Static | ZeroBOX

PE Compile Time

2021-04-15 09:12:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003dfe8 0x0003e000 7.9225348114
.rsrc 0x00040000 0x00010c6c 0x00010e00 3.58729582312
.reloc 0x00052000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00040130 0x00010618 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00050748 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005075c 0x0000035c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00050ab8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-9&,s
Xffeeffefe
Yfeffeefefa
Xfeffeefefa
Yffefefeeffe
afefeffeefefa
Yffeeffeefef
afefefefeffehah
Yfefefeffehah
affeeffefea
afeffeefef_-
affeeffefea
q,fefeffeeffe
fefefeffe
feffefefe
zffeeffefeef
afefeffeef
9fefeffefefe
ffefeeffe
zfeffeeffeef
fefefeffefe
q,ffefeeffe
afeffefefefe
ffeeffefeefYa+
KffeefeffeefY
fefeffeefXa+
ffeeffefeY
fefefeffea
1ffefeeffe('
ffefeeffea(2
-5&d(k
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
alU0>1
`0>vt,KM
ajXtX43
5mM4+|.
5mnb=.W
4a4!5
N83.E,
oMpJ#un*!
'n62Uo_f
@45$R;
Yg[|U_
.EO]B5K
Kz>vd]
9 q0w`
g,!<Qy
$O)!I_
,+8%}zs
jTwA#/
AY~Ap?
+O:>h~
YUY^g*)
L|Z|`FT.
-s]={{*
'zfVcy
Bq"DiGP<
l(ntW71
~W =a&
aUIOov
<!*ggJ
+$t2B'
ZvsJ[E
Eq'P9[
v%lLBg"4
=JBk($
+aeqS!)
0M5z+!
>=`aI]
HQ&]0i
Ifj?>=
krO'yK
T~-X+@)
SM|RecC$
(Tw8}(yq
>;DL
k([xN1
xqt<a-
gwvvvvvvfv
7=&H~T
BEq?=;vT
EVQG14
f 0_(t
k<Jjq/
{%Tg>5
DwWJqw
*s+}5Cm
j#vq7^Q>n
i@u)dp
-ZGqlr1
L)ig/d
LIVP>W>
;[k+ 4
i}@vP_
!{Pr(z|
b`u*|>
gdy|1a
@YPjZU>
K!vGK6
\Y>teCY>
j2=k&'
Q6&gWT
@&U i%y
"g_z_7
70F::9
"s'*v(
RGT[`w
\Y:NTG
UJI_y:F
rFGjxr
Hg0^\m{
R#b-{m<
8w!,MRC
35(9(Y7w
:C;'/J
f(@Gv]
Z8#IKvC!(
rb-jmxj
X@|v,V
Z>>_di
}oe#.50g
p'A>b!
R.~*b.~
}xOaN"_
Yfa&5Z<:\
0:/J"R
Ak)#/n*]
qXF3nbc
EyHNBH
,1xV>
TS)GAqWX
`UZ;/m
QJfl~S
|BIL?-
Ee(e(5
tpccbk
=2Oe"C
:UBHnO
/C(,TR7
"f2\'3
{AQ]-dq
@6r{!.
BAwuPzb
1(Tn3N^
_#Pii?
hI4b]
yXW9[Q
o?x2xR
v5V_k:<
<K>Nju
~xkWzpj
a=?;9b
59{*tX
vs+fi?
CW|q9a
z4|={-
_kS_a
li.YA)
XO~sa)
eXIPpr7
b"/uz%\
@TFRrD
]pG<V\
jCD{:S
2%oS=g
4<(/6V
x}ZNIB
Z8au&;
!=YdFt
iHWOXC
lSqw[
D5|Fj:5
u+T1C!]
SCBZ\l
8nM%3#
P`r/D)h%
0"<cwV
}p^)"X
?GcZv%P
CVWEL#<
5zS1Z=
ka<.4]
ct^n*
Eu7"7
<Xj_(}
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
O4{'3S
P}</>Sf
wuhija
~d)o(s
IeDnV%
Z=Cr=J
HJJZhQg'
(I)cEe
q!{`sa
i<0nyQ|
COPgXOp
&v"""s
sD8pEG
cq$0>B
w4u>_NF
RM)|h(
]o!7sx
N0ssl8p8p
"+wj=_
bxMpf|
J^!6}^M
.|W0av
yw7kD3
4}uo+.
F6Rej3
@^ok77
)_(y}G-
j}#/,sC
qX%(M
~u@?'P
s.M@.N
J-hTTZQ
E9@>N+y
=!9{Br
ZBR'JZM=d
<O<LN
s: h''
S;MUz;H8
.m)?Uj
DocM*g!
"m[/wQ
4Ay<-CP)
I._kWe
QA[8%\`
l=G/QTO
mEWI[7
WlKQi9
&RekPTO
]4#XO7
VY$;ij
IIE {
K3oC3/
h[LlLA
44idRvRY
y&&#65
8-~D|D
''@>@t/#
-_$qRE
]U7b8TR
4oqUEuE
q ~VMe%
wrKS'z
wqol8$
StlN?l
`F83z1#
0;/g;6x
bvqss}{
ok@bEb
gB8/wqP
sC}GmJ{[z-
H+ebbZ
?tq~Ft
qRf-tuos
yF3#;Y
S]W["^
l[-9*qzky
D%[YSK
s3?9;p
y*9NtN
<ncz8~s$
v2rwTP
6e#.5.
+<n^Y)
!AR=!1
)Ghx/Q
IsNeEC
uYw+hA
"ov8i27
fxlTIM
mYu+#rE/
~)Q)aX?
M|Sf~/
|M/[62
JPhh6( 4
x^w*l9
g/7lMN
#xW}QF
g`o0wp
G|5y:NxR
|IcI;?
@DPDAPPX
}~}ES`
;0i~; O
g\2L,m
?18e_m
vaQ$j]
{*RM<kO
+AV[|k#
sMtw;h5
p;]'}K
qzeV?h7{
}ZM4~V
+G0(9w
DS-dSu
.c3Elf
ZAYt%
:5%!xxeK
Y^XM."4
J_^_\=P
"QKQW!luFG
?^$*j-
4tVxz(
'z9oC-
MdQS7N f
oUk[z<S
u0]=cOU7
X!S)b*
39yck6F
;u7S"&
SQ#xSPHO
1U Swt
`B%&V2
yEX}BbV
kcIkcTa
f11EvT
(wXrBb.
B1yHC
]P]^WXVu
P]NNWHZ3
fA|@|A
@*A;X~
A:Ao ]
Ac & 1
Ac & 1
>A ]
WPNqts
,xk!:ZI
((8;z;
g_wYrWw
SXFX"3
J89g{o
mmCOfk|
i?*((/
ny3/Ue%iSMQ
1enN-K
YV]FVS\
-"(f\.
75WW4v2
(pY;_.'
bJk]UumEe
^VTPW-)
=ILo%%
i%$z>+OM
K++]KmNN^
Uuyqi)
Llmn>!.
Ex$4,< 0
UtMY&L
ILJIYXY_G2
ZZWQWyK?Y
e%N?G?+
<##Cc}"
o ($,"*&.!
m5 qW8
YiKqJpIZ
5xPXT];\
(&FXJHp
!v<LNMo'
[]Yz=
]YYXKL
x {j#@/%
z`W+63,
.6\^xr
7~wX_M
`)*=DJ
+4AzhH
v4.0.30319
#Strings
Nnojr.exe
mscorlib
System.Windows.Forms
System
System.Core
ClassLibrary1
Microsoft.CSharp
System.Drawing
j.resources
WindowsFormsApp1.Properties.Resources.resources
costura.classlibrary1.dll.compressed
costura.costura.dll.compressed
FreeJsn
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action`2
Activator
AppDomain
ArgumentOutOfRangeException
Boolean
Buffer
GeneratedCodeAttribute
System.CodeDom.Compiler
Dictionary`2
System.Collections.Generic
IEnumerable`1
IEnumerator`1
List`1
IEnumerator
System.Collections
ReadOnlyCollection`1
System.Collections.ObjectModel
Container
System.ComponentModel
IContainer
ApplicationSettingsBase
System.Configuration
SettingsBase
DateTime
DateTimeKind
DayOfWeek
DebuggerBrowsableAttribute
System.Diagnostics
DebuggerBrowsableState
DebuggerHiddenAttribute
DebuggerNonUserCodeAttribute
StackFrame
StackTrace
EventArgs
EventHandler
Func`2
Func`4
CultureInfo
System.Globalization
IDisposable
CompressionMode
System.IO.Compression
DeflateStream
EndOfStreamException
System.IO
MemoryStream
Stream
IntPtr
Enumerable
System.Linq
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyNameFlags
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
ResolveEventArgs
ResolveEventHandler
ResourceManager
System.Resources
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
DynamicAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeMethodHandle
RuntimeTypeHandle
STAThreadAttribute
Single
String
StringComparison
Encoding
System.Text
StringBuilder
Interlocked
System.Threading
Monitor
Thread
TimeSpan
TimeZoneInfo
UInt16
UInt32
UInt64
Application
AutoScaleMode
Button
ButtonBase
ContainerControl
Control
ControlCollection
DialogResult
FormBorderStyle
FormStartPosition
MessageBox
TextBox
<Module>
Settings
WindowsFormsApp1.Properties
.cctor
f0659e5905454a5e99b9752afc78b700
value__
dbvD1a
ebvD1a
dbvD1c
ebvD1b
fbvD1a
fbvD1c
bbvD1a
GetEnumerator
Dispose
GetFrame
GetMethod
get_DeclaringType
GetTypeFromHandle
TryGetValue
GetExecutingAssembly
GetCallingAssembly
Append
ToString
GetManifestResourceStream
set_Position
get_Unicode
GetString
Intern
set_Item
get_Count
GetName
get_FullName
GetPublicKeyToken
get_Assembly
ReadByte
BlockCopy
AddRange
get_Name
GetBytes
get_Item
get_MetadataToken
Synchronized
get_CurrentThread
get_ManagedThreadId
get_CurrentDomain
GetAssemblies
Equals
get_CultureInfo
EndsWith
get_Length
ToLowerInvariant
IsNullOrEmpty
Concat
ContainsKey
op_Inequality
op_Equality
get_Flags
Exchange
add_AssemblyResolve
get_Now
CreateInstance
get_Date
Format
get_Day
get_Month
get_DayOfYear
get_Year
get_TimeOfDay
get_Hour
get_Minute
get_Second
get_Millisecond
get_DayOfWeek
get_Kind
Create
SetMember
Target
Invoke
GetSystemTimeZones
Select
ToList
get_Current
InvokeMember
FindSystemTimeZoneById
get_Local
ConvertTime
MoveNext
set_Location
set_Name
set_Size
set_TabIndex
set_AutoSize
set_Text
set_UseVisualStyleBackColor
set_AutoScaleMode
set_ClientSize
get_Controls
set_FormBorderStyle
set_StartPosition
set_Tag
add_Load
ResumeLayout
PerformLayout
SuspendLayout
set_AutoScaleDimensions
get_Id
EnableVisualStyles
SetCompatibleTextRenderingDefault
GetObject
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
AnyDesk
philandro Software GmbH
(C) 2016 philandro Software GmbH
$4b9f7e33-6592-4921-ac24-2e735e633966
4.3.0.0
_CorExeMain
mscoree.dll
,LZ~*L\
LSy"L\
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
181024000000Z
220105120000Z0e1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
6yNJfM
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
181214152220Z0#
pd_D&K
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
181024000000Z
220105120000Z0e1
Stuttgart1 0
philandro Software GmbH1 0
philandro Software GmbH0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
6yNJfM
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
JlsCp<
UY^%<M
20181214152221Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
181214152221Z0/
/1(0&0$0"
Kwrbpssrwmpswa
Tnkoismzpmvogh
! " # $
>ABCDEabFGcdefgh
sijklmnopqrstuvwxyz
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
AnyDesk
CompanyName
philandro Software GmbH
FileDescription
AnyDesk
FileVersion
4.3.0.0
InternalName
Nnojr.exe
LegalCopyright
(C) 2016 philandro Software GmbH
LegalTrademarks
OriginalFilename
Nnojr.exe
ProductName
AnyDesk
ProductVersion
4.3.0.0
Assembly Version
4.3.0.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.0223c7c933d53879
CAT-QuickHeal Clean
McAfee Artemis!0223C7C933D5
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Injector.MM.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AALH
Baidu Clean
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Crysan.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Win32.Trojan.Inject.Auto
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4420346
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Malware.AI.2585270474
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
eGambit PE.Heur.InvalidSig
Fortinet MSIL/GenKryptik.FEBC!tr
Webroot W32.Trojan.Gen
AVG Win32:MalwareX-gen [Trj]
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.