Static | ZeroBOX

PE Compile Time

2021-04-22 07:55:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00034b34 0x00034c00 7.71373841335
.rsrc 0x00038000 0x00029ec4 0x0002a000 4.29816355086
.reloc 0x00062000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00061410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00061878 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000618fc 0x00000412 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00061d10 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
afeffeeffefe
Xffefeefeffea
Yffeeffefe
affeeffefe
Xfefeffefefea
Yffefeeffea
Yfeffefefehah
Yffeeffeefefa
afefefefeffehah
Xfefeffeefa
`fefefeffe_9*
fefefeffe
fefeffeef
pffeeffeefef
3ffefeeffe
9fefeffefeef
afefefeffefe
3ffefeeffe
pffefeefeffe
fefefeffe
feffefefe
afeffeefef
RffeeffefefeYa8
feffeefefY
ffeeffefeefXa8
IfeffefefeY
fefefeffefea
ffeeffefe(
ffefeefeffea(
v4.0.30319
#Strings
Bgbbxl
Bgbbxl.exe
<Module>
Settings
WindowsFormsApp1.Properties
ApplicationSettingsBase
System.Configuration
System
RegAuthenticationStub
WindowsFormsApp1.Stubs
Object
mscorlib
AdvisorPrototypeProducer
ClassRecordVisitor
StubAuthenticationObject
Worker
WindowsFormsApp1.Shared
ReponseSingletonConfig
Bgbbxl.Configurations
RulesMapperClass
WindowsFormsApp1.Classes
RuleConfigurationListener
WindowsFormsApp1.Listeners
ErrorComparatorList
WindowsFormsApp1.Lists
EventCallbackTemplate
WindowsFormsApp1.Templates
RepositoryConfigurationListener
ContextDecoratorAdapter
Bgbbxl.Adapter
DispatcherMessageConsumer
WindowsFormsApp1.Consumers
TypeDefFlags
MapComparatorList
Repository
Bgbbxl.States
MulticastDelegate
ObserverRecordVisitor
Bgbbxl.Visitors
WindowsFormsApp1.Specifications
Thread
Bgbbxl.Writers
AccountCallbackTemplate
Connection
DecoratorSingletonStatus
CredentialProcurement
Status
Dispatcher
Bgbbxl.Services
RegistryAuthenticationObject
WindowsFormsApp1.Objects
SerializerRegStruct
InterpreterOrderQueue
Client
Policy
ParamParserSpec
Factory
ItemAuthenticationObject
SearchMapping
.cctor
f0659e5905454a5e99b9752afc78b700
PrintMapping
Boolean
VerifyMapping
DisableMapping
SettingsBase
Synchronized
CountMapping
LogoutMapping
m_Getter
_Mapper
callback
authentication
m_Parser
_Configuration
comparator
m_Definition
AwakeMapping
ID_reference
System.Threading
get_CurrentThread
get_ManagedThreadId
CalcReg
CalculateReg
DestroyGetter
WriteReg
NotSupportedException
MoveMapping
FlushMapping
LoginMapping
PublishMapping
singleton
m_Resolver
_Prototype
object
FindMapping
instance_Ptr
AddReg
CollectMapping
PrepareMapping
_Record
exporter
m_Writer
_Importer
m_Adapter
predicate
FillMapping
taskPtr
VerifyReg
PopGetter
InterruptReg
NewMapping
VisitMapping
ChangeMapping
IncludeMapping
OrderMapping
CountReg
visitor
schema
Dictionary`2
System.Collections.Generic
String
_Manager
_Candidate
interpreter
ConnectMapping
CloneGetter
CultureInfo
System.Globalization
SortGetter
Assembly
System.Reflection
AssemblyName
instance
get_CultureInfo
Equals
StringComparison
get_Name
AppDomain
get_CurrentDomain
GetAssemblies
CollectGetter
Stream
System.IO
second
StartGetter
DeflateStream
System.IO.Compression
MemoryStream
CompressionMode
set_Position
IDisposable
Dispose
EndsWith
ForgotGetter
TryGetValue
ExcludeGetter
get_Length
ComputeGetter
ToLowerInvariant
IsNullOrEmpty
Concat
InstantiateGetter
config
ResolveEventArgs
connection
op_Equality
Monitor
set_Item
ContainsKey
ResolveGetter
Interlocked
Exchange
ResolveEventHandler
IntPtr
add_AssemblyResolve
SetupMapping
PushMapping
ValidateMapping
PopMapping
PatchMapping
GetName
PostMapping
EnableMapping
SortMapping
MapMapping
GetExecutingAssembly
InitMapping
GetManifestResourceStream
InstantiateMapping
InsertMapping
ManageMapping
op_Inequality
RunMapping
AssemblyNameFlags
get_Flags
StartMapping
CalculateMapping
m_Customer
m_Model
m_Event
_Account
RemoveMapping
ValidateGetter
ResetGetter
SelectGetter
MapGetter
firstmax
PrepareGetter
VisitGetter
addinstance
CalcGetter
ConnectGetter
QueryMapping
CalcMapping
indexer
m_Merchant
UpdateMapping
WriteGetter
AddGetter
VerifyGetter
InterruptGetter
CountGetter
CalculateGetter
useident
CreateGetter
ReflectGetter
CancelMapping
WriteMapping
value__
GetMapping
InvokeGetter
ToArray
GetManifestResourceNames
Func`2
Enumerable
System.Linq
System.Core
SingleOrDefault
IEnumerable`1
ViewGetter
Double
visitor2
ClassLibrary
set_Bytes1
InterruptMapping
CreateMapping
DestroyMapping
RevertMapping
CopyTo
SearchAlgo
PrintAlgo
set_Bytes2
VerifyAlgo
Serial
DisableAlgo
Convert
ToInt32
CountAlgo
m_Rule
LogoutAlgo
ReadGetter
ForgotAlgo
RegisterAlgo
ComputeAlgo
Contains
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
EndInvoke
m_Task
_Issuer
_Database
m_Process
AwakeAlgo
DefineGetter
SearchGetter
CheckGetter
SetupGetter
no__init
ChangeGetter
DisableGetter
isident
PublishGetter
ConcatGetter
MoveAlgo
FlushAlgo
m_Proccesor
bridge
m_Struct
_Property
LoginAlgo
RunGetter
LoginGetter
RestartGetter
CompareGetter
remove_IDENTAt
PushGetter
ListGetter
identinstall
MoveGetter
AwakeGetter
PublishAlgo
FindAlgo
CollectAlgo
SetGetter
PostGetter
Format
Console
WriteLine
ReadKey
ConsoleKeyInfo
ChangeAlgo
PrepareAlgo
FillAlgo
initializer
advisor
interceptor
m_Container
IncludeAlgo
TestGetter
CallGetter
FlushGetter
RemoveGetter
init_start
InitGetter
LogoutGetter
NewGetter
FindGetter
NewAlgo
VisitAlgo
_Server
descriptor
_Context
OrderAlgo
PrintGetter
ManageGetter
InsertGetter
EnableGetter
paramZ
RegisterGetter
CustomizeGetter
ineeded
QueryGetter
DeleteGetter
SetAlgo
SelectAlgo
_Producer
_Watcher
m_Composer
reader
m_Listener
template
_Param
m_Facade
RateAlgo
StackFrame
System.Diagnostics
StackTrace
MethodBase
GetFrame
RuntimeMethodHandle
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MemberInfo
get_DeclaringType
GetGetter
PatchGetter
param_max
excludeconnection
StringBuilder
System.Text
UInt16
UInt32
ToString
Append
IncludeGetter
get_FullName
RateGetter
GetPublicKeyToken
OrderGetter
callerlow
get_Assembly
CancelGetter
reg_end
AssetAlgo
TestAlgo
InvokeAlgo
DeleteAlgo
ListAlgo
ReflectAlgo
CompareAlgo
DefineAlgo
CallAlgo
GetCallingAssembly
ReadAlgo
ExcludeAlgo
AddAlgo
CustomizeAlgo
row_key
ConcatAlgo
CheckAlgo
ConnectAlgo
PushAlgo
ValidateAlgo
SetupAlgo
PopAlgo
Encoding
get_Unicode
PatchAlgo
GetString
PostAlgo
EnableAlgo
Intern
SortAlgo
get_Count
MapAlgo
InitAlgo
InstantiateAlgo
InsertAlgo
m_Filter
CalculateAlgo
UpdateGetter
StopGetter
FillGetter
AssetGetter
EndOfStreamException
RevertGetter
task_Z
ReadByte
DestroyReg
PopReg
ArgumentOutOfRangeException
ResetAlgo
CloneAlgo
ViewAlgo
RemoveAlgo
Buffer
BlockCopy
_Request
CancelAlgo
CloneReg
List`1
UInt64
AddRange
get_Item
SortReg
CollectReg
StartReg
WriteAlgo
StopAlgo
ResolveAlgo
RestartAlgo
GetAlgo
InterruptAlgo
CreateAlgo
DestroyAlgo
RevertAlgo
SearchMessage
GetBytes
PrintMessage
VerifyMessage
DisableMessage
get_MetadataToken
m_Identifier
_System
CountMessage
ForgotReg
ExcludeReg
spec_count
LogoutMessage
ForgotMessage
RegisterMessage
ComputeMessage
AwakeMessage
ComputeReg
key_High
InstantiateReg
idx_config
startcounter
ResolveReg
firstID
sumcfg
MoveMessage
FlushMessage
LoginMessage
ValidateReg
PublishMessage
FindMessage
CollectMessage
PrepareMessage
FillMessage
ChangeMessage
ResetReg
IncludeMessage
NewMessage
VisitMessage
OrderMessage
SetMessage
SelectMessage
RateMessage
SelectReg
InvokeMessage
DeleteMessage
AssetMessage
TestMessage
ListMessage
ReflectMessage
CompareMessage
MapReg
DefineMessage
CallMessage
ReadMessage
ExcludeMessage
AddMessage
CustomizeMessage
ConcatMessage
CheckMessage
PrepareReg
ConnectMessage
PushMessage
ValidateMessage
SetupMessage
PopMessage
PatchMessage
VisitReg
PostMessage
EnableMessage
SortMessage
MapMessage
InitMessage
InstantiateMessage
AssemblyDescriptionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
AssemblyTitleAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
RuntimeCompatibilityAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyCompanyAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerHiddenAttribute
DebuggerBrowsableAttribute
DebuggerBrowsableState
STAThreadAttribute
WindowsFormsApp1.Resources.Kmcsvigtijfduu.dll
WindowsFormsApp1.Resources.Dlqlggvaxnuukp.dll
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
Discord - https://discord.com/
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
0.0.52.0
WrapNonExceptionThrows
4Copyright (c) 2020 Discord Inc. All rights reserved.
$dea4f32a-beea-4dcc-9fba-8fb3e1d046dc
Discord Inc.
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
uT]py4
C#H{5c
%HF]]P
h.[s7[
"5FP#pp
l[-9*qzky
D%[YSK
f/OngNL>
s]Rjbn2
v2rwTP
6e#.5.
3`Q?5]
QSzeEM
?/0Bp5
'z9,?^
ZY8D49F
+mMsTnZ
)7UNv/
%Vtf)Od
>u%&x
e6/3!28[
}xrxY~
vCcO^K
?$xp{
;2c|:p
{0|8v
8y=EZZm
e}@.~:p
@x]{b7
${'j8`
&[`9?w
|4{=f<${
CGi@~r
@Vz]*-
BW:tI\
eOyX69o!
#4+C5M
_}kLb"
U2G;e/
Gds8vv
Q8y{!*
v[0dv<
fAveW_h7;^
fEU;}c
c<~BS4t
F/oNbO
l,KzdN&@
KP"|U![
vMg095
V_%e&TP
7IrV97ou
!uT]j?d
+QGemK4
G\X@{m
[RcW.E
o*,VXR
xU5m@H
vE[{db2
mbGAtSX
i@ceGo
+9LhmY
GMI&Pd
Ge"QoMoJ
>'@>%O
KO1auv,.
!sA8?V
[SgoOSlY
6<a8wz6
NTiW&^0F8
F[D.SI
?S&(7;&
QG?~#TQ
~(jgnD51
d;12+'
M8J{B%_
"s0{uc
FkBs=\fJ
uSQZ/>
@)zLsv
7bj1v&
`B)7f3
:XnpGS
F0vI>T
shGg?A<
n@*A7
SniQnb20
i"1:.!9/
=In#cs
/WN}c9
a1>$BA
cdj*ghg
mCGPZH
]Ngpk
-/''"-
RPJB1
168gl)
QJW{hu
)/?_?L
N5ifkf
XRxLD
c}S!ih
jwn};>U6
J<""*|
^%c^>o
qqM8%7W
--,*.m
Bfh.X8
eaa.e>y
2iafj`
|My!!()
Y!iyy)Qe%nYy
j:&6."
QBR3-#g
US]]SU[Y
oD/Z"<
I1%Qi[3e=Asa58
X`DDtQb6&
0\`qf.(1":
TtqL^P@PQKCL
g'=+<x
Mevf{iqx
tHdtyh1a
Tm(m"BR!
;?EBYbx
Xk2WaL
Q.cb2F
Vq59M:O,
,s&PTh}
G|}B4>C
Y^B|l#
?E0lboI
NL~"c\
97oRNa
$'<HWcN
p_P \s
(4_t u
KA7&fl
?6s_~D
W1xsn0t 0
j^F/08
G iY'lA
y7$cB]
gm@27[k
qGG3B!
*;Z(P%
:O}uDf)Njj
k!pgpY
ww^xG:
g@A|N_azp
]eSTZp
K3Z1>vf
h5Zu}q
-/OcT9
/W3_SV
'inWZ5
HC_Y,>I
g0{W_I
_J&Ee~,
,]<sv[
T*UWwK
[nq6J=
sDSX\*
2f^nB"
K<ne@t`i
Qh%?CD
r#jQ^T
-uay'K_S}Xr
81"&o,
gBVm*whh
7m&0S3
L&,&l&
B=\"n:
2wtR2~
CCgG'[k
u4w2w1V27
<acCsk}
vs57zs6y}
"9+S*(
v8HIw:]
"!r{>`
7S!Hr!
x!*McKB
xg7+><w6
pGi<dY
!VYe$nEkN
@@]OOR3
Mf?*8ZY
i_NUNg
qs\%`vJ
g*Cwzx
NYr2^
em=Umur
NAoUhzAR
%K^LG*
e_29N`
<D;DS{
Mn3[w6
@'$YQ1!
v7kFm^
bn.EHT
}zZ>hp
vJ3%uY
K#*::W
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
{0xepE
GZ\Og
x5c%cH
3ng<h9
q6tVYC+
&IFKeFe
[CtEm
]*kdvNe
P'_"-R
C+=i%
!*7k=4A
rq@ec
YT%N1SN
t7iU?3
.w|g_+>I
j)mKyT
~)1u.Zzi*
=g[i?j
(7:X>a
F8g|hq
*vMy^M
>HDHZy
ST_k'DU
.L6L.5b
LSt"}1
85)LNj
%8lqKr;p
Jq%}N(
~!wfN(
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
_CorExeMain
mscoree.dll
z[]>!^
"^h#O;
Nwo]_:|
Ld`%N2
f{l7;E
n&5z9nv
`fr-.|
zKr]7h=%-!
al_MMP
B`3^Ka+
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Bgbbxl.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Bgbbxl.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.0584b79b0075099a
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.7b8626
Baidu Clean
Cyren W32/MSIL_Kryptik.DZK.gen!Eldorado
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:Trojan-PSW.MSIL.Stelega.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Tnega!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.2879811223
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/GenKryptik.FEGB!tr
BitDefenderTheta Gen:NN.ZemsilF.34678.xm0@ayKFDSf
Paloalto generic.ml
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.