get_ANSICodePage
get_Assembly
WrapNonExceptionThrows
me design examine.exe
Asystem move they plan service create quick network red cosmos.exe
integrate learn object
'innovate we change lazy decide (c) 2024
$e5eda08d-da08-45c0-ae32-f19c4da4ba80
4.1.3.4
AllowMultiple
Inherited
2Microsoft.Build.Tasks.StronglyTypedResourceBuilder
4.0.0.0
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
4.0.0.0
aspnet_regbrowsers.exe
Microsoft Corporation. All rights reserved.
4.8.9256.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
system move they plan service create quick network red cosmos.exe
FileDescription
me design examine.exe
FileVersion
4.1.3.4
InternalName
EleanorVioletViolet.XYeA
LegalCopyright
innovate we change lazy decide (c) 2024
OriginalFilename
EleanorVioletViolet.XYeA
ProductVersion
4.1.3.4
Assembly Version
4.1.3.4
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.hc
ALYac Gen:Variant.Jalapeno.18876
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Trojan:MSIL/Generic.4e6ed7a6
K7GW Trojan ( 005b61691 )
K7AntiVirus Trojan ( 005b61691 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.GCY
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Agent.gen
BitDefender Gen:Variant.Jalapeno.18876
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Jalapeno.18876
Tencent Msil.Trojan.Agent.Pgil
Sophos Mal/Generic-S
F-Secure Trojan.TR/Drop.Agent.mxuoy
DrWeb Clean
VIPRE Gen:Variant.Jalapeno.18876
TrendMicro Trojan.Win32.AMADEY.YXEKRZ
McAfeeD Real Protect-LS!35AC830AD122
Trapmine malicious.moderate.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.Jalapeno.18876 (B)
Ikarus Trojan-Dropper.MSIL.Agent
FireEye Generic.mg.35ac830ad12275b6
Jiangmin Clean
Webroot Clean
Varist W32/ABTrojan.BUBV-5398
Avira TR/Drop.Agent.mxuoy
Fortinet MSIL/Agent.GCY!tr
Antiy-AVL Trojan/Win32.Sabsik
Kingsoft Win32.HeurC.KVMH008.a
Gridinsoft Spy.Win32.Gen.tr
Xcitium Clean
Arcabit Trojan.Jalapeno.D49BC
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Znyonm
Google Detected
AhnLab-V3 Dropper/Win.Generic.C5695517
Acronis Clean
McAfee Artemis!35AC830AD122
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/Chgt.AD
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXEKRZ
Rising Dropper.Agent!8.2F (CLOUD)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Gen:Variant.Jalapeno.18876
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[dropper]:MSIL/Znyonm.Gen
No IRMA results available.