Static | ZeroBOX

PE Compile Time

2089-08-31 14:09:22

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00033074 0x00033200 7.96474455621
.rsrc 0x00036000 0x00029f24 0x0002a000 4.29930197938
.reloc 0x00060000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0005f878 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005f8fc 0x0000043a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005fd38 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IMG_106_680_74_80
IMG_106_680_74_80.exe
<Module>
Visitor
WindowsFormsApp1.Items
Object
System
mscorlib
<>o__8
<>c__DisplayClass9_0
Settings
WindowsFormsApp1.Properties
ApplicationSettingsBase
System.Configuration
ProcessWrapperPage
IMG_106_680_74_80.Pages
MessageTestSerializer
WindowsFormsApp1.Serialization
Mapping
WindowsFormsApp1.Records
IMG_106_680_74_80.Configurations
Customer
WindowsFormsApp1.Common
ExceptionErrorMessage
IMG_106_680_74_80.Messages
QueueItem
Repository
HelperMappingPolicy
WindowsFormsApp1.Polices
AssemblyLoader
Costura
EventTestSerializer
.cctor
DisableProxy
CustomizeVisitor
Stopwatch
System.Diagnostics
Boolean
TimeSpan
Exception
StartNew
Console
WriteLine
String
Thread
System.Threading
get_Elapsed
get_Seconds
ManageVisitor
InsertVisitor
FindVisitor
CollectVisitor
start_def
ReadVisitor
InitVisitor
List`1
System.Collections.Generic
IEnumerable`1
PopVisitor
ListVisitor
CallSite`1
System.Runtime.CompilerServices
System.Core
Func`4
CallSite
Target
Invoke
GetTypeFromHandle
RuntimeTypeHandle
CSharpArgumentInfo
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Create
CSharpArgumentInfoFlags
Binder
SetMember
CallSiteBinder
CSharpBinderFlags
get_InnerException
get_StackTrace
WhatsApp
ClassLibrary
Activator
CreateInstance
Action`2
InvokeMember
FillVisitor
instance
Assembly
System.Reflection
Stream
System.IO
MemoryStream
GetManifestResourceStream
CopyTo
GetManifestResourceNames
Func`2
IntPtr
Enumerable
System.Linq
SingleOrDefault
GetExecutingAssembly
ToArray
LogoutProxy
StopProxy
ResetProxy
Concat
PrepareProxy
indexer
_Observer
publisher
VisitProxy
InterruptVisitor
Contains
ResolveProxy
AddProxy
defaultInstance
InvokeProxy
get_Default
VerifyProxy
CallProxy
PopProxy
SettingsBase
Synchronized
Default
DefineProxy
StopVisitor
AssetProxy
CloneProxy
RunProxy
OrderProxy
DestroyProxy
ComputeProxy
CountProxy
PrintProxy
PublishProxy
IncludeProxy
LoginProxy
SearchProxy
FillProxy
CancelProxy
ValidateProxy
PatchVisitor
EnableProxy
SetupProxy
MapProxy
CountVisitor
ConcatProxy
CustomizeProxy
PatchProxy
QueryProxy
PostProxy
ReflectProxy
CreateProxy
ViewProxy
NewProxy
RemoveProxy
CollectProxy
nullCacheLock
nullCache
Dictionary`2
assemblyNames
symbolNames
isAttached
ChangeProxy
CultureToString
CultureInfo
System.Globalization
culture
get_Name
ReadExistingAssembly
AssemblyName
GetName
get_CultureInfo
Equals
StringComparison
AppDomain
GetAssemblies
source
destination
LoadStream
fullName
DeflateStream
System.IO.Compression
CompressionMode
set_Position
IDisposable
Dispose
EndsWith
resourceNames
TryGetValue
ReadStream
stream
get_Length
ReadFromEmbeddedResources
requestedAssemblyName
ToLowerInvariant
IsNullOrEmpty
ResolveAssembly
sender
ResolveEventArgs
Monitor
set_Item
ContainsKey
op_Inequality
get_Flags
AssemblyNameFlags
op_Equality
Attach
Interlocked
Exchange
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
InterruptProxy
ForgotProxy
CheckProxy
ListProxy
AwakeProxy
ExtensionAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
WindowsFormsApp1.Resources.Yzsssqxzgigdrn.dll
WindowsFormsApp1.Resources.Slzefkghbr.dll
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$be554038-d878-445f-bac9-46c9ec4c3d6a
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4Y
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
h&#7R-
ZwIz"<W
8r w"nO\
c(2teh
7Lc<a<k
Q|Z|I8
!|"|#<!P
OU_TV-H:
aNMZS\
m0_06a
6Lq2:`
|?$0q^Y
h#h3b_b
]a\?xL5
stNc.m
8!FrTA
Hr5y1r-Xl
:6"hsk
7]?F~}y>/r
dJqtah
LzFrQp
l`w$&5:
MTb/-$
BOmmQW
Ts}cA<
ER}$hQ
2l#{zG
s9rd7!+
)maw(f
]|$ul"wGQ<
kb\co:
Lt|[WV
VCon-T
}=${Is
9se(wR
c%79E~
XCI="{b
hox_jk
K0>08`
DZ50_j
v[_;+o
|W;?~~
n6$hXh
!N!^!n)|
n`L`T`|@O*`
L=<B}_
T"YcC/
?b2Dwu|>
:H[:HZ
Y%I@Y!
H`fH9(
E=Y'IC$
@/IK%&
?Z!"PT
rA_Y'IMD
d-%;rAS2:
ATdDJ?
d|J:$j
n67pJV$:
%3rA'7
Qw$ip:o
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
_o`gNy
LGxOP$
"/^zGS
D3 2N>
wNCccV
Ii$eDK
QusbErV2E
_xE()t
yzIu "
@t>g]A2
;YO?dr
HYFmYH
k)@?>hLE
sLP`/D"!z
@vGY^[
NgTQzr
6pkZH?@
nBd+y
Y;C^w&
i7ooGq_
oCS(2~
c15a_IN
X+Ghs[
Sd@a:
nPQSw!
%}WI%d
x6.ldb0#)
"e7sG)
fe??M*
{Uv4u6
uw tt
9{IN?I
4'Lq`[#
2GQv^s4
\dc6N^
uL+ka]
cnTyvF
[DiFJI)cI
Npwww'
{pwww'x
>1us&%
^<e`:1
fND/OD
/Q|@{mb"#
+\Jkt"
jncJ+ahkCM
(dkd,lkM+clm`
gn<o>@@
u4w2w1V27
~Pr6pt2wr~w!
wEv91
p[&PaE
ym_S/&
XZr.%o{
cJ,{9^}
lw]P`|
tP;bcF
nx3B)R
*l|T\l
h}RFAL
Z_xTkP
fY[OU[
_YBtEo
;Zpl";
9`X0"[
B4Jg,O
QU_o[F
;xyf.;k
U"bsB\C
sg1MOi
qMgyC>
9=Z%x&
.$&:&0
sCkZ}A{
j]NnE*0
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
{0xepE
[_|{^1
!)LmcejXf
ZIBlOx
S$7Kc?
|E6Zc{
I_$i]#}
Wc?@/W
3fT)&
3ENfnyf
.(/NbqyI
QLL=W*
f#ROXWK
V)*;!q
J\iPnRnQ
EA_,6:03
xihVX/Pw_y
3NVhR
TB*!53
M`oF>QnB]
VA)^e
(XvTF{
Hfw/av
Kkr[sL6
qja&>`
]Qw)mt
s$<8p/
"Ndl-
}AC2|k
aDPV#JD
,<LFAF
~Z(f9@
"RH*k*
@s}C}SC
el3aG-
tXXHV:
]N')<O
X:3/q+ND
qll8yeS"
&VcZ>I
z`W+63,
.6\^xr
7~wX_M
_CorExeMain
mscoree.dll
z[]>!^
"^h#O;
Nwo]_:|
Ld`%N2
f{l7;E
n&5z9nv
`fr-.|
zKr]7h=%-!
al_MMP
B`3^Ka+
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
==============================================
CatchAndThrowEx:
CatchAndThrow:
Didide by zero error
DoStuff2:
Yzsssqxzgigdrn
Contact2
Slzefkghbr
Inner exception:
Contact1
Dailup
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
IMG_106_680_74_80.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
IMG_106_680_74_80.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.e05e738dcb98a9f8
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.a35cc4
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FEMF
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.87508725
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.Inject
eGambit PE.Heur.InvalidSig
Fortinet Clean
Qihoo-360 Clean
Paloalto Clean
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Clean
No IRMA results available.