Static | ZeroBOX

PE Compile Time

2086-10-21 06:37:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00009d54 0x0000a000 5.82572932559
.rsrc 0x0000c000 0x000002a8 0x00000400 2.1645038876
.reloc 0x0000e000 0x0000000c 0x00000400 0.0446870062539

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000c058 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<>c__DisplayClass2_0
<SystemDataAutoIncrementBigIntegerW>b__0
<>o__0
<>p__0
<>c__DisplayClass2_1
<SystemDataAutoIncrementBigIntegerW>b__1
<>p__1
Func`1
IEnumerable`1
CallSite`1
point1
kernel32
User32
ToUInt32
ToInt32
<>p__2
cbReserved2
lpReserved2
dwTextFlags2
point2
Func`3
ToInt64
isWow64
Func`4
__StaticArrayInitTypeSize=226
FE11E3722805C72BC0137B3817E9B4977419FA88
<Module>
<PrivateImplementationDetails>
SystemNetUploadProgressChangedEventArgsA
FromLTRB
SystemCollectionsGenericSortedSetcDisplayClassB
hSrcDC
GetWindowDC
SystemNetChunkParserReadStateC
System.Drawing.Drawing2D
SWP_FRAMECHANGED
MF_DISABLED
MF_GRAYED
TPM_RETURNCMD
WM_SYSCOMMAND
MF_BYCOMMAND
SystemDataSqlClientTdsParserStateObjectPacketDataD
SIF_PAGE
SC_ARRANGE
SIF_RANGE
DCX_CACHE
CCHDEVICENAME
SWP_DRAWFRAME
SC_RESTORE
SWP_DEFERERASE
SC_CLOSE
DCX_VALIDATE
DCX_INTERSECTUPDATE
DCX_LOCKWINDOWUPDATE
SWP_NOACTIVATE
WM_PASTE
SC_SCREENSAVE
MF_REMOVE
WM_MOUSEMOVE
SWP_NOMOVE
SC_MOVE
SC_MINIMIZE
SC_MAXIMIZE
WM_NCCALCSIZE
SWP_NOSIZE
SC_SIZE
MINIMUM_COLUMN_SIZE
CHECKBOX_SIZE
RectangleF
SystemCodeDomCodeTypeParameterCollectionF
RESIZE_ARROW_PADDING
SWP_NOSENDCHANGING
SystemDataCommonSqlXmlStorageI
WM_MOUSEWHEEL
SIF_ALL
SB_ENDSCROLL
SC_HSCROLL
SC_VSCROLL
WM_VSCROLL
HTBOTTOM
WMSZ_BOTTOM
DCX_CLIPCHILDREN
TPM_LEFTALIGN
DCX_EXCLUDERGN
DCX_INTERSECTRGN
SWP_NOREPOSITION
MF_BYPOSITION
HT_CAPTION
WM_NCLBUTTONDOWN
WM_LBUTTONDOWN
WM_RBUTTONDOWN
WM_KEYDOWN
VK_DOWN
SCROLLINFO
MENUITEMINFO
MONITORINFO
System.IO
get_SystemDataSqlClientSqlAuthenticationProviderManagercDisplayClassO
DCX_PARENTCLIP
SC_CONTEXTHELP
WMSZ_TOP
WM_LBUTTONUP
SystemComponentModelIListSourceP
SystemComponentModelSyntaxCheckP
SystemNetWebProxyScriptHelperP
SWP_NOZORDER
SWP_NOOWNERZORDER
SC_MONITORPOWER
SC_SEPARATOR
MF_SEPARATOR
SystemNetWindowsInstallationTypeR
MicrosoftSqlServerServerSmiStreamR
SystemReflectionICustomTypeProviderR
DCX_CLIPSIBLINGS
NCCALCSIZE_PARAMS
MAX_SUBITEMS
SIF_TRACKPOS
SWP_ASYNCWINDOWPOS
SIF_POS
DCX_NORESETATTRS
SWP_NOCOPYBITS
get_cS
set_cS
HTBOTTOMLEFT
WMSZ_BOTTOMLEFT
HTTOPLEFT
WMSZ_TOPLEFT
HTLEFT
VK_LEFT
WMSZ_LEFT
HTBOTTOMRIGHT
WMSZ_BOTTOMRIGHT
HTTOPRIGHT
WMSZ_TOPRIGHT
HTRIGHT
VK_RIGHT
WMSZ_RIGHT
SC_DEFAULT
HTCLIENT
WM_NCPAINT
WM_NCHITTEST
SC_TASKLIST
WM_CUT
SystemDataCommonDbSchemaTableT
BunifuFrameworkUIBunifuVTrackbarT
SC_MOUSEMENU
WS_SYSMENU
SC_KEYMENU
SystemNetSocketsMulticastOptionU
SWP_NOREDRAW
SWP_HIDEWINDOW
SC_NEXTWINDOW
SC_PREVWINDOW
SWP_SHOWWINDOW
DCX_WINDOW
SystemDataAutoIncrementBigIntegerW
SystemDiagnosticsPerformanceMonitorW
WS_MINIMIZEBOX
scaleX
offsetX
SC_HOTKEY
WM_COPY
scaleY
SystemNetWebSocketsWebSocketHttpListenerDuplexStreamMethodsY
offsetY
SB_HORZ
SystemDataSqlClientSqlDataReaderALTROWSTATUSZ
value__
SystemNetWebProxyScriptHelperPa
WorkArea
workArea
MinimumAlpha
MaximumAlpha
Enigma
CloseThemeData
OpenThemeData
dwTypeData
dwItemData
SizeOfRawData
PointerToRawData
SystemDiagnosticsTraceb
SystemIOCompressionZLibNativeInflateInitDelegateb
mscorlib
GitHub
e_magic
System.Collections.Generic
CustomQuadratic
dwThreadId
iStateId
dwProcessId
iPartId
hThread
get_CurrentThread
Rounded
FocusedChanged
ColumnStateChanged
SubItemChanged
ColumnChanged
SelectionChanged
SubItemCollectionChanged
ColumnCollectionChanged
Dashed
hbmpChecked
hbmpUnchecked
DwmIsCompositionEnabled
enabled
Planned
Pressed
Outdated
HelpWanted
BytesToStringConverted
ClosedResolved
lpReserved
Invalid
<cS>k__BackingField
<Empty>k__BackingField
ReadToEnd
HoverEnd
Append
SystemNetGlobalProxySelectiond
DrawThemeBackground
DrawThemeParentBackground
method
SystemCollectionsSpecializedNameValueCollectionhasd
NewtonsoftJsonUtilitiesStringUtilscDisplayClassd
Replace
hInstance
GetInstance
source
GetHashCode
exitCode
SizeOfImage
SendMessage
DrawThemeEdge
BreakingChange
EndInvoke
BeginInvoke
IDisposable
IFormattable
Unreproducible
HatchVisible
WatermarkVisible
BorderVisible
TextVisible
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
handle
RoundedRectangle
get_ToRectangle
rectangle
DebugLogFile
Console
lpTitle
hModule
GridLineStyle
HatchStyle
DefaultStyle
dwStyle
dwExStyle
procName
ComponentUpdateMethodName
DeviceName
fileName
ThemeName
DllName
lpApplicationName
SystemComponentModelWarningExceptiondtionName
pszSubAppName
lpClassName
GetClassName
lpWindowName
hTheme
SetWindowTheme
Uxtheme
lpCommandLine
WriteLine
SystemCodeDomCodeMethodInvokeExpressione
ValueType
SecurityProtocolType
ExpressionType
flAllocationType
BorderType
UserType
EffectType
SystemComponentModelDesignDesigntimeLicenseContextSerializere
System.Core
Feature
Signature
VisualPlus.Structure
get_CurrentCulture
ReleaseCapture
ImageBase
HelpMinimizeClose
MinimizeMaximizeClose
HelpMaximizeClose
HelpClose
Dispose
ClosedDuplicate
Truncate
GeneralInvalidate
Create
MulticastDelegate
Inflate
DebuggerBrowsableState
fState
CallSite
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
TargetFrameworkAttribute
dwFillAttribute
SecurityPermissionAttribute
DescriptionAttribute
FlagsAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
DebuggerDisplayAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
get_Value
SetValue
KnownIssue
VisualPlus.Native
IsThemeActive
Dianthus.exe
dwXSize
dwYSize
get_Size
set_Size
cbSize
HatchSize
MinimumBorderSize
MaximumBorderSize
ProgressSize
dwSize
MinimumCheckBoxSize
MaximumCheckBoxSize
Minimize
Maximize
SizeOf
get_sizeOf
HandleRef
System.Threading
Ascending
Descending
MinimumRounding
MaximumRounding
MinimumCheckBoxBorderRounding
MaximumCheckBoxBorderRounding
BoxRounding
Ceiling
System.Runtime.Versioning
Refactoring
FromBase64String
DownloadString
ConvertToString
lpString
Diagnosing
Selecting
System.Drawing
ColumnResizing
dwNewLong
GetWindowLong
SetWindowLong
SystemSecurityCryptographyXCertificatesXChainElementCollectiong
Stretch
NewtonsoftJsonLinqJObjectGetEnumeratordh
SystemConfigurationSettingsManageabilityAttributeh
SystemCollectionsSpecializedNameValueCollectionh
TemplatesFilePath
GetFolderPath
PathCompactPath
pszPath
get_Width
set_Width
ColumnWidth
get_Length
IntersectsWith
SystemComponentModelDesignISelectionServicei
SystemComponentModelIListSourcei
SystemDataLoadOptioni
Dwmapi
Shlwapi
SystemNetConfigurationSmtpSectionSmtpDeliveryFormatTypeConverteri
lpProces
AsyncCallback
callback
AllocHGlobal
FreeHGlobal
Vertical
Marshal
Normal
Horizontal
Visual
System.ComponentModel
gdi32.dll
kernel32.dll
user32.dll
uxtheme.dll
dwmapi.dll
shlwapi.dll
SystemNetRequestLifetimeSetterl
MemoryStream
lParam
lpParam
wParam
get_Item
hbmpItem
InsertMenuItem
uIDNewItem
lpNewItem
System
SystemNetSpnDictionaryValueCollectionm
get_Bottom
bottom
lSystemNetDnsResolveAsyncResultm
SystemSecurityCryptographyCAPIBaseCERTOTHERNAMEn
InOutRepeatingIn
InOutIn
Boolean
GreaterThan
LessThan
ClientToScreen
hToken
hNewToken
lpNumberOfBytesWritten
get_SystemComponentModelEditorAttributen
set_SystemComponentModelEditorAttributen
CreateRoundRectRgn
ClosedByDesign
DrawThemeIcon
ListViewRegion
Discussion
get_Location
set_Location
ThemeResourceLocation
location
Relation
Animation
BinaryOperation
Documentation
System.Globalization
SecurityAction
action
System.Reflection
GroupCollection
CompareDirection
AnimationDirection
trackPosition
uPosition
fByPosition
DllNotFoundException
ArgumentOutOfRangeException
InvalidOperationException
AbandonedMutexException
System.Runtime.ConstrainedExecution
ToggleButton
SystemCodeDomCodeRemoveEventStatementn
NeedMoreInfo
DefaultCultureInfo
GetScrollInfo
lpStartupInfo
GetMonitorInfo
DefaultNumberFormatInfo
CSharpArgumentInfo
PropertyInfo
hrgnClip
get_Top
lpDesktop
Microsoft.CSharp
DrawMenuBar
Linear
FileHeader
OptionalHeader
StreamReader
TextReader
IFormatProvider
provider
StringBuilder
SpecialFolder
TemplatesFolder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
ToggleBorder
ServicePointManager
Earlier
DateTimePicker
Darker
Beginner
DateTimeComparer
hWndInsertAfter
Lighter
ThemeExtensionSupportedFileFilter
Center
GetDelegateForFunctionPointer
ThemeAuthor
hStdError
get_NumberDecimalSeparator
GetNumericListSeparator
.cctor
hMonitor
monitor
SystemTextRegularExpressionsRegexCharClassSingleRangeComparerr
IntPtr
SystemCollectionsGenericSystemStackDebugViewr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
bInheritHandles
LVControlStyles
Themes
GridLines
LVActivatedEmbeddedTypes
ListViewChangedTypes
GridTypes
ShapeTypes
ListViewHoverTypes
SortTypes
MouseStates
ColumnStates
ListStates
lpThreadAttributes
lpProcessAttributes
dwCreationFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
SetWindowPosFlags
dwTextFlags
ContextFlags
fuFlags
dwFlags
Equals
Labels
Contains
System.Linq.Expressions
System.Text.RegularExpressions
System.Security.Permissions
NumberOfSections
SortDirections
Questions
ControlBoxButtons
nTrackPos
GetCursorPos
SetWindowPos
get_Groups
get_Chars
dwXCountChars
dwYCountChars
SizeOfHeaders
fsModifiers
RuntimeHelpers
VisualPlus.Enumerators
hProcess
BorderThickness
Brightness
GetProcAddress
lpBaseAddress
VirtualAddress
lpAddress
InProgress
VisualPlus.Constants
ClipboardConstants
FormConstants
DefaultConstants
ListViewConstants
ControlBoxConstants
arguments
Exists
Dianthus
Concat
SuperFlat
get_NumberFormat
format
pClipRect
lpRect
GetClientRect
pContentRect
pDestRect
GetWindowRect
Object
object
ColumnSelect
Intersect
flProtect
System.Net
Target
Offset
get_Left
get_BottomLeft
get_TopLeft
get_Right
get_BottomRight
get_TopRight
get_Height
set_Height
nHeight
height
op_Implicit
op_Explicit
BitBlt
Default
IAsyncResult
result
WebClient
NonClient
Enhancement
Announcement
TextAlignment
lpEnvironment
hWndParent
TextRenderingHint
EndPoint
WindowFromPoint
lpPoint
StartPoint
AddressOfEntryPoint
nMaxCount
HoverStart
bRevert
Convert
MergeSort
QuickSort
InsertionSort
SystemComponentModelProgressChangedEventArgst
pszSubIdList
pszClassList
get_Host
set_Host
EaseOut
InOutRepeatingOut
EaseInOut
InOutOut
BackgroundLayout
hStdInput
hStdOutput
System.Drawing.Text
System.Text
DrawThemeText
RestoreText
CloseText
MinimizeText
MaximizeText
cchText
WatermarkText
HelpText
GetWindowText
DefaultCategoryText
pszText
pContext
hSubMenu
GetSystemMenu
InsertMenu
SystemCollectionsSpecializedFixedStringLookupu
SystemNetConfigurationWebUtilityElementEnumTypeConverterv
SystemRuntimeInteropServicesComTypesIDataObjectv
e_lfanew
FindWindow
MonitorFromWindow
wShowWindow
DestroyWindow
GetDCEx
TrackPopupMenuEx
CreateWindowEx
iImageIndex
CloseIndex
MinimizeIndex
MaximizeIndex
nIndex
HelpIndex
ClosedWontFix
ComboBox
TextBox
DefaultDebuggerDisplay
InitializeArray
Consistency
RegisterHotKey
UnregisterHotKey
LoadLibrary
FreeLibrary
lpCurrentDirectory
op_Equality
op_Inequality
System.Security
Bounty
get_Empty
IsNullOrEmpty
get_IsEmpty
GetProperty
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
VisualPlus
The Enigma Theme
1X = {X} Y = {Y} Width = {Width} Height = {Height}
_CorExeMain
mscoree.dll
SystemNetMailBufferBuilderu
Expect100Continue
SecurityProtocol
SecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQ
ESecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQRE7exkMBnopFGgJPDp+Ex4cCgwPFkk3JSUwdQd9K1gyQwsFKS8KPS49LycSND8+HgF6Oj8qBwMLLh0AJRwoEDcJOh0wEygoEX5cFDQlH1kvMg47FQs7YSoMPHY=
pYiKzDKLemQ
The width must be equal to or greater than zero.
The height must be equal to or greater than zero.
\D*(\d+)\D*(\d+)\D*(\d+)\D*(\d+)
The RECT is empty.
{{X={1}
{0}Y={2}
{0}Width={3}
{0}Height={4}
\VisualPlus Themes\
DefaultTheme.xml
ESecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQWs/MhgpHT8oFxgFAy4zCQ==
ESecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQjc7IBgDPDk/KikD
ISecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQWojJyMcGSAwJRsGAFsdACd7IBAJFiYgCyY8Nx07WFA=
PROTECT
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQh4/MhgTJzk8NQMcDCEBDB15Gh8OJk1k
ISecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQWsRPRl2HQU8OmQbOy4eRw==
ISecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQwEnExh3KH4rKxMJO1sFFid4AVg=
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQjQFMh4MHSQHKBcDOy5yEBYTK1g=
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQmojOx4DHR0GAGgaAzEFABAcGhEPYjps
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQmtQeDQuGQQ/NQMlOCEBFh0cHiEPY0VpMxMSdA==
ISecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQms/eywDIzU/OhcbCFtyDyAMGlEJEE1k
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQmtQeDQuGRg/NQMlOCEBFh0cHiEPY0VpMxMSdA==
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQWs/eywDIzU/OhcbCFtyDyAMGlEJEE1k
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQTQ/MR4TeiAzKjkJAz4NEQ==
JSecurityCryptographyCAPIBaseCMSGKEYTRANSRECIPIENTENCODEINFOQDc7HRgpeiQGKwsAAzEvKh4nAgk0YiIpC3lOeQ==
dwmapi.dll
gdi32.dll
shlwapi.dll
user32.dll
uxtheme.dll
UpdateTheme
VisualPlus-Debug.log
VisualExtension
{ToString(),nq}
Unknown
Theme|*.xml
Unnamed
VisualPlus.Resources.Themes.
Watermark text
@C:\WindPROTECTows\MicrPROTECTosoft.NPROTECTET\FramPROTECTework\v4.0.30PROTECT319\AddInPPROTECTrocess32.exePROTECT
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Dianthus.exe
LegalCopyright
OriginalFilename
Dianthus.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.73825
FireEye Generic.mg.77dfc735d37c3f44
CAT-QuickHeal Clean
McAfee GenericRXOD-DV!77DFC735D37C
Cylance Clean
Zillya Clean
SUPERAntiSpyware Clean
K7AntiVirus Trojan ( 0056879b1 )
Alibaba Clean
K7GW Trojan ( 0056879b1 )
Cybereason malicious.5d37c3
Arcabit Trojan.Generic.D12061
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HON
APEX Malicious
Avast Win32:DropperX-gen [Drp]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
BitDefender Trojan.GenericKDZ.73825
NANO-Antivirus Clean
Paloalto Clean
AegisLab Clean
Tencent Clean
Ad-Aware Trojan.GenericKDZ.73825
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Siggen2.63839
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition GenericRXOD-DV!77DFC735D37C
CMC Clean
Emsisoft Trojan.GenericKDZ.73825 (B)
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Unsafe.AI_Score_100%
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/Redline.GD!MTB
ViRobot Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
GData Trojan.GenericKDZ.73825
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4397310
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKDZ.73825
MAX malware (ai score=82)
Malwarebytes Malware.AI.2034931719
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent!8.B23 (TFE:dGZlOg2VEnUKr0KKww)
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Small
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.HON!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34670.cm0@a0PzwKj
AVG Win32:DropperX-gen [Drp]
Panda Clean
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 Clean
No IRMA results available.