Static | ZeroBOX

PE Compile Time

2072-08-02 07:44:21

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000594b4 0x00059600 7.99642098746
.rsrc 0x0005c000 0x00000568 0x00000600 3.95129631086
.reloc 0x0005e000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005c0a0 0x000002dc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005c37c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Jzrmxxsxx
Jzrmxxsxx.exe
<Module>
f6lshqutfBFQsuBKVq
E81ve4l7gTewYMYpSo
Object
System
mscorlib
Ry9tDvjBMcAPboZmgT
NlHx0GwAv11wPmUIw4
oXuAABWc97vwr6n7GS
yp7tnUBIjlVKaPiHRv
fUfvij5hoM8X4mlUZA
p5Odug3hHcwPcELPv2
Settings
Jzrmxxsxx.Properties
ApplicationSettingsBase
System.Configuration
<PrivateImplementationDetails>
DQlgelCxMyIXYWrEjW
ValueType
m8DD424280B2361C
.cctor
p1XMkUa5d
IEnumerator`1
System.Collections.Generic
MethodInfo
System.Reflection
Random
GetMethods
Func`2
Boolean
IntPtr
Enumerable
System.Linq
System.Core
IEnumerable`1
GetEnumerator
get_Current
MemberInfo
get_DeclaringType
get_Name
String
InvokeMember
BindingFlags
Binder
IEnumerator
System.Collections
MoveNext
IDisposable
Dispose
vaKVXy2v4
TTR6eVBIP
RTnGDtwEn
op_Equality
yFYs4Wn2D
System.Security.Cryptography
ICryptoTransform
MemoryStream
System.IO
CryptoStream
Create
SymmetricAlgorithm
set_KeySize
Convert
FromBase64String
set_Key
set_IV
get_Key
get_IV
CreateDecryptor
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
Stream
CryptoStreamMode
ToArray
DJHUjX9Hx
AppDomain
get_CurrentDomain
Assembly
HNVFmcE5f
GetType
If1ygkjsj
GZipStream
System.IO.Compression
BitConverter
ToInt32
CompressionMode
defaultInstance
get_Default
SettingsBase
Synchronized
Default
65325106BDFD9EEEB6D3767D636014103166D9AE493029A7882801A3F7D90179
ExtensionAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
WrapNonExceptionThrows
$edea8b84-e55f-4487-aae5-9e76ccac0523
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4Y
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
$$UCcQVqc
&Cj0[RQ]
.X*48a
~qf)>bL
Kf2"8U
Br1J=D
\X:B5X
tNdWye
A2]BsO
Y.a'/, x
FJhW/J_
a-:A<T
#2lTzgA"rOxO
ePqAr%
V)2Zcv
e].W?^
rl~39P:>
OEFbsSG
3Q&KP}CL9
A72ug5
gazsrrt
%rq4/N
2/ cm2
r[gp\a
!Z48"7
~n$U?
\b2Pv?0
MhkriS
s`FuH}
j;t8STV
dqc]|R
BA:)q_
N|F<*cy
vH H/'
q=pOS8
^R.=0a>
^W"(5Bw
":|}%k4
10e=.
S)FE;Z!
qxYG#_
8Jjpn*
%v\9JE
M35.z~:>
a4':%L;
SA#uC^
t3(W,
I.|:[2a
?Bk6;K
`4)K=6m<
n{<77e$
>+=5#{
\&SusYv
h?8p@
`X>'&!
gP@`)%
S{HELY
GK2^xn8
<{bTkj
BRMz[8e
kAeS2(kU
(p2qjH}
`.3,Rb^
vYD,5E
ziK}^7}
3~f*~n
Pso84Z
e`V}5DE?
t9qo,8
WUn?dK
nWpQo\^
`Je1@PA
aUjVS=KXu9K>
kd}IffAj:C
i|hMc`
`?rN(T
{Qg@fZ>
{iEaJi
Jfh0pe
INQo-1
Qa7cD]
8OUTIK8
l@fyC'J
G6|WRU
n]06|Ob-&
7}e%t6Z
c9b~v]d
KK8It=
w:[$_]
`kQsYh
)*Jj/'
(|<J<*Cv
+&wc.,
_81m^$
_9LR"N
T(-mYC4NSo
:#c6h>
m=X8L%
CqS4Y$
M)Hl*Q
zs)35,
p<'Vp.
6\X?\:1
PP,4M]
)Kq\rc
|16e?u
Gg]gWJ
sWSggV]
sbW~'J+:i
L.7[\`
zjCjo}
RmD+jL
N-gul"
J}[~#-q:
u3(Q#p
T`3Rx;
GRH|J3yV
CLpO$hBA]
\N<]zN
~[xJ\^
p+_6K7
QfPv>U
)v@R="
L.upa@
dJ"I"V81U
B-ss[o$_
G&5N'IetW&
9~;[4c
UiUlv
HwZTzZ
;E8EO2
RwGO~\I
.?u/=B
@:^>[6E
v+s!l,
cA>1b!*Dvab
Al1-`t
M*6e:D
IDF?vm
p*vT.|
yr5]-4
.p"5MW
SJa)$)
a$:^}%
wvDkMMOK
p^%F=.
(j9Wm:a
z}&$ k
K4i|"4F&
*^)~>]
v:0qh\
Je0H&-C
'|uEtQau
!t!6l2g
;0/$Wkb
/up9;z;b
dlmkNY
}mEc$>
Stz&wz
G]y`(e
5-u)IhhA5
D<'=\>
heF"rUa3#/
^1id[Z
4,X7jh
{fR;ti
\EsWwu
_.wF-(
K%>(JT
`4K2?
=jtcxB
}QAFan
>PGZ(9j
;Kx`dK
-nl)zW
_(sHGuy
v`B&c:
p$QF^d
+DDVEBR
nd$=i`b
B;!\dS
}vZegSh
w2[lOBkc
8S(~duu
N3j^Nx
%Ajf(!"}
mQ|d[N
?6B:pHx
;?<De
|G*[_;
}qOUP`
3C9ZeN|d*3H
pSk"\ArC
IJx#>h
RCwu=T
?fe{8
_-D}jD
iyAtXMc/
dNmYZM
}LMO
#YDSOq
xZ5R)O
P%L2%e
0SEG.<-=
LX?d#a
GA@&;S
$cV]S4
iQyfRf7'a
NjP8_9BPMa
>IYHjM
(Apq+\%
/_'=R%J
GlCz$'
9c;@x
,AuVYJ
yUc%+g
;)*&BE6
rL(2Hb
vpi\hb
Xe&*"~
U7%xPG
4i)]"h"
M*];"+
;BQluR
v-{+Hz
i aOF?
l;3yVD
XMFO\R
,7@wVg
uEpDb%
|FUKlC}C
*aK~/ns
aa7QLg6
Z}c~*
ShNi%E5QB
0T-a1R
@Di&q't
A2$W%#
gS0VeCZ
v'^ZB2'l
`60 1h'8J
p76*NeD
lDkIc4
vQN70)
Qy>IZk
#J@!'C
ViMewu
!~blr,
>WBnh!uvn\PB
I^4e}
H/1No}t
>6mK-0
L<Ya!*
pvIv#O
l]"?A/
Je?AY3X
f_xvhmU
]QWtX
f-z6d l
x2Cjokp
=5^_HC
UD[}T#
7wn;JLa>
HB?Mvj
61WFdS2
9HAcmd
A4:^=f
tD>LJ
t3I0na
V#75FG
*R(/Xi
]$^8SCr
a=Kc@~
,YXYJN
.i>H[l]
j OA,y
H0C-/Vg
RO-+|h
^/~;O|
>:W"<Y
X*u7,w
(~I)]$
P/;',F].zi?
%lRS$Ef<
dZ|[rp<^
@LWh1U,
$k8*hJ
j9?8\U%
TdZ`9P
{dz 3
f<I0oj
H'H *7
gpd6I:F
`O:h52
h-hi$S
XaVISs
pK%W(NeI
Obj>\"K9!
P7RVh|S
Ls\{%by
V'l}`d8Z
CH%**|W
f@s:WU(
12RHA}
?-$6!K
"Ua.M=
Q^`@5a
ha[W3`
(yt]AI
_v!@0]
x^}K?T+H$F
KVI "*
kqhYwj#
<gGEuu
r`X&(b
ZA_gX|
8ng;D*{L?`.
slG1xH
]m=mxV
V,Z2?CW$
/BD}.Bw
5~M2$e
HE*'Fp
FCJ)Yn
^hwO.
g6{1py
sl[qCr
Bb_]2>
ui7q^eq
qoWq=v
e)H26_3
E*g#!M7
C#RMO*[u
ojZ.(p
/b5^QC^
|[-nh~
>-7gWcj
ISJz7c
km7tNWCy
=d"2RD
PMx5 `
0q^F9u
$GWr!/
y*wFSg[Lu
NVk!Dr
(/W$2)n
<rkmk8
#GI3}[
8pzxZx
L!G^R[
k}bq~o
"PcBeSDGN
4WjkKR
r+vz$Oy
c+@n[w
IRBX1I&
FwDjL;
we@23,&{<
Wc#\sg
VBx'eU
'1>+E,
Iwi&B5[
r#aW?D
i]Sq;CNpj
#dqL))`
[ZD42w
3N NDf
p"uf]gx
so&<I@
90:E2.
AVxmK
57CR 6
w8=a[H
UwlmBAv^
X0\-*YSJ
Fjq@/K
*Gh~B,
hu[mR|c
;l,*gkO
8[qd-O<Y
Z@*<`;
aCLzm|f-
mU@]ZR
(K5mJ9
M_}Sbz
/*-J>"
YgCB$;
1c})!n
j} PbQZ
|'<Id[
1/O>9m
BqH.N/
;o+Hfa0
q?Gz-"
t}xN`?/
Sc9'=e5'
GOn{C#Z
Pn>}"g
TiF\`qf
s!.|W*
y=I! #G
t*y_3^
0l*ih1D
WE+;D1
N">tEi
]0mA?t
[[00Er
9n'syk|'
zJT'$B'
ghuahS0Q
O$37Al
#X.26e
y,>F.{
$GR=g(
!.Al!D
|[&w r
`0d&L)R
yCXc(R\CO
JD"1O>
/^ek1+
5Z'%vB
hN&~`WyN
d]NshP[
%]U_w$6
P+`AUV
'qK=Rv
A)"Vws
&_aM;.
+de-JA
Tq}6$)
iDoH/e
w@33 )[
HmmCZq
(n[WYm
qRxr8VuB
T}JMS9
&@GNlMXi
H*iOFn4
5p}QG$
|T)0EN
^sPAW^
/Qq*H3
FMSG;~0
NAwl=E~
;+\]0;
*8@n\v
EAvv a
?wJ;`bF
!@mv7UT,
=zczX\
T> 87+
Y%R&6(
;"dgXTAqW
ns_,)1
a<[YqH
:,D(6/
@^@VQW
ZEd=mx
yvJY9S
h}k&TR
TlcDb#sQx
6iQ5kW
]{g1M0]
Q~syhY
},vM0%"
.`v`!|F
z~3Ua\
;A\99a3
S^OiV[
scCQ[0
,p\WbQ
W}\=F:
B'uEncI
-Kggdul
;@57J$B4
!'bBQl
B_(%3F#
+VopYG
=$WI |
"[f2#4}
GbH;]"
"{dCH}
v"n@*>Ae
D,xL^e
$B|.0!
-Kn6[Jp
J'$b<.ey
AmlO-E
<5JS/
sVz7ED
rMp)+F
Kk+]os
N[J'C3
&98MT3
'CuWt'
6K5U)~
d7iOa;yO
o3X-f_K
,M'?4sa
fu+:^*
xZ@\}B1
1pV'vT"wc
cR<5p\
K\dph0
/*ltU|
msw,gN
OA\&DF
331Iv>Z
'P{06V
xpniBE
4Yc)wyX
4v.K9&4ix
}UY!Dn
W-HO79
lb^N[#
GSVQ$mBs
MV RV)2{
bykaLl+bk
m1CB0F
KwxR\6
h'NhH0
=@{!On
cC$G"1
[?z6VN
T6AQD!
.Rg?HW
#]NHv8
uZFWye
ws?A3*
,ZpR+{F
AEw6{#
AuU|SZ
m0D]@(
tQt]r`
bDc5eC
gC$J_a
(+p@E+*
QO )96
`\c-,s
u<]F"q
B9Tum4
L7hui9
Nqh!UO:
MI:PO}r
PUznFK
LPBaEf]Rg
w[D(SI
f$R[<]%G
4b.C|W
G[>z+q
nO"I'g
7 X:HD(a
^b>A.;o3W
e1!E/G
+<iwd=
!<S;#l
o*c1>LBe
(L~m[.
m!9Dd/
86[1A,
(;[*3#
k5_t~N
n!)w\
9%TU:-
FKEl#7
fO6NYL
p2Ld}JP
VQ(5;;/
x\$A)7
m'T"YO
S&(We1
BXzT|,
r=9V^y
@lcf#tSQ
egpJ[/
IU\}";
g677[P/
K:$l%Hwb
aOG11w
zt0C-Q
*6gC,{
hJ`RzF
5^]~YB_F<
2ya 9P
<F"Hno
A!(a`Qt
Y+ml_S
8jw]vL
=rDl$$
u9C:\)
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
BK6XoeMuL
7lIJ/xIUMCmJYSmFJ1hR2k7X2/sO3Iu/MzHaGwk81Fo=
AvBT0njMEeI3ca/KxwALog==
x3XasEDFHHFhXAv4qb.biYtPWNQrmaiWAWt6j
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Jzrmxxsxx.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Jzrmxxsxx.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal cld.trojan.msil
Skyhigh BehavesLike.Win32.Generic.fc
ALYac Gen:Trojan.Mardom.MN.9
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/GenKryptik.97f9951f
K7GW Trojan ( 005c0eb21 )
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Symantec Downloader
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/GenKryptik.HGBG
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Backdoor.MSIL.NanoBot.gen
BitDefender Gen:Trojan.Mardom.MN.9
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Trojan.Mardom.MN.9
Tencent Win32.Trojan.Dropper.Nzfl
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
VIPRE Gen:Trojan.Mardom.MN.9
TrendMicro Clean
McAfeeD Real Protect-LS!E1408ABC6C49
Trapmine malicious.moderate.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Trojan.Mardom.MN.9 (B)
Ikarus Trojan-Spy.MSIL.Agent
FireEye Generic.mg.e1408abc6c49f683
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Kryptik.LYU.gen!Eldorado
Avira TR/Dropper.Gen
Fortinet MSIL/Kryptik.AFN!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Exnet.gen
Gridinsoft Trojan.Win32.Kryptik.sa
Xcitium Clean
Arcabit Trojan.Mardom.MN.9
SUPERAntiSpyware Clean
Microsoft PWS:MSIL/Dcstl!rfn
Google Detected
AhnLab-V3 Trojan/Win.Leonem.C5727655
Acronis Clean
McAfee Artemis!E1408ABC6C49
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:TaoLI+M3XJSQN3YGyNp43Q)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Gen:Trojan.Mardom.MN.9
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
alibabacloud Trojan[dropper]:MSIL/Wacapew.C9nj
No IRMA results available.