Static | ZeroBOX

PE Compile Time

2021-05-26 01:13:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002f299 0x0002f400 7.91384270164
.rsrc 0x00032000 0x000046a6 0x00004800 4.31666338547
.reloc 0x00038000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003206c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000360d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00036120 0x00000360 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000364bc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+!+&+'+(+)
+&+++0+5+6
v4.0.30319
#Strings
ConsoleApp4.exe
ConsoleApp4
<Module>
mscorlib
Object
System
MulticastDelegate
System.Windows.Forms
Settings
Yecevrsaldro.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
IContainer
System.ComponentModel
Button
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
System.Reflection
ResolveEventArgs
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
EventArgs
.cctor
Culture
Xzrlppt
Jchjjpopnlhl
Default
Dispose
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
EditorBrowsableState
.resources
.resources
Yecevrsaldro.ClassLibrary1.dll
System.Drawing
Control
set_Size
set_TabIndex
set_Text
ButtonBase
set_UseVisualStyleBackColor
EventHandler
add_Click
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_ClientSize
get_Controls
ControlCollection
set_Name
add_Load
ResumeLayout
SuspendLayout
set_Location
MemoryStream
System.IO
ToArray
Stream
CopyTo
IDisposable
GetExecutingAssembly
GetManifestResourceStream
PerformClick
ClassLibrary1
RepositoryDescriptorConsumer
ClassLibrary1.Consumers
StopListener
Console
WriteLine
ResolveEventHandler
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
AppDomain
get_CurrentDomain
add_AssemblyResolve
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
Email Sorter
Copyright
ASTGD 2018
$9f30ecaa-b749-4cb1-bd0e-3ecd2d6b0e71
1.3.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
-J8w]q
e~G!/_7
qX1B W
q'(}y9CX
->~UsKY
',o^cX^
Z.[z5m
5`Fb,vK(
ds!7Nb
6!tNW\;*
F-F&s,
y1Ilf%
^%J5`N2
fRh>_s
ghK tX
pB`>_=V
'&)zcNCh
D3{TM%a
U OT
v8EB?^
Ci]xq,G
EoT[r-j
rztZBv
w<91@H
X5q!:w
Tjr5+F
uQd[wf
SuvVSei7
Z=FDos
6mz=fFu|
d)daJ#
dT&yBd
fJ^zvbzZc
1;77=1)
vfqAYO,L
@U?-X,
pTcgL'D
R T`GL?
LGX]ej
}\an'7
dFdpd[
'S)OyUy^
?b[MkS
A^zoTE
KX}ikl
OoH8o(/Z
~]1O](
4m&M1{
S"m'-2a
ZwS?m!^
_&jcKI
eKI?^g[
$J4SSI7
y4S=m&~
ZFZ`o_#]2
b+HgLqi
7ZOTi8
N|L<r;(wm
)>)S)`
Zbh?CF
A{<qKL
fB@{<}
-mH:GL
Q^AoB/
?3IVmF
=AL]SN
+?<-3^
9B%IIEV
4wz>6'
!*xV\X
}Q]9Z@f
|RzrRRUM
/y-U=y*
zfn^!>
cW7w3P
}S~]t7
yayNLQmr
1mT:@*
qNZJR]U]@
n&Z9:-^.z}I1b
vxx||xxvvq
vEEJGQL
rzl|TrjeYYD
|Z3<?{\
QVaaQnFz=&"
c]bBjEgm
Z6zgczqq^Q
N~Znfa9
c)")!d"."-
bRvbMX
58~8/L
GJ)KWd
mWGgWg
={'E[j
jMU[I\
JjL~cD
QQ2o[:(
s np>1
NESjRd
1!&FOz
^.q!nIIE
&isYP^
"+cbdj
vu'QZ1aF
T|zMiH
WT#}}C
eF+IKw
iybqMr
F&fG1I
5#-;8s=M
xDDP{p~
^}7c+
!EQUEj
|-8-(h#
W@HQTa
O\B*`$
HQT'QP_
%6'-`H
!-PYF8
"L&1`H
z+R=?<
/6J/6j
p_am0-
GX?bz6
ZIMX/X
ZIIZMEm
!HJ!HA`M0S
65`&vs
|J>d[|
=Z/03z
1}){O%;8
#fXm;#dK;J
Rpnw)V]
Nmi_Z=
}dC#GH[
[jqEt6s
qwge;Y
6"R)]/
m3?}6[
f*.OD
fq]W.7s
+VH2M#
cm3"ti
gZtJ~V
h,=O7M
<+:j{w*Fo
~QUWhns
,iQ,=s)
/[==j9
w4RvCg
Ky.s|z
OsV}aD
Bq{260
~F%qDf
xt_"U%
"$n(n7
,%3Z:a p
"j%S"7
;z0PZ}
W#1m&,y
XuSK#b5
_P4!Ul
;(s#k.m
;2"{on
Z^Q>(On
-oeih}
{y`s{F
I!r?Y6
CAEw=
&o{5y^
?V|).p7
o%ad}9\
HTUXPj
VM%.@5a$
o,Q<3wW
kr _hw%
r48gSc1a
|$#~^^]N
k`WX!;
>wu!V+
Ad|Wo2
Qz%O%
*We!1r
p}hjJU
//+*?<
;@:#R.
J[9<)~
Kmn.8s
aj[^\
Zjrxql{-6mp
]K{jg
yV_6Nl
!O$2>
LS95[~o
D?:$\:sA
59RES2
MaQo3Y
-'K"6&r
^@3!QSJ
#V_i2:
3O5Il#
T0DhG)
0=M}a
:=Q{3P
DjVbwK
=N:c,*ra
i=9-Lgl
3FC=93
6a!`cp
G>&O T
+i."u{V@
VL4,xV2
[c+5@XN}
{>xa$z
J;a^kS
r:_@U=
$_k$Lf
iMuCMu
bzCCbk
b"}Q{BR
2!ieRQb
'DeB(c
{^$LgOj
C i7S<L
>taMEl
>(%NM
]H|Hh}mPpb
kV6%|C
2a{ww_
lWI`jS
v<2oIa
77wlhB
Ls\<)~
K,Oyy'
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
33F~m?
}i=?FF^k
KuIx=}s
a_Sel&
iV]g&k
uv{}yaw:
NU'E27b
#'NYi~
G\Jw:4:}<b\}
vIl_nC
8F1OYth
W>t0G\
{SNq~_
Ie3'x
3hwWly
_wog>Z
>2]30U
uMq{oxX_
k8KIFA^z
!LJ0QE
WXV,bo0{$bm
2021*`T
#8v=X?
"#?| #?
A,i<b[ s
%bfLL&8Q
K_kHmZ
eJ(fd#
.QC~$#Ge
YN%Hm2
&BG^8S
z8}9}5]
00|&/ B
pfr9Apv
9 2v00
Qph"e'
n`8+H\K(
J*RIE*
RIC*iH%
axOVWW'S
*KjI`M
DR!Hh*U
PR;\VT
5aoPs4
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
b l!MHa
7ca .W
cf K/.
cf K/.
c {FQX
}(a |x+=a
g#ZIX
c P=5Ca
Xe {KO
cf K/.
f Yu4Ba
cf K/.
%P-e ;
D3wj
sXYYe
g#ZIX
g#ZIX
v4.0.30319
#Strings
ClassLibrary1
ClassLibrary1.dll
<Module>
RepositoryDescriptorConsumer
ClassLibrary1.Consumers
Object
System
mscorlib
<Module>{f2cd1422-f32c-4ac4-808c-fe068cd336cf}
listener
_Broadcaster
m_Visitor
String
ExcludePolicy
CountListener
PopListener
PushListener
InstantiateListener
EnableListener
RestartListener
StopListener
connection
CalcListener
AppDomain
MemoryStream
System.IO
Assembly
System.Reflection
GZipStream
System.IO.Compression
MethodInfo
Concat
Thread
System.Threading
InvokeMember
BindingFlags
Binder
Stream
CompressionMode
Boolean
GetMethods
GetTypes
ToArray
MethodBase
Invoke
MemberInfo
get_Name
ToString
op_Equality
get_FullName
CreateInstance
get_Length
IDisposable
Dispose
get_CurrentDomain
Environment
GetPolicy
AddPolicy
CheckPolicy
LoginPolicy
GetType
m_ab7eac5714bb464db19109ccef62dfeb
m_13b3fab00aeb4817872a8413faf782f4
m_8671769d67c44aeea848058fc51d04a9
m_e1a3425f31104071ab2b05380153b265
m_0c74c9f1a3114466aa092d5aeb7a2bd7
m_5d85c33187874fc58f994814cbde53f8
m_9bceaf18898f4abb9469bf04239ad36d
m_ad18df87c02c4e0e933e509f50a9929e
m_f3c6681dfd1c41ffa263e88170e64cb3
m_4774612a372f48c2a06961745ec1429f
m_f4e79495ea1f4e6e87c71ae6e17cc74a
m_1d0d4802dbc54080b6cee0b5a9aaac2b
m_b463438ce6644ce888fbdf1de18357f4
m_7447a2f27d2e4246b1175f5f83f5fd94
m_05070091b1e242b6b2823b34336fbf22
m_7d693d6c82714b0e8e62600aa16000f1
m_039e6d664f8c46c1921b62465cb3370e
m_b9f3076b86764bdb9cd8e1439d423868
m_e153c89fa33c427e8b6e181de7705fab
m_0f5fbc4cb2e248b3a57251ab01081c9c
m_183e51c991424f048d6a126dfe5f32a7
m_47849af62228447a97fd397415df91e3
m_387735b7824641b1910dee94e2929bc4
m_b12258f522b64b3c92b675657b93e654
m_414186aca32944be9528161dc566b341
m_75b715adc1e2470c981a940c8baf3268
m_c49ce5496d4b4d02856223d9fb34e99b
m_edd8f84846a143ec99f050bf217108a5
m_80e875b7cb764888a1ee090719510231
m_73c6088cb807495ea8b2e0ae49215958
m_7a24d89caf0447f39484f8a29c5f424a
m_07c248420fc944a7ba750d5eb1f729dc
m_87c25bfed4d0468b99b482f83156fade
m_321da0687d9e46f9a2721b7509a79cfc
m_16f21e29911344ce98774e95b469423d
m_400582a5eb6e42c987d7a17caaacc7bd
m_69c8aaf000454e4091ab131b08ba2cbb
m_004a8736129e456dba79e06f418d96c7
m_b6e59f25060d4b9ab0dedb8640dd12fd
m_c282b315070a42e695d100ae1d1d3f69
m_a20d9ab474944224a2a975fa44dcf437
m_2685963e5a184af39e84c03d2d8eaf7f
m_f66f088598404b51b9ad598eaf074ceb
m_ec3a2c9da1f243348a32c0538aa48f2c
m_e9587fd733d4495fad9f2cf715d63efa
m_4ff9dc5e5db24d9b87f7e911fb9e4240
m_cc8f3d80dd0f4b69a4171eee5117e91c
m_e3b0c563036d40b8aa9adfae013096b5
m_c2648f041c9448c9ab0c79357d74a612
m_8e4e5b5ec969447aba899f6a8bd4b798
m_3bc6af1dd834452cb0fa863294eeb9e1
m_713b1130bb0542e3bf91ce382a4b962a
m_071cce42ffa84448a1be6452f4f3cba8
m_cc5f8cf6e9644654b7eb9866cb60c99f
m_9a21ccfde0ca4d9195b9b80fdba9e013
m_dc7577bcaa2f4f4f8a9f5f9f6252e86d
m_a12a8ed9dab54ce0bad4686f9007c34a
m_c8c026a9bc8843ad806bcd400bcc6561
m_c767b505852d45d182f53807033baff8
m_9e6e9555b403455993fafe1f22d286ab
m_7b1be1a79ebc47d6817dfd0d36fdfa48
m_a644a286454f4e188ff6d1a72f6869c9
m_850dd47d214a4fe182bb251bbade3db9
m_d22050b5a3f941dc86513d2f25e215ba
m_dd581b1190664657a295fa2eb1b7d681
m_5bca2343966e4f15904393294bc39c1e
m_efdcf6d41c59460d830b9c2b91facde7
m_dd25f38d837a4045844771c596707915
m_47437b38be67435ca20b7c2adbcc7513
m_6cb9f3701f034388bca5bad7da298fb9
m_c3caed1a152a43848e525fb4bbd36497
m_d084af86cfa740b8b42746484dd81d38
m_5555737a2adb45c0852ac242c7c0d014
m_5ef8039dd64c45b8aaa1679f0c922991
m_d74517e3ec8c4cf180d5080f5747854d
m_b02b9642ee8a4571bce48d353327019b
m_95f3fc16f393404191513f6819e32360
m_1b087bf9c93143edbf69c13aa173485c
m_c19c5cce736c4840b3b31814d5688f2d
m_560d6ee9f5734d37b2843bbe6e2b461c
m_3d2a4c670dbc48658553fd3d77596517
m_63301607a12b4480b0edddd9444d78c1
m_6e272c4bf6ae47d3b05006610abdef5d
m_6830b500fecf4e1892c046307bbe3b4e
m_96f2bc2abd3d46f98bd1e62f7108068d
m_1c9c167f4597447dba245fefabcbcc16
m_393f5dd529c44c6d99e880446e18fa19
m_bfff91ed9d6a49419ed6fed23db08c85
m_0da75a947e874834b89d42b61d66d645
m_bbfb00ce28ac434982a728968de760ca
m_ebac8ae7bad84272beaa336281d8bf7c
m_dc0528f7210b424d950b98505bde2b41
m_5f2e41e4132341498e399d486f8e9c3e
m_924ac58641964747b2565072aba78fe8
m_bd7e0553a6da4ba88fcc2c1b6a89d256
m_5ab8c0db406d46a4becd8c4e20441209
m_b3e7107cf2a649dc8fcdae31e97b91cc
m_05509df3ebc64439bf7c5bc7ffe7a7f6
m_20c0881cbf6948439a6ac8ba724501cc
m_fb8169b401054acc87869e610ba6257c
m_33bd622c6bfc400f8fb129159c4adaa9
m_14b655fbcae34e38bee20dd360e96987
m_1daf17a983a041c1a739ebbb44d37dc3
m_9514b40ad96a4ad2ae3848a5540dd7f7
m_4886172bce274021b6ac0ebf9de745df
m_44fd6aaae38146608ea6aa732e8e9da5
m_7d02f4b91950438aa05e086185d7da22
m_293587384311469e946a610744b00027
m_0ee5fef59fb84a52a2b7a30daa32356a
m_6afd18b6f6b64d80a5e02ce2997a72c7
m_ebe984bfdbe04f3fb1cfc3df913d396a
m_aca4720d442e4740a4e53ac8ddd23d46
m_643567c416604d20861a648b7a9c1250
m_c53b3149edb543d4802d528e5f7a57ac
RestartPolicy
.cctor
v2a67b3fc84c149138380e347be9c2bb9
VisitPolicy
NewPolicy
PostPolicy
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
WrapNonExceptionThrows
ClassLibrary
Copyright
2021
$7c158b45-9dc4-4066-8cda-58e028d1a857
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
button1
Yecevrsaldro.ClassLibrary1.dll
4 + 10 = {0}
ComputeCallback
Xzrlppt
Jchjjpopnlhl
Jchjjpopnlhl
Xzrlppt
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Email Sorter
CompanyName
FileDescription
Email Sorter
FileVersion
1.3.0.0
InternalName
ConsoleApp4.exe
LegalCopyright
Copyright
ASTGD 2018
LegalTrademarks
OriginalFilename
ConsoleApp4.exe
ProductName
Email Sorter
ProductVersion
1.3.0.0
Assembly Version
1.3.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.2bb5676bd130e551
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.bd130e
BitDefenderTheta Clean
Cyren W32/MSIL_Kryptik.EIC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.AAQQ
Zoner Clean
TrendMicro-HouseCall Clean
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:Trojan-PSW.MSIL.Agensla.gen
Alibaba Trojan:MSIL/Kryptik.b7de5b7f
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Clean
TACHYON Clean
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Crypt
GData MSIL.Trojan-Stealer.AgentTesla.WYBWHE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!2BB5676BD130
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.AAQQ!tr
Webroot Clean
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.