Static | ZeroBOX

PE Compile Time

2082-10-17 04:08:07

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002b1d4 0x0002b200 7.95964186634
.rsrc 0x0002e000 0x00029f00 0x0002a000 4.2986725618
.reloc 0x00058000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000573e0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00057858 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000578ec 0x00000412 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00057d10 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
bEHD)*
1'M5O;}
w[T>uu
!Txt@U
-0{OYr
s#`X+"L
e+p|KoM
,rL9a;
c@x|,tu
hZ{TU8%
%x_H0V@
x}.!jW`
|`]oi$
vqJ60s)
QdtsB$
2RZtif-B
}D9#)7
$EhpS
y* VoA
X#j5G"
wHeOZb
!g36>X
,#Y8UTK
r8V)b_9
0%ULIW
/mrVbf
Z.nH(\1'\
8uUVm=
ui{q<d
njfM:,v
"ZZK44R
hZQrBr
EZIR.]
o^ G3G
yw((J0
Q$`UXOP
^>/_\;
jtW^5h
Npwww'
W:5Lc.O
w{IG*A
o~QGC7
[3z)c;[Z
/wO||
vYhk<I
sCLzP:
$pEeJ<
gYJR WYg$nGkO
__`1"G
j+\9FQ
lXJk[[Ao
CaR]lg
1&1;,f
;b8^tj
0&<cwV
YC}n~M
,F%Y.U
]VWEL#,
N1y0jErT
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
{0xepE
[_|{^1
c/tyxg
W|P=b`
e,f,5S_e
%_t@F5Os
G+\jYy
Bjc'ff
avZc3
qZy%)j
\o}BNs
Ba}(^
~t$^^_W
@tn0!
#NVhB0
Pqb~J#
FNY ^
A2[`OBfc5{6
6vp.Z%
9yJv6-AD
&A]:R|
'@9LG,
9ZWC&4
*~~~KE
)75=}o
M-6afr
6!qaau
6;G_ &l
O.:tTc
S]W["~
s>~ff`gN
zk|-R^
!a-Oa
jR&bRD
eXTW1(
@6RO(^
?u&G@>
zqN`)J^
\3Gw[E*
-c;26CP'm
p;!=)Y
-&J<|h&
l@tA6
D'x'Jni
uYw+hA
"ov8i27
M\>NMhO=
CF..U(w
_7nuq6
ke\Vt{
~bTWFb
?~9?~*V
NYzsmY
vFANNLfp}
zqN.+k
!))#-(
l}iiq1
ghl`v?
m`u`E`k@
WMt\-]
/Q9Gl1X
z=}4+5
4]j^7xi
<-x_pY
O*0{shw
Om:NSy
;rW@r7
W`/h]7
g\2L,m
?19e_w
aQ=vT9
7eJ%Oy
hzXe4HS
&.he$H
Rp:8wH
X>bKD^
DCG50m
<jPza!;
f\]#Q-
c6T:((
v=|BGC
|B"n-y,B
?ckP{ko-M#
Alvj-3}
~vu=%cv
d3u3\I
KU`yRP
?^$*j-
^-Kl?]
y" t4Q
%eQRU$
C3\3gt
k/?@)J
oUk[z<S
u0]=cOU7
X!S)b*
=au>(b
a^e)Nxt
lHG~ 3M
"@QTE7
%/9j!/
eSPZ7>
>&0oV1
}SemET
7wK^ktUH
qU Srtx
jqU StwaoMa
Xa1N2P
RNE@N'
(9<Of><
#PP^A-5
UCP]J_j/R
DY=QoK0
fA3 ~
AzA_ /
AJAw ;
2~>hhhds
~5#sc!
k)~//<
\\xUw:c^
D&-^,
SXFX"3
.>A>mD
p4B(7X
YV]FVS\
UJbFR|
{|wUk
-"(f\.
/e]YY?
+~YN=;uA
.- *$(
yj>!+:
mf:> #
Bmh78h
N??w,
(mc"f-)k/*
YEUi}usG
.$"/&(#!*
.-%"+*
Llmn>!.
Ex$4,< 0
QtMY&L
RBDJPHFF\GC
]3nv*>n.i
]S>.m)N
nUu>!Ne!
hQ1n`g
\|}|.>!V
ineQNQueea-3
p0>62*'
J)ML^U
^sq{<^'
-i?45U
j>?2mo
hP`nc:
/U%hU*
lO7^9g
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
<>c__DisplayClass8_0
<.ctor>b__0
<>p__0
<.ctor>b__1
<>p__1
IEnumerable`1
CallSite`1
label1
button1
WindowsFormsApp1
input1
textBox1
Func`2
Dictionary`2
label2
input2
textBox2
Func`3
<>o__9
<Module>
System.IO
Costura
mscorlib
get_IsPublic
System.Collections.Generic
GetDataSync
sensorId
Thread
Form1_Load
add_Load
isAttached
Interlocked
get_Elapsed
costura.costura.dll.compressed
costura.classlibrary.dll.compressed
Synchronized
<GetMethod>k__BackingField
<GetAssembly>k__BackingField
ReadToEnd
set_Method
get_GetMethod
set_GetMethod
Replace
CreateInstance
defaultInstance
source
set_AutoScaleMode
CompressionMode
Exchange
nullCache
Invoke
Enumerable
IDisposable
Double
RuntimeTypeHandle
GetTypeFromHandle
get_Name
set_Name
get_FullName
fullName
GetName
requestedAssemblyName
get_DeclaringType
GetType
System.Core
get_Culture
set_Culture
resourceCulture
culture
MethodBase
ButtonBase
ApplicationSettingsBase
WebResponse
GetResponse
Dispose
Create
DebuggerBrowsableState
EditorBrowsableState
CallSite
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
add_AssemblyResolve
Scb2pf.exe
set_Size
set_AutoSize
set_ClientSize
Scb2pf
get_Hnerjuuktextf
System.Threading
System.Runtime.Versioning
CultureToString
disposing
System.Drawing
Attach
Stopwatch
get_Length
EndsWith
button1_Click
add_Click
PerformClick
nullCacheLock
System.ComponentModel
ContainerControl
ReadStream
LoadStream
GetManifestResourceStream
GetResponseStream
DeflateStream
MemoryStream
stream
Program
set_Item
System
resourceMan
TimeSpan
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
Application
set_Location
destination
System.Configuration
System.Globalization
System.Reflection
ControlCollection
set_Position
StringComparison
Button
CopyTo
MethodInfo
get_CultureInfo
MemberInfo
CSharpArgumentInfo
Microsoft.CSharp
System.Linq
InvokeMember
GetMember
StreamReader
TextReader
AssemblyLoader
sender
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
IContainer
Helper
set_UseVisualStyleBackColor
Activator
.cctor
Monitor
Convertor
System.Diagnostics
get_Seconds
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
ReadFromEmbeddedResources
WindowsFormsApp1.Form1.resources
WindowsFormsApp1.Properties.Resources.resources
DebuggingModes
GetAssemblies
WindowsFormsApp1.Properties
EnableVisualStyles
resourceNames
symbolNames
assemblyNames
GetTypes
get_Flags
AssemblyNameFlags
BindingFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
Settings
ResolveEventArgs
Equals
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
components
Concat
GetObject
System.Net
Target
get_Default
SetCompatibleTextRenderingDefault
DialogResult
ToLowerInvariant
InitializeComponent
Convert
WebRequest
SuspendLayout
ResumeLayout
PerformLayout
get_Text
set_Text
IWin32Window
set_TabIndex
MessageBox
TextBox
ProcessedByFody
ContainsKey
get_Assembly
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
get_GetAssembly
set_GetAssembly
ClassLibrary
op_Equality
op_Inequality
IsNullOrEmpty
get_Ilzdxvhhwy
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$b1a5f6e4-9fba-4018-9e66-ecb23bb13297
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
z[]>!^
"^h#O;
Nwo]_:|
Ld`%N2
f{l7;E
n&5z9nv
`fr-.|
zKr]7h=%-!
al_MMP
B`3^Ka+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
Hnerjuuktextf
Ilzdxvhhwy
ClassLibrary1.Expressions.ReaderTaskExpression
InitTag
label1
label2
textBox1
textBox2
button1
Lfoadf
https://github.com/
WindowsFormsApp1.Properties.Resources
Hnerjuuktextf
Ilzdxvhhwy
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Scb2pf.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Scb2pf.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.c0555665c606123b
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_80% (D)
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.Inject
eGambit PE.Heur.InvalidSig
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34678.vm1@aCXuVCn
Qihoo-360 Clean
Cybereason malicious.f894c2
Paloalto generic.ml
MaxSecure Clean
No IRMA results available.