Static | ZeroBOX

PE Compile Time

2051-02-27 19:55:01

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00004194 0x00004200 6.56674160228
.rsrc 0x00008000 0x00014e80 0x00015000 7.44451013384
.reloc 0x0001e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001c43c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001c8a4 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001c938 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0001cc94 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
get_77iW5hraJ2A795a2aabvT59Td4fGW6g54J2MKg10
Nullable`1
ThreadLocal`1
List`1
ToInt32
ISTORE_BIND_REFERENCE_TO_ASSEMBLY_FLAGS
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Versioned
Synchronized
Append
CompareMethod
Replace
IsWhiteSpace
IDisposable
CallByName
DateTime
CallType
Capture
ApplicationSettingsBase
Dispose
Create
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
ParamArrayAttribute
get_Value
get_HasValue
System.Diagnostics.Tracing
System.Threading
ToString
GetString
System.Runtime.Remoting
get_Length
SerializationMask
ClaimsPrincipal
get_Item
set_Item
System
Boolean
TimeSpan
Conversion
EtwSession
System.Deployment.Internal.Isolation
System.Configuration
op_Subtraction
MatchCollection
GroupCollection
WebHeaderCollection
MissingManifestResourceException
IndexOutOfRangeException
StringComparison
System.Net.Http
HttpWebRequestLightup
StringBuilder
ResourceManager
RemotingConfigHandler
HttpClientHandler
System.CodeDom.Compiler
IEnumerator
GetEnumerator
.cctor
System.Diagnostics
get_TotalSeconds
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
Matches
Strings
Equals
System.Security.Claims
System.Net.Http.Extensions
System.Text.RegularExpressions
System.Collections
StringSplitOptions
get_Groups
get_Chars
get_Headers
Concat
Format
Object
TryGetAllowAutoRedirect
TrySetAllowAutoRedirect
System.Net
WebClient
get_Current
Convert
HttpWebRequest
MoveNext
System.Text
get_Q1vyEf51ead449bK7pxa0K0v
set_Q1vyEf51ead449bK7pxa0K0v
get_Now
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.6.0.0
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwwwwwwwwp
ggggfvgfvvvwwg
dvvv|vgG
Edtcegfvvvvvggfvvfo
BCgcggggcggvvwx
F4'f4v66rw'rwwv7x
vppccgwg'vx~
%'&6wwwg
gaacgggx
6wgwww
wwwwwwwwwwwww
4vegfvwvvwwx
cacgwgvxxh
ggggxw
FfVef~
2222222222222222222222222222222222222222222
CSEPECCE>79E>C>EPQP|PPP|
C@CCCECEEE||Q|||
E9C@CEEEE||E||||
>7999>>CEQQ|
<5><=?AAAAEE{||
35<<=??IIKKRRR||
6666::;;;::FFHIGJLNNN
"%$%---%
^,^^`ddpddbb
- ,,^^^^)Z[V[['[canu
X_))__[VYUUo
XWesl0Xm[WYq
(MMM00kt
/Mhh/kk
wwwwwwwwwwwwwwwwwwwwwwwww
vvvvvvvvvvvvvvvvvvvvvvvvv
99AAACCCGhhlhnnk~
<>>HKLLMMwqwww|
77<>HILwwwzz||
;;AAFKKnww|
??DDhhjky{
&,-16P\`
#..*0/46Yea[d
rrrrrrrrrrrrrrs
=================gggggggggggggg==g
###&(('g=@m
.02459GRXQm@@m
%+m@@m
*$-3?_fm@Bm
,elcc
BBmYcl
c^ZZcc
PjeTTNMUjcZE
/;71:7O]ll<H
DDDDDDDDDDDDDDDDD
>EzAx'
CQqB0.sQ3B
g)A=_
$B2fA>_
D1DV/
;$FL/:
XRITr
JtelG^
kk* kd
U1Jv`n
[L0~"Ub
$QICKE
u!&<ABb
}G`=_D
; FZQq:0
%*PC}u
T\E6R2
},E0W5
LN/Nl;:
.nr;g+&R
0HFa,1%
!=EX#M#
>H5aYC%h
qK1x"I\
QL`c\e
[PfJaY
Yp_''k
9c*:^B
Tz%ZO
nxW8V./
u^k/T(
1s;zyE
D>l"s$
wNOKh(
d!KH@>
#{d^v
Q33]|`L
V3J("~
W"c?LvR
Q(%1EF
<.(:FQ
FLQ"&eb
`^m0&1
#V;tiX.V
',QDTa
6dZpK0gk
}O:qk[
7L(p)xv=
(V%ZIv
PB#%du
~'LZ~^
KMgR&4
Q/Vdy9
+R|!H
(#Pj"B
Se<xkIDpR
'9Jg8/
s1YM62
'v`7[#
HYVS5fz
}`_*
IDATEQac
-1D\?&
|"%kEn
/-~_F~_9
|zEQW(
9::ck7
y'/FOb
:O*BLY
<E]`KK
bC;8TL
a9+9Z5\
*\?~KR
-L^mFd~}Y
G(-39)
3=Y6<=
)IK9khw
()p><8MM
DJ|q~GH0k,
7w<?[rr4
.[^==nxq
vm`>/q
dYhUZv
idh&+p%
r[!Q$9
./vtc^
H)98l8]5
EI3+Y,J~
p2Zp6Z
0x:I@/2x
4m>G=~
L3&sa2
'_z]~^\;
_z]~^\
eMe-kQD
C9)nz/
9yU3OKv6
uiYNK>~<e
8"/-EY
;{Cb I
VtZ!76
Xd\,3B
Xk1]dL
iqkw@Q[
$"2!=
Mnotxp<EG
IW9UQrR[
1d6O99K9[
\2:[2-
x%`')vyt
lJZUt;!o
<$hZoY^
=lst1c`47
MUT|r2F5ru
O),b-)
aaa6nnn;lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9lll9kkk9lkk9lkk9lkk9lkk9lkk9llk9llk9llk9lll9lll9lll9lll9lll9lll9lll9lll9lll9kkk9lll9ttt<MMM2
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
181107000000Z
211117120000Z0\1
Mountain View1
Google LLC1
Google LLC0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
https://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
20210420001836Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210420001836Z0+
A4Wzq@
Q1vyEf51ead449bK7pxa0K0v
<meta name="keywords" content="([\w\d ]*)">
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-935E964B23126C54BA3A2FFC8EA154CE.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-258E48939AFC85C28CC3028886F4A492.html
UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
DownloadString
YavBQRbTkU
EntryPo
VS_VERSION_INFO
StringFileInfo
040904e4
ProductName
Ad Muncher
FileDescription
Ad Muncher
CompanyName
Murray Hurps Software Pty Ltd
LegalCopyright
Copyright
Murray Hurps Software Pty Ltd
LegalTrademarks
8f40ab5f 512d 49ac 9308 d263c32039cd
Comments
c9e5f82d 9d42 4873 bc63 48ad4347cdf0
47869d0f-e96f-43d5-bd43-4e0e826921e7
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.128943
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HVE
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Worm.VBInjectEx!1.99E6 (CLASSIC)
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Generic.mg.4d0b19cd29e6c8ce
Emsisoft Clean
Ikarus Trojan.Inject
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34684.gm1@a0ZC4Uli
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Agent.HVE!tr.dldr
Webroot Clean
Paloalto Clean
CrowdStrike win/malicious_confidence_60% (D)
Qihoo-360 Clean
No IRMA results available.