Static | ZeroBOX

PE Compile Time

2021-05-03 07:53:53

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00031724 0x00031800 7.93978345701
.rsrc 0x00034000 0x0000472c 0x00004800 2.1901673024
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00034130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00038158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003816c 0x0000040a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038578 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
afefeffefeef
Yfeffefefea
afeffefefefea
affeeffefe
Xffefeeffea
afeffeeffefe
Xfefeffeefhah
Yffeefeffeefhah
Yfefefeffeefa
Yfeffeefefef_:
Xfeffefefea
5fefeffefeef
ffeeffefe
feffeefef
gfeffeefef
affeeffefe
9fefefeffe
fefeffefeef
gfeffeefef
fefeffeefef
5ffeeffeefef
afeffeefeffe
fefefeffefeYa8
fefeffeefY
ffeefeffeefXa8
fefeffefefeY
ffeeffeeffea
feffeefefef(K
pkfefefefeffea(V
v4.0.30319
#Strings
Pcsyh.exe
<Module>
Helper
Plboaqeapinner
Object
System
mscorlib
Settings
Plboaqeapinner.Properties
ApplicationSettingsBase
System.Configuration
Adapter
Plboaqeapinner.States
StatusVisitorAnnotation
InitializerResolverPage
PrinterCreatorCandidate
Plboaqeapinner.Candidates
OrderItemState
DefinitionValProperty
InvocationObserverComp
Pcsyh.Composer
StructVisitorAnnotation
Plboaqeapinner.Annotations
RuleValProperty
IteratorResolverPage
Pcsyh.Pages
Predicate
Pcsyh.Configurations
PredicateRecordTask
Pcsyh.Tasks
Interceptor
Pcsyh.Writers
ValueValProperty
ContextVisitorAnnotation
Factory
SchemaValProperty
ConfigDic
Plboaqeapinner.Dictionaries
ObserverTagQueue
Pcsyh.Queues
WatcherClassSchema
Pcsyh.Schemes
PopulationPriority
ValAttributePolicy
ConfigurationRecordVisitor
Pcsyh.Visitors
ClientIdentifierWatcher
ParamsTagContainer
ErrorResolverPage
Repository
VisitorAttributePolicy
GlobalRecordVisitor
Manager
.cctor
SettingsBase
Synchronized
_Visitor
m_Attribute
_Creator
observer
m_Composer
_Resolver
flags_init
Thread
System.Threading
get_CurrentThread
get_ManagedThreadId
CollectAdapter
64np2vwhtpbzl5w6q7zsr5tty8vrqeqslZOPa
Boolean
RestartAdapter
OrderAdapter
ReflectAdapter
NotSupportedException
m_Identifier
m_Test
record
_Product
init_amount
RunAdapter
SearchAdapter
_Token
m_Class
writer
m_Filter
m_Utils
mean_ident
RemoveAdapter
SetupAdapter
WriteAdapter
ConnectAdapter
ListAdapter
SetAdapter
AppDomain
get_CurrentDomain
ResolveEventHandler
IntPtr
add_AssemblyResolve
DestroyAdapter
Assembly
System.Reflection
ResolveEventArgs
Stream
System.IO
MemoryStream
BufferedStream
GetExecutingAssembly
GetTypeFromHandle
RuntimeTypeHandle
get_Namespace
String
Concat
GetManifestResourceStream
CopyTo
ToArray
GZipStream
System.IO.Compression
CompressionMode
IDisposable
Dispose
ConcatAdapter
GetManifestResourceNames
Func`2
Enumerable
System.Linq
System.Core
SingleOrDefault
IEnumerable`1
System.Collections.Generic
get_Length
InvokeAdapter
HttpWebRequest
System.Net
HttpWebResponse
StreamReader
ClassLibrary1
Activator
CreateInstance
WebRequest
Create
GetResponse
WebResponse
GetResponseStream
TextReader
ReadToEnd
Console
WriteLine
Application
System.Windows.Forms
get_ExecutablePath
get_StartupPath
op_Inequality
CSharpArgumentInfo
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
CSharpArgumentInfoFlags
Binder
InvokeMember
CallSiteBinder
System.Runtime.CompilerServices
CSharpBinderFlags
CallSite`1
Action`5
CallSite
Target
Invoke
FindAdapter
reference
Contains
_Singleton
m_Watcher
m_Parameter
account
_Mapper
system
_Wrapper
Dictionary`2
_Interpreter
_Template
StackFrame
System.Diagnostics
StackTrace
MethodBase
GetFrame
GetMethod
MemberInfo
get_DeclaringType
RuntimeMethodHandle
ResolveAdapter
var1_min
Monitor
TryGetValue
MapAdapter
assetID
isconnection
StringBuilder
System.Text
UInt16
UInt32
AssemblyName
GetCallingAssembly
Append
ToString
set_Position
Encoding
get_Unicode
GetString
Intern
set_Item
get_Count
NewAdapter
GetName
get_FullName
AssetAdapter
GetPublicKeyToken
DisableAdapter
custlength
get_Assembly
RateAdapter
vis_length
helper
value__
strategy
reader
DefineAdapter
PrintAdapter
ValidateAdapter
LogoutAdapter
EndOfStreamException
SelectAdapter
param_High
ReadByte
PrepareAdapter
CloneAdapter
first_amount
ArgumentOutOfRangeException
Buffer
BlockCopy
m_Facade
PostAdapter
UInt64
List`1
AddRange
get_Name
GetBytes
get_Item
CustomizeAdapter
CreateAdapter
VisitAdapter
get_MetadataToken
m_Model
_Database
MoveAdapter
CalcAdapter
start_def
IncludeAdapter
task_start
num_visitor
ChangeAdapter
indexOf_spec
indexOf_result
ExcludeAdapter
ident_Ptr
previous_connection
CalculateAdapter
ManageAdapter
InterruptAdapter
VerifyAdapter
ComputeAdapter
EnableAdapter
AssemblyFileVersionAttribute
CompilationRelaxationsAttribute
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
RuntimeCompatibilityAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerHiddenAttribute
STAThreadAttribute
Plboaqeapinner.ClassLibrary1.dll
Plboaqeapinner.Resources.Dtxwcrmposp.dll
Plboaqeapinner.Resources.Ykfoeqdygqhsxv.dll
0.0.52.0
$1f7ea7d0-792e-40f1-b4ea-68e8934ac229
4Copyright (c) 2020 Discord Inc. All rights reserved.
Discord - https://discord.com/
Discord Inc.
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
;*n>O!
HkzNIA
#9<fb3J
9}"71
WEw'eyXV
'#c]s0
HYU3L%m
i])pC7N
bHF"#/
gShK]<:J
m2D/d"Nx
=>b0(z
['o$y~f
/$WI?K
[^{C?8
CIqXyTA
`/V<7p
Z44a><5
G{U{V6
KR-O56
)vW/,nC
{(vW>V>T
sKOJe.
9Q%oeS
/,^M~L<
UA;@{AG@
u/24\W
:u:gnm
|AirHj8Q
zYaZl3
^<aZHPItzrjAD~|
fdhiDPah
1,'SU
~fLt06p
EAM""(
***(J1$
]lt_cV
NdUff@;
o,^B'2
V1thOk[)
&q!Nw{
j$eq#T
f4.s{*m
ke>G[|
=Ow>5;2
Cs{RvY
9S(0m6
Dg<oY:
o_kos.Sm4
2WW:GQ
hox_jk
K0>08`
DZ50_j
v[_;+o
|W;?~~
n6$hXh
!N!^!n)|
n`L`T`|@O*`
L=<B}_
T"YcC/
?b2Dwu|>
:H[:HZ
Y%I@Y!
H`fH9(
E=Y'IC$
@/IK%&
?Z!"PT
rA_Y'IMD
d-%;rAS2:
ATdDJ?
d|J:$j
n67pJV$:
%3rA'7
Qw$ip:o
wd^x[!
fr2dk"
Y:UC@]W
B'}!01
*Mn](s
e|v5zI
UJAx4
~4xGL.
}5h<ba
.AMpyQ
NErb@JP
cfzl9
@[]6Kk
:+^d>h
ue v/"
4"Vj"
kW?z=j
VM{V~x
#MjB@P
5r{bSe
vkxZ)h
<@z3^t
Nw\`WI
>a|lBlX
O'@Ze4~$o
v@Z>IM
7IjdyT
xdo-~G
]wfaMj
W$i.RC
}2=6Trc
i-[ZKV
Rt|S%R
#z\]YS
.]Vpub/
{Q^fCF
giQ0"m
wq4cq{
\45>%N
Dj;{>q
!j2/M]A
X%YcS&
LG@1dGt
Y\oY\R
`~<0_:
TYjB'DL
Ar,:|D
hqZ)Rp
xkNiWr
G[k9[Z
@'vLO^{7.
+7E"tb
*q>Fl?
r)59GxLr
f&,6(~
,[m@.:
_>j(ikC
:=xX;6t
0Dq@l`
!vb3!vI
>,/|63
=OM^soE>K
MaV3Gu
y)kN5*}H
Kse(,Z@
]jME0!
t,G*.9
ZlI>E&d
ZM4$cm
L]nmO`
&[*V.q2
v jkZ'`x
])I%<f
}>K8nE_V
KbMOb<
t3\A6Y
d..igHkqx!OQ
06?x,a
TmAba7
L]>O)S|j8sK:2
7t7t12
dC_Tm9
Dd0&yq;'L~
P\0DG9
[c+Ws,
c3Abqc
(,np3m
KW@=hS
,|IrlH
N6#]N]
}<Lvr"
Ft^qy%
s5>X`r
s(|?d'
qxG+]51
&"=iE0
+RsDZJ
_|)T:HhG
Mf,z]i
$RTy&c
81M=+
l|]Q|t
^B~v3*
gorBj"
U3JTUt
>d@kEo\S
0l@Cs(
Ppg4)U
G }=m<
(k~GP{
EzJjB*
D#o> Avy
_U-vT1
Zo5~p7
FF'nVW
0j6RHf
|BM/.h
RTBhb&
h<F-kC
S*{wY3
e-(8s4
]O><c1
n8oVw[
'3[>0w}
Q|f^tR
%dUl#H
Q"UfCiDQ
6z}|s)5
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
oh;;&9
/->N.g
k}oQ)#.XxP
7;_v)+
LVg.P4!W
h_C&pO6\0
`.t10HQ
Fb3,^%
lFqv|M+
V|_BA
?zm}0U
09W,19h
:;S/a"~w
N+%w<H
41r~Y\
$=y@]'
'8agBp4v
CaDY^"
7,W}YSJ}S
+|Bjj6
%6v0|z$
RoH_`!
Xy`M;XF
@4|Lw
1uCTuL
+pxf^tQ
#m4~0n
M|:q>
2+bO}a
2#L<c-c
_tKWJdxr
,.{;FW
G6>kUJ
%o+w".H
+slN"I
63zk@r5
MK8TXEdI
G3gvR+
u-H0-
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
180314000000Z
210218120000Z0
Delaware1
Private Organization1
51288621
California1
San Francisco1
Discord Inc.1
Discord Inc.0
_v<WBP
US-DELAWARE-51288620
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
20200910175959Z
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
141022000000Z
241022000000Z0G1
DigiCert1%0#
DigiCert Timestamp Responder0
https://www.digicert.com/CPS0
2http://crl3.digicert.com/DigiCertAssuredIDCA-1.crl08
2http://crl4.digicert.com/DigiCertAssuredIDCA-1.crl0w
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertAssuredIDCA-1.crt0
iW!]4/q
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
211110000000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-10
.http://www.digicert.com/ssl-cps-repository.htm0
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0
DigiCert Inc1
www.digicert.com1!0
DigiCert Assured ID CA-1
200910175959Z0#
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Discord - https://discord.com/
CompanyName
Discord Inc.
FileDescription
Discord - https://discord.com/
FileVersion
0.0.52.0
InternalName
Pcsyh.exe
LegalCopyright
Copyright (c) 2020 Discord Inc. All rights reserved.
LegalTrademarks
OriginalFilename
Pcsyh.exe
ProductName
Discord - https://discord.com/
ProductVersion
0.0.52.0
Assembly Version
0.0.52.0
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.2b4a1bcc464360c3
CAT-QuickHeal Clean
McAfee Artemis!2B4A1BCC4643
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.fa3473
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FEUY
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/GenKryptik.d026eff3
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Ad-Aware Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Formbook!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34686.om1@aKo5y4o
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.4276529596
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Win32:RATX-gen [Trj]
Paloalto Clean
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.