Static | ZeroBOX

PE Compile Time

2021-05-17 06:41:13

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004e964 0x0004ea00 7.94131125548
.rsrc 0x00052000 0x000043ac 0x00004400 4.2028502912
.reloc 0x00058000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000536a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x000536a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294967295, next used block 4294967295
RT_ICON 0x000536a0 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 4294967295, next used block 4294967295
RT_GROUP_ICON 0x00055c48 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00055c78 0x00000580 LANG_NEUTRAL SUBLANG_NEUTRAL XENIX 8086 relocatable or 80286 small model
RT_MANIFEST 0x000561f8 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
GRACE.exe
<Module>
Settings
Xvtxfer.Properties
ApplicationSettingsBase
System.Configuration
System
Request
GRACE.States
Object
mscorlib
DatabaseModelExpression
ValueType
PoolWriterCandidate
Xvtxfer.Candidates
InvocationValueConfig
GRACE.Configurations
PrototypeGlobalResolver
GRACE.Resolver
StrategyWriterCandidate
Importer
Xvtxfer.Common
IncludePage
.cctor
SettingsBase
Synchronized
CollectPage
Boolean
ForgotPage
_Writer
m_Property
String
connection
global
_Singleton
_Policy
PublishPage
DefineInfo
ListInfo
IncludeInfo
PostInfo
PopInfo
FillInfo
DisableInfo
GetInfo
ConnectInfo
DestroyInfo
VerifyPage
CreatePage
m_Base
PreparePage
RateInfo
Concat
JsonConvert
Newtonsoft.Json
SerializeObject
Console
WriteLine
ConnectPage
InsertPage
ResetPage
List`1
System.Collections.Generic
Tuple`2
AssetPage
Notifications
Twitter
ClassLibrary1
set_o1
set_o3
set_o2
Thread
System.Threading
ConcatInfo
Assembly
System.Reflection
Stream
System.IO
get_Length
GetExecutingAssembly
Func`2
IntPtr
Enumerable
System.Linq
System.Core
SingleOrDefault
IEnumerable`1
CallInfo
InvokeInfo
FirstOrDefault
get_Item1
CountInfo
Enumerator
GetEnumerator
get_Count
get_Item2
get_Current
MoveNext
IDisposable
Dispose
Format
GetPage
Explore
PrintPage
AwakePage
ComparePage
GetManifestResourceNames
ResolvePage
GetManifestResourceStream
RegisterPage
CalculatePage
m_Task
ReadPage
ReadInfo
Contains
ManagePage
ListPage
InterruptPage
WriteInfo
op_Equality
PrepareInfo
StopPage
WritePage
CustomizePage
VisitInfo
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
FindInfo
ResolveEventArgs
ToArray
CloneInfo
instance
selection
RatePage
DeletePage
SearchPage
FindPage
RuntimeFieldHandle
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
NewPage
InitPage
ValidatePage
AssemblyDescriptionAttribute
GuidAttribute
System.Runtime.InteropServices
ComVisibleAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyTitleAttribute
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
CompilerGeneratedAttribute
DebuggerBrowsableAttribute
System.Diagnostics
DebuggerBrowsableState
ParamArrayAttribute
Xvtxfer.Resources.Olrsfjxvzz.dll
Xvtxfer.Resources.Rwraogxdw.dll
$NpWCC
<Cisco Packet Tracer 8.0 32Bit Setup
$21cd640f-a8e3-4712-9bee-d1f376c7e1b4
d
<Cisco Packet Tracer 8.0 32Bit
<Cisco Systems, Inc.
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
8.0.0.211
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
P}&*QO
$-D',l@j*#
>v)C>>X
tz>5[Va>
6Qovc|EyAh5
[kb{iD
(cOr4[
bR0v,7
dg6v>L
"~M(EM
Ye#YYL\F6
,)mB)E_
DcQTF
Z#KDuQ
{O36T8
#=}vhED
(u0[^F
Z0l4kmd
9]z"D-
WnT+6]
Tjr5+F
+2326a
tetUVdFy|
rJBbJN
<v0IMF
5Y[SX>
~nyqXO
1T}enJ
%H]`:zg^
M8DLW`
q*7?`n
;)$!v?yW-h
)C3mkJK}&
k#hI=z
W{XsB%
$MHLv}
t&[XSBi
T-?_f^
+;XmB=
Uh[{XGB3
D.nBik5S
_hj<J .
6nD&`1{C}
XZ7gD
:hW0%
LmG~Qj
zu7m%I
''_yM"
j,~F7Lp
bkuNLq
*zs6)|
^,v[Np/
)Xt`:U
Y%i[4Q
8K[c&D
Cz'OBc
}JzgOi
.q)!>nF~!ay6n6f
\Lqzzk
;gSk''S
sc|Scg
6-.$s:]
us/9j{i
$-+) <<
.ff6v>
aVFzbT
%93'/?}>
N^VSiqJ
1%>6,~?
~.9-u<
%%$ #$
DRK8&!
}{=]51
vQaV^|
9=7zTW
i.N~6)Yf.
:<%||n
Zr_[Gh
]==L]kl
XXay|jhtHHiS
h\f,Vm
xx]MyYs
440r:?
^FNcwwqQn|U
#Sbb++'
Kv,22RN
MjDDla
g([L8;
SoAv6n
[kwKGSp
fZtJ^Nj
,)(/]OK
N^QQit
mYuC]<
M>f]6,
GG$Os'
^>~Oa1
DHGG2m
iF~IqaZ
[WKsS4
M*8"%7
03cj>R
\B&6nLqV
[OC[IL
Xo6zof
[OI[IM
)m=)`.&gP
D&i=&z.'
=6z=6J
_(y$e3!
DRJS{/
qjUS?N
LP~:A1
[r:Gk5
F}E.*
X]mf=<JP
LEw,FV
gc<zGm
eu*&#U
(k? 2/
My$b\s
"Z3V)0
f'?u s
>-,#ZY:
#~487)E
VJQ l@
dMhj@5
+&jgw*D
<3q+{.
p6e3mm
K_#*ph
},6;%A
3Ik{>T#
NEzw<T
n|K=~E
Vm|#;W
y!+q:N
8ubonK
y8`~?L
OPWJ^R
R~%O}P
ZZ/qn9
AzHK4B
^W#B4/
P'`-B'f
CB}?;L
(%C*'E
ZZ?uih
cq62jV
^nP?(H
nS)x_(
2~IZt|
2>[otj
J|O\"r
4c<t:w8p
TA=tn!]
NA&w$D<p
I2#kwC
E:~Hitu
*<'xB@
v}aZ]Q
(X8Or~vw$"
:;jm-6
J97[d
fT0:*wy
X>rO>T
:R\%8A
xyl`1/>
B+nWmy
Dok7?p
4TjsL4N
4:@lb I
83(>y
k6WQ <
E&(9;=Pi
0x8n28
~Ix@/r
*UJ&A[
f0v_LS
|Dh<mF
sg-VA(
jbvc*Q
$,aIX[
~DL@~C
o.xa;Q
{/|S@.`
Qw>A>
?,}[@~
=hwiD{P
hzC5*??
:-E^U|
F1|(J<N
m`d<hh(
:kQ*jF
o.Mpt3z
9Tl_B6
T`SK=i)
%,FqwB
!HGc|T
+1Xp88
$${>dL
IzIu9RJ
#@):?>
3ex3eF
%qhWB/
V*k>/k
adTjL
}ki-59+
UY;F2/
ASe*HY
1K]USQ
|%5<_i%
m};S]cv
!NpRKm
iEMc'oMU
'tl>)B``.
tqF/nY
utkeGfK
HWn3t_
6LFg_g
rA:U&}
/S,HwZB
/AKEC{
4a,oB.
oKwr,b
0>Nrd3F
%:HI7i~
ivO6t7A
oUWWW=
8emf=4a
!<2n:
yL|C{P
*r<$T9
R%1d^=@
!->]J7
P1u`ev
toa[gp
8hAma
Jcc7bz4
bY0a^u
aDFvi#?^,.
*dy]+G
l)GR;j
yWsFpmO
W0"R,T
@Cg5>l(\`
9/'bF(j
;hEcpa
8A#i0h
7y2&o#
ScPYOh
%`%U*
kK<(\[
dF<&7kMc
7y%QVk
cJktmw
aRz0|Ne
u'4e-^
C% V|*W
2DY)4M
-<hP-Y
w9[CL<g
Uzh}p
zVe'C/
D.pT1|
kp==@w
fk%$k
BdBo0"
>3G4A8
^-`mF "L
uK9Q6&
aQF j"
RQTh+F$<
(RI@v@
WNb11b
Pkam
x(_5z%
)NI "@
(hE3S@%$
~~@G!j
g!B}D|T6d
/o2+4u
ep;$*o
~>s>&k
Qz<,>oX
Z0zwf'{
aop;zi
<q3+ZG4
'_{YR2
*gPo)>8
(Sn\}q
s.?qkK
g?[3Is
lZ{twph
.]~=wimM
7=N>jO
IO&y9Xncm
I&uo6O
t~k}kJ
tM)4$|
^*),DS
n`@s7B,
SgR!\gM
(eqA~K6g
R.59_m
C!`yLD`
a~)4v{Nn
{Bzx?g
;6Nkw8
8pe*5g
J7$OO
0]X?i!
v8~/IGGD
)qhxR(w
c34P'v
l O m~
hmDf]H
(`M2qd
pT,yH+
=hxIrQ
|W>+<J
OI{n*U7"3
T{n-!a'?NS
2?>Yc}lj
b?Ni N
T?h$-WE
@@n|br?
cC5=a/
%&w[1n
|z2W*=
b\WPd?_
VUTch=
.#WBJf
dmc;!9
AG+<*>
bwtGiBG{'
[6;9hX
G;q+ux
jx)S4Q"
c5jn/t
t.myB<
>1m=g[W
D@jU.d_0@N
39Mqmd
%>xx,-Y
/&JmjIw
t7x]8K#
7%p5y>
@OZzrII
BUTT{m
+v-Bdi
H0F'T<
.s]XC*4vh
',8#zUc
sIi[pv
'!KD#B.
Z.JXW@
*a`r=7san
sMfA}$
7$'pr
R4Wc*WR
1PSQ>E
ca><$7:
qk?Q>@
RT\L['
F;;(Ut
hM^rMK
P[g?t1^
F]iKgb
R#GQc
8JSh0a:?D
Q6Kse ?
GP~ *Dr
B'd=*C
XL1ba"w
!kq.6O
k5$Z2x
Vs1g(E
|Uq<Zbi
URFQ|/%
C-D*EqL
T^Qn;~r*
>"wOov
:3_*gd
o-<D6A]
xfJg96
iQt%ljH
w:w;37
jC:g!j
^{hJ`58d
*)N^;;
v[Y=W_
&gqMw6#
pB=}^
NW0NL$"
e.W/3Y
S?!Rf!
*f'Y'6
q|m$N-
.(~^7E+\y
Kz`#bj
TlR#C
l;n^K@
Mdd}j;
b9ZeWz
PCF}*4r
Ly?IGk
{*B+|sX
T|+2JP
^-^nQ6
IX@vOPz\
t{o|w
WN.}+J
(:1D=b
b~F:)4
7)*lg.<
H%E|&ncy
0]e|6|e@u
-W(YiB
+wNGa
/h2tNe
_|Xh/1
442c W
KmH@=
Zqa,Lx
-F536]q
gXSf-g
PX4!'-
^FJYA-M^#A
QYh .c~
=p{Vz"
H!i|aB>-
xpR|Z>
E84>$O
_`fa\4
|@wzYV
BM;\2e
W,$$s5
srsTo3
mqjC#~
/%dBVv
wdj/S~
qo(/s1
9[U&e;
0>h1|.4
!L9?hM*o
KG|64Ni
[KY^/|>
ieInIw
.5)a *zP
@MN"GH
hwIe"OG
\29'W6f
QRCBl-
U/(IaB
{gd^,1
:fg\6Y
43,{,.r&
)=SK&=
IL:)`\
!3#A//
= :&Rf
*6Rrl6l
h-Hv`<Th
/@Y/({
sCC~[h
)p%xBP
QVZTVTVVZVZdX
GYYYZQ
['i7-9
ZOHMnA
q*@J^d
D3%Eh_j
P;8(%7:
2H\*$?
Nz{Mo9
xn'_qo*A
>Aisjo
ic'z@If
sUWS:"
em}d]}d
eSK~2Z
e&%t)DQOF
6I$32'
h4:h<4
TyFd=z
<'6$2MY
;n^F[Y&
_c"gn==
W5^5x9
|zmUUeu
B[nd{wT
9~Q@.jX
5#7#U76
2,p9\n
r0(a*L
C&N.>/
ql9V*;N$'N'Y
9}fjjvV
payyK&
".1u_1v
V}oamCJ
@L6MU2
*:8'u1!'
T%C9j9
Y!oq HjD
db7!k_Z
af\-/4u
o(LOa5>
byS/vby
0F.$)v
,Ep8XGKQ
3p_|}RGx
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
YffeeffefeefX
Yfefeffefeefhah
Xfeffefeefefhah
afeffeefefa
Yfefefeffe_-
Xfeffefeefefa
ffeeffefeef
ffefeeffe
ffefefeeffe
mffeeffefe
afefefeffefe
9fefeffeefef
ffefefeeffe
mfefeffeef
feffeefeffe
ffefeefeffe
affefeeffe
Rffeeffefea(A
ffeeffefeYa*
feffeefefefY
feffefefeXa*
|CfefefeffeY
feffeeffefea
j9fefefeffe(6
v4.0.30319
#Strings
ClassLibrary1
ClassLibrary1.dll
mscorlib
System
AppDomain
ArgumentOutOfRangeException
Boolean
Buffer
Dictionary`2
System.Collections.Generic
IEnumerable`1
List`1
DebuggerHiddenAttribute
System.Diagnostics
StackFrame
StackTrace
Environment
IDisposable
CompressionMode
System.IO.Compression
GZipStream
EndOfStreamException
System.IO
MemoryStream
Stream
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
MemberInfo
MethodBase
MethodInfo
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeMethodHandle
RuntimeTypeHandle
String
Encoding
System.Text
StringBuilder
Monitor
System.Threading
Thread
UInt16
UInt32
UInt64
<Module>
Notifications
Twitter
.cctor
value__
GetEnumerator
get_o1
set_o1
get_o2
set_o2
get_o3
set_o3
Explore
get_CurrentThread
get_ManagedThreadId
TryGetValue
GetExecutingAssembly
GetCallingAssembly
Append
ToString
GetManifestResourceStream
set_Position
get_Unicode
GetString
Intern
set_Item
get_Count
GetName
get_FullName
GetPublicKeyToken
ReadByte
BlockCopy
GetTypeFromHandle
get_Assembly
AddRange
get_Name
GetBytes
get_Item
GetFrame
GetMethod
get_DeclaringType
get_MetadataToken
get_CurrentDomain
GetType
InvokeMember
GetExportedTypes
CreateInstance
get_Length
ToArray
Dispose
Invoke
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
ClassLibrary
1.0.0.0
Copyright
2021
WrapNonExceptionThrows
$7c158b45-9dc4-4066-8cda-58e028d1a857
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
Flyweight: Displaying shared
and unique
state.
Rwraogxdw
DisableIssuer
Olrsfjxvzz
FlyweightFactory: Can't find a flyweight, creating new one.
FlyweightFactory: Reusing existing flyweight.
FlyweightFactory: I have {0} flyweights:
CL234IR
James Doe
Chevrolet
Camaro2018
Mercedes Benz
Client: Adding a car to database.
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Cisco Packet Tracer 8.0 32Bit Setup
CompanyName
Cisco Systems, Inc.
FileDescription
Cisco Packet Tracer 8.0 32Bit Setup
FileVersion
8.0.0.211
InternalName
GRACE.exe
LegalCopyright
LegalTrademarks
OriginalFilename
GRACE.exe
ProductName
Cisco Packet Tracer 8.0 32Bit
ProductVersion
8.0.0.211
Assembly Version
8.0.0.211
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Ursu.190803
FireEye Generic.mg.7238cb41274f63e1
CAT-QuickHeal Clean
McAfee Artemis!7238CB41274F
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Ursu.190803
K7GW Clean
Cybereason malicious.1274f6
Baidu Clean
Cyren W32/MSIL_Kryptik.CFF.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FFLD
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky UDS:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:MSIL/GenKryptik.50280455
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Ad-Aware Gen:Variant.Ursu.190803
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Gen:Variant.Ursu.190803 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Ursu.190803
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Ursu.D2E953
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.AgentTesla.R350659
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34690.um0@a8jRtbl
ALYac Gen:Variant.Ursu.190803
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.100922700
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH09EG21
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_97%
Fortinet Clean
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.