Static | ZeroBOX

PE Compile Time

2083-10-01 19:50:34

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000ddc4 0x0000de00 6.81230040872
.rsrc 0x00010000 0x000005e8 0x00000600 4.45460863978
.reloc 0x00012000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000100a0 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000103fc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ICollection`1
List`1
ToInt32
IDictionary`2
get_Yn3ZU5D1d4O43aKfdc5Cau0l826elc091d67
get_C3Ubo4i6ab46e9v2b4563IH317a0a3e9
set_C3Ubo4i6ab46e9v2b4563IH317a0a3e9
System.IO
FUNCFLAGS
System.Xaml.Schema
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Versioned
Synchronized
Append
XamlCollectionKind
GetGetMethod
Replace
Microsoft.VisualStudio.Workspace
IWorkspace
CryptoAPITransformMode
IEnumerable
IDisposable
get_IsVisible
RuntimeTypeHandle
GetTypeFromHandle
CallByName
DateTime
MakeGenericType
get_IsGenericType
CallType
get_ReturnType
Capture
MethodBase
ApplicationSettingsBase
Dispose
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
ParamArrayAttribute
get_Value
GetValue
Microsoft.VisualStudio.Services.Client.Interactive
System.Threading
Microsoft.VisualStudio.Services.Client.Keychain.Logging
Microsoft.VisualStudio.Services.Client.AccountManagement.Logging
DownloadString
ToString
GetString
Formatting
get_FilePath
GetFolderPath
get_Length
ClientChannelSinkStack
IsPublicOrInternal
CheckForNull
NotNull
System.Xaml
get_Item
set_Item
System
IsAssignableFrom
Boolean
TimeSpan
Version
Conversion
System.Security.Authentication
Microsoft.VisualStudio.Validation
System.Configuration
Microsoft.VisualStudio.Workspace.Implementation
op_Subtraction
System.Reflection
MatchCollection
GroupCollection
WebHeaderCollection
GetGenericTypeDefinition
XamlSchemaException
KeyNotFoundException
MissingManifestResourceException
IndexOutOfRangeException
JsonReaderException
InvalidComObjectException
InvalidCastException
Microsoft.VisualStudio.Services.Common
Newtonsoft.Json
StringComparison
BinaryMethodReturn
CompareTo
MethodInfo
MemberInfo
ParameterInfo
PropertyInfo
GetMember
IFormatProvider
StringBuilder
MakeRootedUnderWorkingFolder
SpecialFolder
Binder
System.Resources.ResourceManager
ILogger
ParameterModifier
System.CodeDom.Compiler
WorkspaceHelper
JsonNetSettingsHelper
PropertySettingsHelper
IEnumerator
GetEnumerator
.cctor
TypeReflector
Monitor
System.Diagnostics
get_TotalSeconds
GetInterfaces
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
Matches
System.Runtime.InteropServices.ComTypes
MemberTypes
EmptyTypes
Requires
System.Net.Primitives
BindingFlags
DeserializeSettings
IPropertySettings
Equals
System.Runtime.Remoting.Channels
SslProtocols
System.Text.RegularExpressions
System.Collections
StringSplitOptions
get_Groups
get_Chars
get_Headers
GetParameters
Exists
Concat
Format
SerializeObject
System.Net
Microsoft
WebClient
Environment
IWorkspaceDocument
get_Current
GetCurrentTextContent
LogEvent
JsonConvert
MoveNext
System.Text
ReadAllText
WriteAllText
get_Now
get_IsArray
System.Security.Cryptography
System.Runtime.Serialization.Formatters.Binary
IDictionary
op_Equality
op_Inequality
ArgumentUtility
DiagnosticsLoggingMessageSeverity
CheckStringForNullOrEmpty
IsNullOrEmpty
GetProperty
yAyOy=y
yQyAyPy@y y
%S3\313p3F3]3u3^3K3U3`3^313-3o3133333
lilhlflhl
]1^.^"^
]/^.^$^
:`:`:d:
mdmtmDmKmsmsmBm
msmumFmwm
mFmWmEmHmCmEm
mwmBmFm
mvm{mCm
!NNN@N
NPN.NSN#NVNYN
A"ARAAA
W?W%WDW
W/W%WCW
cI*C*H*H*
*Y*_*C*C*H*H*q*s*C*`*b*u*A*r*h*F*D*z*s*D*i*u*A*B*A*u*|*I*D*q*I*|*I*A*f*q*U*s*E*d*
7JdJeJJJ1J1J1J
45.5-5
4+5-5+535
5.5-5?5A5
9BB2B@B
BFBUB@B1BHBEBCB
B@BBB%B
B+B6B.B
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.6.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGX
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
100119000000Z
380118235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
130509000000Z
280508235959Z0}1
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA0
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
http://ocsp.comodoca.com0
SN20s
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA0
181113000000Z
211108235959Z0h1
Cambridgeshire1
Cambridge1
Simon Tatham1
Simon Tatham0
https://secure.comodo.net/CPS0C
2http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
2http://crt.comodoca.com/COMODORSACodeSigningCA.crt0$
http://ocsp.comodoca.com0
'&"=oaCR=0>
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA
190922093006Z0
SSH, Telnet and Rlogin client
3https://www.chiark.greenend.org.uk/~sgtatham/putty/0
Run(+!!c^
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
190922093017Z0#
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
100119000000Z
380118235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
130509000000Z
280508235959Z0}1
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA0
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
http://ocsp.comodoca.com0
SN20s
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA0
181113000000Z
211108235959Z0h1
Cambridgeshire1
Cambridge1
Simon Tatham1
Simon Tatham0
https://secure.comodo.net/CPS0C
2http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
2http://crt.comodoca.com/COMODORSACodeSigningCA.crt0$
http://ocsp.comodoca.com0
'&"=oaCR=0>
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Greater Manchester1
Salford1
COMODO CA Limited1#0!
COMODO RSA Code Signing CA
190922093017Z0
SSH, Telnet and Rlogin client
3https://www.chiark.greenend.org.uk/~sgtatham/putty/0
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
190922093028Z0#
C3Ubo4i6ab46e9v2b4563IH317a0a3e9
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-7D77BFB8D680A99A3DEC3EF11B63CBC1.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-00C6707A4C3680722D987A5BB7114B0B.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-307E578725C4F3AA44F824BA2753FDB2.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-16116FCB016B7CAA5050F3DB0E637327.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-E2304DCD5B5C3352E705442E9DABC84C.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-EEC279DBCBA0C0CE17E741F5C0B1F0BE.html
http://ldvamlwhdpetnyn.ml/liverpool-fc-news/features/steven-gerrard-liverpool-future-dalglish--goal-E81034F64EBA344DC31E3E3D72E849B5.html
<meta name="keywords" content="([\w\d ]*)">
UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 OPR/38.0.2220.41
WxRfapPVwg
GetType
Assembly
ToArray
EntryPoint
Invoke
VS_VERSION_INFO
StringFileInfo
040904e4
ProductName
Ad Muncher
FileDescription
Ad Muncher
CompanyName
Murray Hurps Software Pty Ltd
LegalCopyright
Copyright
Murray Hurps Software Pty Ltd
LegalTrademarks
209e4aa6 7495 4be2 8d17 a6891daef034
Comments
a5366510 cfd2 45fd ba47 6f3c0ba1356b
08cc5d86-6422-406a-98e9-f9457a66535f
VarFileInfo
Translation
<<<Obsolete>>
<<<Obsolete>>
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.aa94a9e0f856bbe5
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.7baba4
BitDefenderTheta Gen:NN.ZemsilCO.34688.em2@amPIufki
Cyren W32/MSIL_Kryptik.ECN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HVI
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
MicroWorld-eScan Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition PWS-FCYO!AA94A9E0F856
CMC Clean
Emsisoft Clean
Ikarus Trojan.Inject
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira HEUR/AGEN.1142886
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Clean
Acronis Clean
McAfee PWS-FCYO!AA94A9E0F856
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.Agent!jemwtb+HDpM
SentinelOne Static AI - Malicious PE
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Agent.HVC!tr.dldr
Webroot Clean
Paloalto Clean
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.