Static | ZeroBOX

PE Compile Time

2021-04-28 11:09:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00029c86 0x00029e00 7.92505429021
.rsrc 0x0002c000 0x00004778 0x00004800 2.23946615796
.reloc 0x00032000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002c06c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000300d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00030120 0x00000432 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003058e 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
FPI_0485010214.exe
FPI_0485010214
<Module>
Program
WindowsFormsApp1
mscorlib
Object
System
<>c__DisplayClass2_0
<>o__3
Settings
WindowsFormsApp1.Properties
ApplicationSettingsBase
System.Configuration
Xqchacorrdppgw
WindowsFormsApp1.Nrxnphp
Hgifhodmthtv
WindowsFormsApp1.Oopdxoj
Zewvodxhg
WindowsFormsApp1.Focluehkwrim
Nuzscmuxin
WindowsFormsApp1.Ofalvlzlxea
Fzyfczhzhdzecj
WindowsFormsApp1.Puxlhazxttrzo
Uiztvs
WindowsFormsApp1.Dlchjpyugvdw
Uqwethyct
WindowsFormsApp1.Uzyqrchm
Ksccyu
WindowsFormsApp1.Ulxgsuht
Epusxeovgkwbvm
WindowsFormsApp1.Enadxqwwdzkx
Ckcvnnexim
WindowsFormsApp1.Dpqitpyiacoiy
Oaanivziztptr
WindowsFormsApp1.Arkdai
Jokjhgeikmo
WindowsFormsApp1.Effjlfdf
Rlskrgexztcor
WindowsFormsApp1.Mawmzez
Wzawynwvfynb
WindowsFormsApp1.Xnamtmgqeqt
Xuavze
WindowsFormsApp1.Hbmhvgqcwsfi
Ggmevbsxz
WindowsFormsApp1.Fxwhurylkrm
Cyrnsas
WindowsFormsApp1.Txtusnseajyryq
Qzvmbwqqycsfq
WindowsFormsApp1.Ruqsrafnqtxpt
PoweredByAttribute
SmartAssembly.Attributes
Attribute
resourceName
<>p__0
System.Core
CallSite`1
System.Runtime.CompilerServices
Action`5
CallSite
defaultInstance
CurrentDomain_AssemblyResolve
Assembly
System.Reflection
ResolveEventArgs
sender
ShowGCStat
GetEmbeddedResourceContent
<GetEmbeddedResourceContent>b__0
ToString
get_Default
.cctor
Default
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
STAThreadAttribute
WindowsFormsApp1.ClassLibrary1.dll
WindowsFormsApp1.Resources.Opurhbjehyb.dll
WindowsFormsApp1.Resources.Cwnbyk.dll
ResolveEventHandler
AppDomain
get_CurrentDomain
add_AssemblyResolve
System.Windows.Forms
Application
Stream
System.IO
CopyTo
MemoryStream
ToArray
IDisposable
Dispose
GetExecutingAssembly
GetTypeFromHandle
RuntimeTypeHandle
get_Namespace
String
Concat
GetManifestResourceStream
CollectionCount
Console
WriteLine
Thread
System.Threading
Func`2
Enumerable
System.Linq
SingleOrDefault
IEnumerable`1
System.Collections.Generic
GetManifestResourceNames
ClassLibrary1
get_MaxGeneration
GetGeneration
GetTotalMemory
Microsoft.CSharp
CSharpArgumentInfo
Microsoft.CSharp.RuntimeBinder
Create
CSharpArgumentInfoFlags
Binder
InvokeMember
CallSiteBinder
CSharpBinderFlags
Target
Invoke
DateTime
get_Now
Collect
WaitForPendingFinalizers
op_Subtraction
TimeSpan
get_TotalMilliseconds
Double
ReadKey
ConsoleKeyInfo
Activator
CreateInstance
Contains
Format
SettingsBase
Synchronized
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$5ed1db35-c690-406f-bf51-8a08c2a9ac4a
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ClassLibrary1
<Module>
System.IO
GetData
inputData
mscorlib
CreateInstance
CompressionMode
IDisposable
get_Name
get_DeclaringType
GetType
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
System.Runtime.Versioning
String
get_Length
ClassLibrary1.dll
GZipStream
MemoryStream
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
MethodInfo
MemberInfo
InvokeMember
Binder
Transalator
Activator
System.Diagnostics
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetTypes
BindingFlags
GzipDecompress
Object
Environment
ToArray
Assembly
op_Equality
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
?tq~Ft
NyF3#;Y
rS^Qfo
6;G_ &l
"5FP#pp
cM.8jG
!aos!avv`gN
c/O_^T
e.N&F[
"[_k4N
-&J<|h&
YY7=:MYe
V`:`+2Fp
T`8`*0S
~2)(vz01
}|T gu
-(:0x
ZY8D49F
+mMsTnZ
qnVnGA
/;?"5i
@ON5=y
@FY@|)
PpcYmw
JJ\QIGnO
SHj'QI
Dh\C]G
;YEo()
AxNxFxv~
.X{O>K
)S<O9
v0{Kxw
|hkqVq
_^[1zo
fOl"v$
8kv_Vpa
%~^GIp
|av-[?
o^B_{y
PDPDAQQ
|5W#0
qNFp[;=g
z69ygQ
NK$}w`
WC%TB_
54*U5M
!T1!P1[
;AV{Xu
@K@eb[u
,($zYo
;{[Hwy
xxO.{x3
m3|:FSD
9I\8qYL
{%n+ Em_q
&Ri'mk
MMoZ-j
{`Q9e+0
`9_I9BI
"QkQW%nuFW
:JB{_<
Cr[ 8e
u/$}W$
VU2LAGh3
n$&.E(_[
^eR#jE-
oxEc4F
PPDQq,
TcUg"cT
4 SYFX
}C$l/5!
Alu2oT
QNEBN'
A"Ak 5
fA|A3 >
&A\@\A
lyRT|c
E?6o3P
B0N)>T
AJAw ;
AL@L@c
UcGJ9R
u^\NST8/
ThDNf;[
FW[_EJR]
wZ2m%'
dCT;KP(e
7W02772
Yu~A,Jrj
ml}w?{
SG"Kq=
lg+??
c}gK{Wwv
B0?Z3
J{Z{?M
++[i(HF5
@24dcI
b!LO0_
Ul66]7
1=!7<|?
+;7/){8N~
sP9M+,l
}]X\0%
wBZ@\@X
WOkkGgGo
vT;>^+j
E}g7Wk
@.XNFX
_]R|j?
|UXLETFX_
VBK8tJLEEP\5
ee^5u>I
IJA]^1##
.(!(n,#
w?J}?gy#
u57;7?8
|i<6TWn
i{O^vZD
y]ycyGO
@iDD2C"
4xtZ=f
,@bELV
~Tc Cn
{fo6:[
4S.+s+
F)BG-j
T.L60
~/PIjDU
Zw$Q-s
]E4@Op@%
Qt}2@m
3Rtb:iX/1\p
- HnVM
M$18I
6C~#+[
H])?{=
0LP$9
7$-I$c
-bt{hv
d^y.VN$
oU91 W,
cz)!pJ=K
\~D_pO
C8VDJq
&f%)[q
'L}x@_
[*".KP
y6bM37
v#v~h\
k/Lqmf}57
%F-F:(K
8B*~|1
?<_}uP
D<I1BH
W_Wn#e
xfOm&n
uW5HZ7
/O5T?y
DQ333;ffffv
3^ni?K
D![#ca[kZ
7Xk]%[
u4w2w1V27
<acCsk}
-'cnee
|asSs'
vs57zkl
O]a.s5
'~Q4<-L
a%, $_
+hhZzx?
^zIRy`^6m
"!r{1`
T%Z~Nf(0v
^U_dGm
!*3W:|
w7Z`JSnm
r[H/^%
AOw<2rB
G{h] 0
g;rfh0
U"bsB\C
^R@Y`>3
a.^nx/X
{"})hI
]n#[w&
4F)Y&U
sCkZ}A{
j]NnE*0
'_Bk1*
@k]gB w
:g6=J~
.{T7Itig
XLK&=(
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
8PaT)g
mn3tDl
hk5&\_
o2,sW$'
|aVZA@M*
=[P+`)
*>>*4M
g'L5)G]
dsR(9
k 2>]7
FzZh;Y
0 /_U6
e-x2W:e
\kxc (
,NBiA[?
]?'S`U
YDomHp
:rqp]}
p `o%Dn
"H<bgk
KGi8%R
1t$8B,g
CAfL{o
@1Gy?s
bdh=^\-
]}(0F^%
@gMNzw
XE'j&W
q`P>T9]
ShKu%Ec2
8_sw_.
\T+/5%
p?p5>u
FuG&"e
%du8$Gb
T=Rw{4:
mA(Qkl
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
.ClassLibrary1.dll
generation 0 checked {0} times
generation 0 checked {0} times
Cwnbyk
memory in heap {0}
heap have {0} generation
RENAULT
Opurhbjehyb
Object car in {0} generation
Size of memeory in heap {0}
Transalator
IncludeService
size of heap {0}
start GC
GC worked
size of memeory {0}
Object car in {0} generation.
{0} with speed{1} km/h
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
FPI_0485010214.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
FPI_0485010214.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Trojan.Agent.FGOU
FireEye Generic.mg.00bc3f04139ef508
CAT-QuickHeal Clean
McAfee Artemis!00BC3F04139E
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Trojan ( 0057b95d1 )
BitDefender Trojan.Agent.FGOU
K7GW Trojan ( 0057b95d1 )
Cybereason malicious.09436c
Arcabit Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.EBW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FEPS
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Trojan.Agent.FGOU
TACHYON Clean
Emsisoft Trojan.Agent.FGOU (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/AgentTesla!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan-Stealer.SnakeKeyLogger.FD2TZE
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Kryptik.C4443843
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34684.mm1@ai5zAEf
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH0CDS21
Rising Backdoor.Bladabindi!8.B1F (CLOUD)
Yandex Clean
Ikarus Trojan.MSIL.Krypt
eGambit PE.Heur.InvalidSig
Fortinet W32/Bladabindi.FEPS!tr.bdr
Webroot W32.Trojan.Gen
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.