Static | ZeroBOX

PE Compile Time

2059-10-27 03:50:12

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002b864 0x0002ba00 7.96194582048
.rsrc 0x0002e000 0x00029f1c 0x0002a000 4.29898090312
.reloc 0x00058000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00057410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00057878 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000578fc 0x00000432 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00057d30 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IMG_5023075401
IMG_5023075401.exe
<Module>
Comparator
WindowsFormsApp1.Exporters
Object
System
mscorlib
<>o__8
<>c__DisplayClass9_0
Settings
WindowsFormsApp1.Properties
ApplicationSettingsBase
System.Configuration
PredicateParamsTask
IMG_5023075401.Tasks
HelperAttribute
WindowsFormsApp1.Attributes
ParamMockSerializer
WindowsFormsApp1.Serialization
DicClientBridge
WindowsFormsApp1.Bridges
CreatorErrorFilter
IMG_5023075401.Filters
CodeAttribute
SpecificationListExpression
IMG_5023075401.Expressions
Product
WindowsFormsApp1.Shared
AuthenticationProccesorWriter
IMG_5023075401.Writers
RegistryProccesorWriter
WorkerListExpression
IMG_5023075401.Queues
Manager
MockProxyStatus
WindowsFormsApp1.States
AssemblyLoader
Costura
.cctor
ConnectComparator
Stopwatch
System.Diagnostics
Boolean
TimeSpan
Exception
StartNew
Thread
System.Threading
get_Elapsed
get_Seconds
Console
WriteLine
String
ListComparator
ResolveComparator
RestartComparator
CollectComparator
asset_length
PrintComparator
UpdateComparator
List`1
System.Collections.Generic
IEnumerable`1
Concat
SelectComparator
ComputeComparator
WhatsApp
ClassLibrary
GetTypeFromHandle
RuntimeTypeHandle
Activator
CreateInstance
get_StackTrace
CSharpArgumentInfo
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Create
CSharpArgumentInfoFlags
Binder
SetMember
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`4
CallSite
Target
Invoke
InvokeMember
Action`2
get_InnerException
ConcatComparator
Assembly
System.Reflection
Stream
System.IO
MemoryStream
GetExecutingAssembly
GetManifestResourceNames
Func`2
IntPtr
Enumerable
System.Linq
SingleOrDefault
GetManifestResourceStream
CopyTo
ToArray
_System
_Client
_Proxy
ReflectComparator
Contains
defaultInstance
get_Default
SettingsBase
Synchronized
Default
IncludeComparator
InstantiateComparator
PopComparator
SetupComparator
ValidateComparator
CalculateComparator
PrepareComparator
RateComparator
nullCacheLock
nullCache
Dictionary`2
assemblyNames
symbolNames
isAttached
CultureToString
CultureInfo
System.Globalization
culture
get_Name
ReadExistingAssembly
AssemblyName
AppDomain
get_CurrentDomain
GetAssemblies
GetName
Equals
StringComparison
get_CultureInfo
source
destination
LoadStream
fullName
DeflateStream
System.IO.Compression
EndsWith
CompressionMode
set_Position
IDisposable
Dispose
resourceNames
TryGetValue
ReadStream
stream
get_Length
ReadFromEmbeddedResources
requestedAssemblyName
ToLowerInvariant
IsNullOrEmpty
ResolveAssembly
sender
ResolveEventArgs
Monitor
ContainsKey
op_Inequality
op_Equality
set_Item
get_Flags
AssemblyNameFlags
Attach
Interlocked
Exchange
ResolveEventHandler
add_AssemblyResolve
ExtensionAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
WindowsFormsApp1.Resources.Bocswavkhz.dll
WindowsFormsApp1.Resources.Cfdzsyy.dll
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$f2c96579-0299-4eb2-9e29-8e511642692f
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4Y
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
uT]py4
C#H{5c
%HF]]P
h.[s7[
"5FP#pp
l[-9*qzky
D%[YSK
f/OngNL>
s]Rjbn2
v2rwTP
6e#.5.
3`Q?5]
QSzeEM
?/0Bp5
'z9,?^
ZY8D49F
+mMsTnZ
)7UNv/
%Vtf)Od
>u%&x
e6/3!28[
}xrxY~
vCcO^K
?$xp{
;2c|:p
{0|8v
8y=EZZm
e}@.~:p
@x]{b7
${'j8`
&[`9?w
|4{=f<${
CGi@~r
@Vz]*-
BW:tI\
eOyX69o!
#4+C5M
_}kLb"
U2G;e/
Gds8vv
Q8y{!*
v[0dv<
fAveW_h7;^
fEU;}c
c<~BS4t
F/oNbO
l,KzdN&@
KP"|U![
vMg095
V_%e&TP
7IrV97ou
!uT]j?d
+QGemK4
G\X@{m
[RcW.E
o*,VXR
xU5m@H
vE[{db2
mbGAtSX
i@ceGo
+9LhmY
GMI&Pd
Ge"QoMoJ
>'@>%O
KO1auv,.
!sA8?V
[SgoOSlY
6<a8wz6
NTiW&^0F8
F[D.SI
?S&(7;&
QG?~#TQ
~(jgnD51
d;12+'
M8J{B%_
"s0{uc
FkBs=\fJ
uSQZ/>
@)zLsv
7bj1v&
`B)7f3
:XnpGS
F0vI>T
shGg?A<
n@*A7
SniQnb20
i"1:.!9/
=In#cs
/WN}c9
a1>$BA
cdj*ghg
mCGPZH
]Ngpk
-/''"-
RPJB1
168gl)
QJW{hu
)/?_?L
N5ifkf
XRxLD
c}S!ih
jwn};>U6
J<""*|
^%c^>o
qqM8%7W
--,*.m
Bfh.X8
eaa.e>y
2iafj`
|My!!()
Y!iyy)Qe%nYy
j:&6."
QBR3-#g
US]]SU[Y
oD/Z"<
I1%Qi[3e=Asa58
X`DDtQb6&
0\`qf.(1":
TtqL^P@PQKCL
g'=+<x
Mevf{iqx
tHdtyh1a
Tm(m"BR!
g_y|`dq
l3(#u3cCv
&0|^|(
UAp0vtj"
&;1<_I
x~Fc<(B
-Oo4o#
}d!d18
F0*9g+
\!OP{B
qQe*|G@
;e~&8A
~Ck!9#Y
Euz8qY
.9X+TFT
gQc)}2='
7;Z48E+s
F!_)tF
)6(G?*Mt
S0gW)^
RGRD<E@
HW ]H"
R/ncA9
e\%S9D6
t7 _c D
-E=v"4
'hP8-(
J)FJvu,
C@IR%2
8xs69$
au%:/clRCFg,
c]mcJNG6
Ai:Cw
|yvg\A
<)(z?L
xRiI`B
K.7_dj
zqRzN|
c.Lk]55
{e&?PR
s9UQ09
g2b1b3b`0`
0]+cq!
S'CESc+
F!zCMF
$.#[;Q
}+mGf^
AJs#b1
G@]MMP5
%#s1?
Qd5E9n1
J\Ltgi!
^0{a;>=
JU)6El
cP|*/N=nW
VmTbP;
j@{F_#
q`gwp}1o
-t/CQWk
BY&>:}
uVY_`\
[Eta<?D
,v7LY9K!d
`Z578'
E+Vlk-
{B%G3%
<yp&E/
nduIiW
wqx+eK
f;uu~dt
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
C,DBTQ
=E/cgWS4
W1s44b
Yti$70
ZY=^I_/
%Fb}B'
|'C3wEr
Up>*4M
v$_t=f+3
oR>;7
@nR7K+
{3ch0K
C)+3[L
wuFsZT**=
jx`he&
, pBT(R$
R@ZKXt\-
X(eLfo8
#`%6i"
;tlQu83
!iyopEz5
CYl|lo'
R'x]_.
,V4-=}[
Q[VH_b
\&/Yz
7"\<(-8
~$Jv0?
ix'_)j
9?x4At
OrxVx8
H!@H@A+
L?i53]
nRu9uN
Zh3$_Zd
2_{W^x
WqX4+M
\_uVYL
\n~re6
lWy|a_~
K%JQqzV;
"ge"kV
h1+*Yc
dj6r<1
T*s9},4;
^*!&n[r
cnc_Y{
Jg5&,D$
:tB 5!6h
#aEWjh
{/Rx+Rx
5^#JNt
"Ndl-
}AC2|k
aDPV#JD
,<LFAF
~Z(f9@
"RH*k*
@s}C}SC
el3aG-
tXXHV:
]N')<O
X:3/q+ND
qll8yeS"
&VcZ>I
z`W+63,
.6\^xr
7~wX_M
_CorExeMain
mscoree.dll
z[]>!^
"^h#O;
Nwo]_:|
Ld`%N2
f{l7;E
n&5z9nv
`fr-.|
zKr]7h=%-!
al_MMP
B`3^Ka+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
==============================================
CatchAndThrow:
CatchAndThrowEx:
Didide by zero error
DoStuff2:
Contact1
Cfdzsyy
Contact2
Bocswavkhz
Dailup
Inner exception:
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
IMG_5023075401.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
IMG_5023075401.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.427e21ef958ea63e
CAT-QuickHeal Clean
McAfee Artemis!427E21EF958E
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.bdd30c
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FEMF
APEX Malicious
Avast Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-PSW.MSIL.Stelega.gen
Alibaba Trojan:MSIL/GenKryptik.fb9fea7c
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/AgentTesla!ml
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34678.vm1@aa5Rnme
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.