Static | ZeroBOX

PE Compile Time

2021-04-26 18:45:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00032a8c 0x00032c00 7.97583236274
.rsrc 0x00036000 0x00029ecc 0x0002a000 4.31186309301
.reloc 0x00060000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005f410 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0005f878 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005f8fc 0x0000041a LANG_NEUTRAL SUBLANG_NEUTRAL ARC archive data, squeezed
RT_MANIFEST 0x0005fd18 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-*&&("
bHF"#/
gShK]<:J
m2D/d"Nx
=>b0(z
['o$y~f
/$WI?K
[^{C?8
CIqXyTA
`/V<7p
Z44a><5
G{U{V6
KR-O56
)vW/,nC
{(vW>V>T
sKOJe.
9Q%oeS
/,^M~L<
UA;@{AG@
u/24\W
:u:gnm
|AirHj8Q
zYaZl3
^<aZHPItzrjAD~|
fdhiDPah
1,'SU
~fLt06p
BOmmQW
m<`;v'
\s)=[x
uGy]ifv
46oe02y
<ciuI@oR
I!KgKp
G:f"I*
h2yVtx
xk,Kvz
K0>0X`
DZ50_j
O&fMT}@
~K\9iS0
I#}'lp]
<|tJ*D
ZRQi4
f`!yE\
L&KXH)2
|<||\/$
'/7
%*=m<O
sJBp0*ea
Ydzx6W
wmSQCqqk
wd2eIy
*zM{^f
43S1{t
ZHk-$5
pJn$03$
JY$D4HY(
SVOY(G
\`w%9d
rSq"NH
zH'%1d
9#pJ.$
)!Oa]_
@^An<0d
V!IqMh
t#Pw9w
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
nvtPRDv
"_$t$.
euBbjY
viri@[
$tCcE7
fA--BY!
_h"TE(Z
&KGKbD
gGIxAO*
eCH*`0
g7+!5*+
(!%^RtE
R\8R5d^
z'P4(MZ
^L8gB_
%Bb</a
FqH2_TM
{3=}MS
9!v)*ukRU
vn'c9
J'=YQ9
_sB@s\
ZpQr>^+
u*}h-s
5P(.0M5
mijC3m_
"8HYs
he?>M%
&M6zD>
:DQW,R
s-VC}d
]%1uxk
[qex.Xk
4OquaFJ
L0)g!p
Cpwww'x
{|za+ei
0`}%=
\(-Z#]
O{bi<hh
_fn$O<
sd~Tw%
NN}vCv
G ^W~
l>p9}9
Us)#GQH`;"
LW]Hp"
.w}Y}Rd
N/\R^{
7vX@<7!
aj3})*=l
+b0:y%V
US7@T)
nfip00De
I~</{!
(<%2hd
r)'dt6
DU`O"c
xyJnYo
XB'Sw
We,7aa
U"5~>p
?*vIj479
HBaBe1
D-5u(|0
fMVvY28
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
l^xewk
h`!|+^
&,%,'|
62 v"L&
+TX/`K[
o5<G&+u
K*;DlY
$1<^d
l w8Hn
33/l@&F>3_
wDS>E=4
N"\OXMXO
6*I&|N
RgH] %B
8r04+@
@^t <jQ
'h68c'
^OA vHO
`f9d&`f
B@-t6q
hxtc0a
c1PUX`Si1
-\t`Rd
P1l`2g8]
oERYPk
"Ndl-
}AC2|k
aDPV#JD
,<LFAF
~Z(f9@
"RH*k*
@s}C}SC
el3aG-
tXXHV:
]N')<O
X:3/q+ND
qll8yeS"
&VcZ>I
z`W+63,
.6\^xr
7~wX_M
v4.0.30319
#Strings
Yekimaoix
Yekimaoix.exe
mscorlib
System.Core
System
ClassLibrary
Microsoft.CSharp
WindowsFormsApp1.Resources.Ypzigi.dll
WindowsFormsApp1.Resources.Epgcvnrfxlz.dll
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action`2
Activator
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
Dictionary`2
System.Collections.Generic
IEnumerable`1
List`1
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
Stopwatch
System.Diagnostics
Exception
Func`2
Func`4
CultureInfo
System.Globalization
IDisposable
CompressionMode
System.IO.Compression
DeflateStream
MemoryStream
System.IO
Stream
IntPtr
Enumerable
System.Linq
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyNameFlags
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
ResolveEventArgs
ResolveEventHandler
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
ExtensionAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
StringComparison
Interlocked
System.Threading
Monitor
Thread
TimeSpan
WhatsApp
<Module>
Settings
WindowsFormsApp1.Properties
WindowsFormsApp1
.cctor
f0659e5905454a5e99b9752afc78b700
Synchronized
get_Name
get_CurrentDomain
GetAssemblies
GetName
Equals
get_CultureInfo
GetExecutingAssembly
EndsWith
GetManifestResourceStream
set_Position
Dispose
TryGetValue
get_Length
ToLowerInvariant
IsNullOrEmpty
Concat
ContainsKey
op_Inequality
op_Equality
set_Item
get_Flags
Exchange
add_AssemblyResolve
WriteLine
StartNew
get_Elapsed
get_Seconds
GetTypeFromHandle
CreateInstance
get_StackTrace
Create
SetMember
Target
Invoke
InvokeMember
get_InnerException
GetManifestResourceNames
SingleOrDefault
CopyTo
ToArray
Contains
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
$bfd5f029-7e17-4402-850f-26bbcda58175
4Copyright (c) 2020 Discord Inc. All rights reserved.
Discord - https://discord.com/
Discord Inc.
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
z[]>!^
"^h#O;
Nwo]_:|
Ld`%N2
f{l7;E
n&5z9nv
`fr-.|
zKr]7h=%-!
al_MMP
B`3^Ka+
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
1bcdefghijklmnopqrstu
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
.compressed
==============================================
CatchAndThrow:
CatchAndThrowEx:
Didide by zero error
DoStuff2:
Contact1
Epgcvnrfxlz
Contact2
Ypzigi
Dailup
Inner exception:
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Yekimaoix.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Yekimaoix.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Gen:Variant.Bulz.449427
FireEye Generic.mg.a746c90dae245470
CAT-QuickHeal Clean
McAfee GenericRXOH-XB!A746C90DAE24
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.449427
K7GW Clean
Cybereason malicious.b78dd8
BitDefenderTheta Gen:NN.ZemsilF.34684.xm1@aGpPiYe
Cyren W32/MSIL_Kryptik.DZK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AAPV
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Trojan:MSIL/GenKryptik.75a4fab1
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.449427
TACHYON Clean
Emsisoft Gen:Variant.Bulz.449427 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Trojan.MSIL.Inject
GData Gen:Variant.Bulz.449427
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Bulz.D6DB93
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
MAX malware (ai score=89)
Malwarebytes Malware.AI.87508725
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit PE.Heur.InvalidSig
Fortinet Clean
Qihoo-360 Clean
Paloalto Clean
CrowdStrike Clean
MaxSecure Clean
No IRMA results available.