Static | ZeroBOX

PE Compile Time

2021-04-21 22:47:19

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00040c40 0x00040e00 7.95294707335
.rsrc 0x00044000 0x0002c848 0x0002ca00 4.68666831052
.reloc 0x00072000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0006fd8c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000701f4 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00070278 0x0000041a LANG_NEUTRAL SUBLANG_NEUTRAL ARC archive data, squeezed
RT_MANIFEST 0x00070694 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
A"#{(j
O"#{(j
t"#{(j
-*&&()
Xfeffeefef
<d}Ta
affeeffefea
Yfeffeefeffea
Yffefeeffe
Xfeffeefefa
afefefeffefe
gE[0X
affeeffeefefhah
Xffeefeffeefhah
Yfefeffeefa
affefeeffe_-
Xffefeefeffea
=ffefeefeffe
fefefeffe
feffeefef
$,ffefefeeffe
afeffefeeffe
9feffeefeffe
fefefeffeef
$,ffefeeffeef
feffeeffeef
=ffeeffefe
afefefeffeef
ffeefefeffeYa+
ffeeffefeY
ffeeffefeXa+
feffefefeefY
ffeeffefea
>Yfefefeffe(
ffeeffeefefa(
B+S'M=
_'U0H9-
NleR'7p
#>PQ+)o4
*SMS).TW
WvNf0\n
o=g8q,%>
[rb{wD
>V~C_X
Kr,Y;R
Wxe%)4@
~,?]Pp
wVBA1
dVFUMa
v8EB?n
==D:!=9\
Sh=edX
(qmjm
QkTZr-
=kKkwkk
uh6Vzku
G]D~;U
df7X<&VXz3P
{I09h:
bWHUhV
:Jm&5$
}LeLNLXLgh
p~]C.^
<Wy`TxN
)r9r%Z69)
w[7C>4
X]}:+:T
_g5^~i
2mu_R?
*{1>"cW
TNa]I^
b?l"RkN
t`J5hv
k6hX{Y
Vt&>~r
+O}/!a
k6hU-g
w8mBik;
Spk*hE
k>hY-b
z']e!f
x,=TAe{
j8hG0=
PztSk5M
kf#'Ma
YUh[Od
'hP-}XF
@DPDQ(
t}+,o,
V8UX=>
'@Y-}M%J
U[\]R@T
?&7Ee
iMVZFP
')YmMO
FJHSKVBUM
;Q]}ol
>%6-}R
{]TXR]
EjNItjewWs
322>>22335
lBF|KY
'VA:?f
~MXH@G^
jgXo[{
:/9yzi
k[N^BA{U
_UPQcT0P
iPWI\\PS
\[\X_:
bl||zaKbNjh
$e%71$|q=4s2>
6jVF*zF
x=hDk6
9o6|<=
<47[Q>;
L'aana
p~kkk=De
q1<XUZ
![NVD+
~r!AA-
9:6,v{
12w `o
k7/&&z
y1~q"q
~h?i:0
um%EZH
:.+=~_ZVP
%!-&};
<~[9_/
'17?,zo|y
tVCWLC
t#FVT48#
#vP_\WZ[=
rv5Po;W=
IBBLaH
!G|k8
27dsa)
$leDlec
%PDP8
@$^Qv%
5PT5J
P8\.34
!A\BPg
!QcCA(
`o6rof
4G'0?b
ZNEX/X
ZNNZIH
srUv&
F i6riIX
I6rI6J
J-p/I,
0'&`J-
y>>>Y&
qWw#"&
N1bO^I0
* c=xy
LQ|u-I
_,dGycH>?
K(`ZOi
ckOx/k
B#%6a'm
z6j79^
"n"l!""u;)*;
h|1Y|9
_K>ny=
M5Ma|A
I[[Z-
wM[q'N
>0wT+-
IkdMHJI
s\13'T
WsE'd6x!Z
3,<6eV
w;qrr1
s,s4HB
g7CbtY
&#'n]Z
;<\BW5
qZ5m F z
MAFz*
+kLrD(
G#0m&<y
!~4Ge_
pYReT'
@.9yLO
r[VD{9
}m%sNRT
/IB]% zJ1
)bl)bh
G;36q}
;o%1:v
>J_$X"a6
X</<&;
4#<@<l
[Fm9vO:3D
"~30\@
r!896IY
_ TT5b
y[kd["
Z|fZc$z
yy58F"
!SZn':
W|2?u?2@
C%+J,E
pEIZiR
arA@k0
4ZBda I
M1Y~KXe
Lq3;&a
Ydf*){
,q3a_>
z3xS*Sb
_vSEk2
~2}rWY%
E@Ya=3*^
.Kym1F
'7dLnz$kdJO
iA`Vw+
@m&3}~$u
<C63]B
{/kK]7X4
R:MuNu
$7:KqI
gX|Xcy4
t&1aX<S
)Qo'H\uo
Qui42y
s$:KX}
`=<lmM
a ;^s3
("]SHvcMz
f,,h}KeE6z
mC'Fd$Y
zGu~O
NtG4j
Mvzc7`
O.QV^O<
/rXtf]
nW/k&}
QZ?=LRw
3uWO8m
NoOrKw
Mql-SS|B
iC1}GC(
:X[Q=v
%+Vhjk
a+1jfl
/'Xs(O
Am,>N
sEAY*k
x]DOSh"
*l'G.q_
"Eq[E
zMQkn@i
D[uu!+
T{*fe[g
VKAI4
5h"b 4Y
x=.1,HRP[
CH]T3
0US?aP
-\[TWEeQ
r;Eo`=L
Zl[[\tw7
}RQrh=N
ndG@Gq
;rRa9[
KZ#[t-
8g4QXF
b!!D7Q
mz9@[9
sqFbDzV
t}1i5{
6,1?Ij;',
3^?jk/
_Q_OWIy
R'z'c6
qc6P5w6v
KRqL<r
p9\]lB
kDGZd`
_EuVhV
A`gu|1
u.wci1
3664|J
hjW5^'G
z;N}N
V0j[O:
;\g#"o
gb^'Z|
Q+X6%M
5E5}X,p
Yb<FxP
tzsNOtvh
vy$?6;
nkYZ`X
?:#Aj.6>#!
#JZA,_
C$s%#j
+g-.j8
EbJHmN
,*HC3J
No$Fv%";u
gaEW)
#K}(w
g"| ##>U
DEv.Ic
94D1^|E
T|Kq|p
p%8ONck
In|I@w
5)=_a<u
hzg{~s
yw!:^]B
>GCv1HW
~s<`~
zYmA*4o
/Hpn&sd1
j@F6Z!#
)#e1#z
UEJD od[(T~B}
m~CfbL
lnwfFg
ZrL9JEDT;
|_L@<b[
m[Pn{g
95)s<r
~G}'sd
FB.*Hu
>T)+?m
TYeIemr6
U,xjTB
fTy<GS
=B</KV%
^`(}?W
?2$bii
-/S?7t]
O{g5,~
tgk+O_I\
rPFfRj
&9<Z&e:
f(J+Z*
NMHKLM
BC_{Frfr
cUs)[*
;*}rN6
/w&}.n
:Bmj&Fh
C+[ek!Ef
*t[+Va
Q|f^tR
%dUl#H
Q"UfCiDQ
6z}|s)5
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
g?DF;G\
3E[c/-9`
Y%Z(kn
epkB[xm
Z~$8}xf1
`KX;`pp|
[Um1."<+UZ
gEsE^5
*Lno_Pm+
A&h%O_S
'fu3!Y
dn6W0u
r~e55$
\<~U9S
T$Gl?v
176L.]c
*|OwO@
9W%mzW
^6ac>L:
A~9js@
~vuZxh
h?OQyS
<_696{
4L>$H.
._uqogU:
>n1DE>
~AqSof>#
mrm="L
VrHi!=
p!"<!$D
/")A]F2
8:+q8:+)
Ij\Rh.
iyZk4qY
Tnu:[4
gcE?TT
(j$Z-$%
M8MRO"6@
"Ixc0E?Exc
E'C_N
%z|11\
sq'y^cT}
$fX{lz
uNbIkuR
gu$u_&
|7?3??
|?;8_
W<{=o{>
RpRAUA
hK:}X(
)S#ge0
T(#z\<
'r\S4:)
@{si89<
{,L5YrP
@-]YP$
">?,mrZS
xB^C3LY8
VBT3R3
,C!-R4
]xl(Rw
7V]uXW
`bI*``
D^XTH:
c/q4,w
rM![7R-
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
Mkqhnnyzd
Mkqhnnyzd.exe
mscorlib
System
System.Core
ClassLibrary
WindowsFormsApp1.Resources.Tjdbyqlewgks.dll
WindowsFormsApp1.Resources.Ykbthfnuibdc.dll
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
AppDomain
ArgumentOutOfRangeException
AsyncCallback
Boolean
Buffer
GeneratedCodeAttribute
System.CodeDom.Compiler
Dictionary`2
System.Collections.Generic
IEnumerable`1
List`1
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
ConsoleKeyInfo
Convert
DebuggerBrowsableAttribute
System.Diagnostics
DebuggerBrowsableState
DebuggerHiddenAttribute
StackFrame
StackTrace
Double
Func`2
CultureInfo
System.Globalization
IAsyncResult
IDisposable
CompressionMode
System.IO.Compression
DeflateStream
EndOfStreamException
System.IO
MemoryStream
Stream
IntPtr
Enumerable
System.Linq
MulticastDelegate
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyNameFlags
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
ResolveEventArgs
ResolveEventHandler
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeMethodHandle
RuntimeTypeHandle
STAThreadAttribute
String
StringComparison
Encoding
System.Text
StringBuilder
Interlocked
System.Threading
Monitor
Thread
UInt16
UInt32
UInt64
<Module>
Settings
WindowsFormsApp1.Properties
.cctor
f0659e5905454a5e99b9752afc78b700
dJzKsa
eJzKsa
dJzKsc
eJzKsb
fJzKsa
fJzKsc
bJzKsa
GetEnumerator
value__
Invoke
BeginInvoke
EndInvoke
Synchronized
get_CurrentThread
get_ManagedThreadId
get_Name
get_CurrentDomain
GetAssemblies
GetName
Equals
get_CultureInfo
GetExecutingAssembly
EndsWith
GetManifestResourceStream
set_Position
Dispose
TryGetValue
get_Length
ToLowerInvariant
IsNullOrEmpty
Concat
ContainsKey
op_Inequality
op_Equality
set_Item
get_Flags
Exchange
add_AssemblyResolve
GetManifestResourceNames
SingleOrDefault
CopyTo
ToArray
set_Bytes1
set_Bytes2
Serial
ToInt32
Contains
Format
WriteLine
ReadKey
GetFrame
GetMethod
get_DeclaringType
GetTypeFromHandle
GetCallingAssembly
Append
ToString
get_Unicode
GetString
Intern
get_Count
get_FullName
GetPublicKeyToken
get_Assembly
ReadByte
BlockCopy
AddRange
GetBytes
get_Item
get_MetadataToken
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
Discord - https://discord.com/
0.0.52.0
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$75e88362-eeba-4b5e-a36e-45ad74313977
_CorExeMain
mscoree.dll
'LaYGc
MCVwz{S
&Q(\C*
]<u{[D
gTG"E9
OEOD&
.Z[6RPP
o*O}n!
(pjAJS
hFWl]/
.l{c)
~nyiu[
9Hx"8X
|(%b *
'eG]~B
J-!2IHj
HA0<HD
HA-c.4
pctCG>
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
sadefbcghijklmnopqrstu
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Mkqhnnyzd.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Mkqhnnyzd.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
ClamAV Clean
FireEye Generic.mg.75ab568fe148e4d2
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.815372
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FEGB
APEX Malicious
Avast Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.MSIL.Agensla.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition GenericRXMP-PA!75AB568FE148
MaxSecure Clean
CMC Clean
Sophos ML/PE-A
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Tnega!ml
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXMP-PA!75AB568FE148
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2879811223
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit PE.Heur.InvalidSig
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34678.Bm1@am8KhJg
Paloalto generic.ml
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.