Static | ZeroBOX

PE Compile Time

2021-04-28 10:51:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002a046 0x0002a200 7.9207347661
.rsrc 0x0002e000 0x00004770 0x00004800 2.24079426326
.reloc 0x00034000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002e06c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000320d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00032120 0x0000042a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00032586 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IMG_001263082.exe
IMG_001263082
<Module>
Program
WindowsFormsApp1
mscorlib
Object
System
<>c__DisplayClass2_0
<>o__3
Settings
WindowsFormsApp1.Properties
ApplicationSettingsBase
System.Configuration
Qmtagm
WindowsFormsApp1.Ykevsqud
Fxrvuppjaob
WindowsFormsApp1.Xpuslfk
Hsejwvyuytl
WindowsFormsApp1.Twescxfwuidrw
Pgetcq
WindowsFormsApp1.Rncaplc
Azaimhrqzmri
WindowsFormsApp1.Pteogee
Qzqfixdlcqjkf
WindowsFormsApp1.Omiwctdynsx
Mrwkrwiigzmlj
WindowsFormsApp1.Phfppzrdajeusk
Tmucbwvpvpfm
WindowsFormsApp1.Nuynqyrl
Uuaymaskranyp
WindowsFormsApp1.Etafxkyevhopx
Lavqxizejb
WindowsFormsApp1.Wplxusgk
Wczpuchryfpcdg
WindowsFormsApp1.Tyzpcfavobapjg
Ssosyv
WindowsFormsApp1.Nyauxmqvpr
Ponwnn
WindowsFormsApp1.Jbjnlmnzvhjrq
Wcimiblrbqdb
WindowsFormsApp1.Birgvy
Epwdbcvgd
WindowsFormsApp1.Wqogkp
Plfazfsdtqpmx
WindowsFormsApp1.Qqidcggwguzfbq
Rnmdsqtyygrc
WindowsFormsApp1.Zeskix
Jpwoxd
WindowsFormsApp1.Higpbvlktvoc
Drmlzcdhnzs
WindowsFormsApp1.Umbwrmfkups
Dpbghoevuzc
WindowsFormsApp1.Klgzvxehjzh
PoweredByAttribute
SmartAssembly.Attributes
Attribute
resourceName
<>p__0
System.Core
CallSite`1
System.Runtime.CompilerServices
Action`5
CallSite
defaultInstance
CurrentDomain_AssemblyResolve
Assembly
System.Reflection
ResolveEventArgs
sender
ShowGCStat
GetEmbeddedResourceContent
<GetEmbeddedResourceContent>b__0
ToString
get_Default
.cctor
Default
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
STAThreadAttribute
WindowsFormsApp1.ClassLibrary1.dll
WindowsFormsApp1.Resources.Cmznrvpqyxtup.dll
WindowsFormsApp1.Resources.Pkslahuxyfmoya.dll
ResolveEventHandler
AppDomain
get_CurrentDomain
add_AssemblyResolve
System.Windows.Forms
Application
Stream
System.IO
CopyTo
MemoryStream
ToArray
IDisposable
Dispose
GetExecutingAssembly
GetTypeFromHandle
RuntimeTypeHandle
get_Namespace
String
Concat
GetManifestResourceStream
CollectionCount
Console
WriteLine
Thread
System.Threading
Func`2
Enumerable
System.Linq
SingleOrDefault
IEnumerable`1
System.Collections.Generic
GetManifestResourceNames
ClassLibrary1
get_MaxGeneration
GetGeneration
GetTotalMemory
Microsoft.CSharp
CSharpArgumentInfo
Microsoft.CSharp.RuntimeBinder
Create
CSharpArgumentInfoFlags
Binder
InvokeMember
CallSiteBinder
CSharpBinderFlags
Target
Invoke
DateTime
get_Now
Collect
WaitForPendingFinalizers
op_Subtraction
TimeSpan
get_TotalMilliseconds
Double
ReadKey
ConsoleKeyInfo
Activator
CreateInstance
Contains
Format
SettingsBase
Synchronized
WrapNonExceptionThrows
Discord - https://discord.com/
Discord Inc.
4Copyright (c) 2020 Discord Inc. All rights reserved.
$76c31f40-9b35-455f-8c66-4152484f7151
0.0.52.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ClassLibrary1
<Module>
System.IO
GetData
inputData
mscorlib
CreateInstance
CompressionMode
IDisposable
get_Name
get_DeclaringType
GetType
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
System.Runtime.Versioning
String
get_Length
ClassLibrary1.dll
GZipStream
MemoryStream
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
MethodInfo
MemberInfo
InvokeMember
Binder
Transalator
Activator
System.Diagnostics
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetTypes
BindingFlags
GzipDecompress
Object
Environment
ToArray
Assembly
op_Equality
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
9ZWC&4
*~~~KE
)75=}o
M-6afr
6!qaau
6;G_ &l
O.:tTc
S]W["~
s>~ff`gN
zk|-R^
!a-Oa
jR&bRD
eXTW1(
@6RO(^
?u&G@>
zqN`)J^
\3Gw[E*
-c;26CP'm
p;!=)Y
-&J<|h&
l@tA6
D'x'Jni
uYw+hA
"ov8i27
M\>NMhO=
CF..U(w
_7nuq6
ke\Vt{
~bTWFb
?~9?~*V
NYzsmY
vFANNLfp}
zqN.+k
!))#-(
l}iiq1
ghl`v?
m`u`E`k@
WMt\-]
/Q9Gl1X
z=}4+5
4]j^7xi
<-x_pY
O*0{shw
Om:NSy
;rW@r7
W`/h]7
g\2L,m
?19e_w
aQ=vT9
7eJ%Oy
hzXe4HS
&.he$H
Rp:8wH
X>bKD^
DCG50m
<jPza!;
f\]#Q-
c6T:((
v=|BGC
|B"n-y,B
?ckP{ko-M#
Alvj-3}
~vu=%cv
d3u3\I
KU`yRP
?^$*j-
^-Kl?]
y" t4Q
%eQRU$
C3\3gt
k/?@)J
oUk[z<S
u0]=cOU7
X!S)b*
=au>(b
a^e)Nxt
lHG~ 3M
"@QTE7
%/9j!/
eSPZ7>
>&0oV1
}SemET
7wK^ktUH
qU Srtx
jqU StwaoMa
Xa1N2P
RNE@N'
(9<Of><
#PP^A-5
UCP]J_j/R
DY=QoK0
fA3 ~
AzA_ /
AJAw ;
2~>hhhds
~5#sc!
k)~//<
\\xUw:c^
D&-^,
SXFX"3
.>A>mD
p4B(7X
YV]FVS\
UJbFR|
{|wUk
-"(f\.
/e]YY?
+~YN=;uA
.- *$(
yj>!+:
mf:> #
Bmh78h
N??w,
(mc"f-)k/*
YEUi}usG
.$"/&(#!*
.-%"+*
Llmn>!.
Ex$4,< 0
QtMY&L
RBDJPHFF\GC
]3nv*>n.i
]S>.m)N
nUu>!Ne!
hQ1n`g
\|}|.>!V
ineQNQueea-3
p0>62*'
J)ML^U
^sq{<^'
-i?45U
j>?2mo
hP`nc:
uwA1Q:
Mu/f#M
&OD3*$
{J68hh\D
fc=ae%tP;
FRg*0)k
Rl9v[0
"P+L3Sp
O)~,PR
yF<laqr
${%7`t{[
cc~c99N
3Yfp16G
;p)R13
A6BTYI
BDq7!$8
>v`.Lg
!di2A'
!d<7iBL
{)K*bY%
/!Dvd#
iJglho
3>&NPo
kj8ij0
xjGv<r
12na%R
R]@fr#}k
jXHQA3
5PLJVn
e:rKI'K
2imLn>
5%&`1(
OZ+v|n
tUuWuMOOW
gGCkZ"E
/~QGC7
[3z)c;[Z
nZsr46
~#\Nrm
N@eQ e
z>n<)1C}H
hs#De$%G
MGxfmk@
S@N#.O~ln
T%Y}Ha*
fERe,b
eVlC*7
qb]O_tU
u+R1C!]
]*rkRRK
qJh/Fs
y.\K6N
<*VG5Zrj
v]oeS1
}rZ{\<
BLnFi=
}hlLlP2
U*88/ R7>O
uqh(F<
4+'"<Hbn
F,nWzq
}q5g}PDI>
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
|an3S7
"EEE=oYs
~y*;*\
Gp3ar!
&y88*W4
#O`!S%
o2,sW4'
6{+hAYZ
`t=G30a
1% CT~
a:Y&Ce
*=ka61X
qvXT&=F
P'@u^1
p[T*)?
'RX+"y
*vdht?=
RA[KZt\.
]HWxPm
OWa$wS
UMHD:
_l~iMOW
1X~Tl
Q33-%
E-vG*I#'@v
nC8DIg
RVW&%@
"H"bgk
Z'!$m8
K15EkZl.
Q4?Y!A
)[QE\8
L<E1Kh
[CxkHP
(P6p>o
qF~tE$
{p~<Ml
@;VY3zN
}7X-s2*
QN>(Wo
?,pgu
[ED#:J|!
U ".+};0A[XJ
zk@*_
C~%00P
h[>fTu
aYKM{,
Dss<ub
,gi<cf
paYcg{
_mJ7;b
VlirP#cO
rfly|2.
ljj:s\
zy8azrz'
kQ)u5*$
+*BX/P
,`T#g,I
VA+X~E8$
+uSf,w4
p%"\"/
iv#ORN
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
.ClassLibrary1.dll
generation 0 checked {0} times
generation 0 checked {0} times
Pkslahuxyfmoya
memory in heap {0}
heap have {0} generation
RENAULT
Cmznrvpqyxtup
Object car in {0} generation
Size of memeory in heap {0}
Transalator
QuerySerializer
size of heap {0}
start GC
GC worked
size of memeory {0}
Object car in {0} generation.
{0} with speed{1} km/h
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
IMG_001263082.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
IMG_001263082.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.6e18d889d1ecbd6b
CAT-QuickHeal Clean
McAfee Artemis!6E18D889D1EC
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34684.mm1@aehaIDh
Cyren W32/MSIL_Kryptik.EBW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AAQQ
Baidu Clean
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
SentinelOne Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/AgentTesla!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.Bladabindi!8.B1F (CLOUD)
Yandex Clean
Ikarus Trojan.Inject
eGambit PE.Heur.InvalidSig
Fortinet Clean
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.d1971a
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.