Static | ZeroBOX

PE Compile Time

2021-04-28 20:42:34

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00030320 0x00030400 7.94744233558
.rsrc 0x00034000 0x00004734 0x00004800 2.30656857948
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00034130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00038158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003816c 0x00000412 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038580 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-.&&rA
- &&rA
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ClassLibrary1
<Module>
System.IO
GetData
inputData
mscorlib
CreateInstance
CompressionMode
IDisposable
get_Name
get_DeclaringType
GetType
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
System.Runtime.Versioning
String
get_Length
ClassLibrary1.dll
GZipStream
MemoryStream
System
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
MethodInfo
MemberInfo
InvokeMember
Binder
Transalator
Activator
System.Diagnostics
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetTypes
BindingFlags
GzipDecompress
Object
Environment
ToArray
Assembly
op_Equality
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
%WtDo']
mg_[{%
"_#NB>K
DD,U1d
<v<@\'
TCOQ=(
m.AzM]q
&T>P%/
4TE?J^
]Q}A&t
=U}P}X
.}$}"ZG4
/?)? \
$nH~BY
h)h%P:
Y5zxxG
Id0mM[/
X;]=<0z
"* 4"X
rDzQrdvvqR
/\X&K_
qXA~BBYBBA
<BPhbLe
$@^[nPb
bzatBZ
.aPPF|4O
zHFZ{l
AJYz\
Ts}cA<
ER}$hQ
2l#{zG
s9rd7!+
)maw(f
]|$ul"wGQ<
kb\co:
Lt|[WV
VCon-T
}=${Is
9se(wR
c%79E~
XCI="{b
hox_jk
K0>08`
DZ50_j
v[_;+o
|W;?~~
n6$hXh
!N!^!n)|
n`L`T`|@O*`
L=<B}_
T"YcC/
?b2Dwu|>
:H[:HZ
Y%I@Y!
H`fH9(
E=Y'IC$
@/IK%&
?Z!"PT
rA_Y'IMD
d-%;rAS2:
ATdDJ?
d|J:$j
n67pJV$:
%3rA'7
Qw$ip:o
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
8As%:BKj
rM~[4e
TG`P^
Rf*P.h'
l'[];H
U&&NG>
M'pDmFJpB
@Samy
,lkgf4d
LLF#Xq
n?f.9|BK
0YlV.l
x(363p
$KJQ~z
sQ@g(Qz
a).QL{
s-%)O\
~3bQB
Fj02HPT&
x}-$(s
Ht8d*m
fs kmQ
p3b{{3
7[MQI9
Y,tf,t6X
a!l{K
Sjns)@
TU{Mnh
Y+/gWp
DSR\}x
cUxP9^
rypYGp1
MInj9S_3
YaM!&M^
b!k"+Q[
m2]DNE
?jo22e)
_TC}+c
u4w2w1V27
j,a{Vx{
J>(cjn
`mnh_u
WQ2wh
p[nmH%
(}<E%_
L\Jtgm%
vr4Xiic
A({q'>=
Z_xRkP
em=Umur
_YBtEo
^K4iCd
e_29Na
/?D;DS{
m$J#J
YPY1,L
?Lu'S*
mUju,P
}zZ>hp
68ESqM
1V1iC^
LkKX+,W\
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
{0xepE
[_|{^1
3N0NGJ
bvHgnf
wky`s
/5NLk}
})+6RI
; /x@cG
R>qX.y
w(~J];
iYU1_Z
@?Xphx^Zths,F:
n5Z47V
BL.MlI0
1V}_5v
O-lsUE
@l4=m4cU
DOk_OkwO
GxZWq+
v4.0.30319
#Strings
Lcbvsny
Lcbvsny.exe
mscorlib
System.Core
System
System.Windows.Forms
ClassLibrary1
Microsoft.CSharp
WindowsFormsApp1.ClassLibrary1.dll
WindowsFormsApp1.Resources.Hzgrdr.dll
WindowsFormsApp1.Resources.Aqwnvrpx.dll
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action`5
Activator
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
ConsoleKeyInfo
DateTime
Double
Func`2
IDisposable
MemoryStream
System.IO
Stream
IntPtr
Enumerable
System.Linq
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
ResolveEventArgs
ResolveEventHandler
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Thread
System.Threading
TimeSpan
Application
<Module>
WindowsFormsApp1
Settings
WindowsFormsApp1.Properties
.cctor
ToString
CollectionCount
WriteLine
GetExecutingAssembly
GetManifestResourceNames
SingleOrDefault
GetManifestResourceStream
CopyTo
ToArray
GetTypeFromHandle
CreateInstance
GetTotalMemory
get_MaxGeneration
GetGeneration
Create
InvokeMember
Target
Invoke
get_Now
Collect
WaitForPendingFinalizers
op_Subtraction
get_TotalMilliseconds
Concat
ReadKey
Contains
Synchronized
Format
get_CurrentDomain
add_AssemblyResolve
get_Namespace
Dispose
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
$95ca315f-c0eb-4236-a8ff-404b20ae9f9d
4Copyright (c) 2020 Discord Inc. All rights reserved.
Discord - https://discord.com/
Discord Inc.
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
0.0.52.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
scdefghijklmnopq
generation 0 checked {0} times
generation 0 checked {0} times
Aqwnvrpx
memory in heap {0}
heap have {0} generation
RENAULT
Hzgrdr
Object car in {0} generation
Size of memeory in heap {0}
Transalator
CloneReg
size of heap {0}
start GC
GC worked
size of memeory {0}
Object car in {0} generation.
{0} with speed{1} km/h
.ClassLibrary1.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Lcbvsny.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Lcbvsny.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Gen:Variant.Bulz.455425
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.4276529596
Zillya Clean
AegisLab Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.455425
K7GW Clean
Cybereason malicious.0475f0
BitDefenderTheta Gen:NN.ZemsilF.34684.nm1@aynSwom
Cyren W32/MSIL_Kryptik.ECD.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AAQW
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.NanoBot.gen
Alibaba Trojan:MSIL/GenKryptik.d02ee2b5
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Bulz.455425
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.ef8bf0e0c08418ed
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.NanoBot.gen
GData Gen:Variant.Bulz.455425
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!EF8BF0E0C084
TACHYON Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Backdoor.NanoBot!8.28C (CLOUD)
Yandex Clean
Ikarus Trojan.Inject
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.AAQQ!tr
MaxSecure Clean
Avast Clean
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.