Static | ZeroBOX

PE Compile Time

2044-12-11 08:45:14

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00251b04 0x00251c00 2.58765357154
.rsrc 0x00254000 0x00000720 0x00000800 5.00735904233
.reloc 0x00256000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x002540a0 0x00000494 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00254534 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ahmed0
ToInt32
<Module>
System.IO
astarata
mscorlib
Microsoft.VisualBasic
Replace
instance
RuntimeTypeHandle
GetTypeFromHandle
daName
TryCallName
CallByName
Songofthename
CallType
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
WriteByte
ToByte
GetObjectValue
astarata.exe
System.Runtime.Versioning
ToString
get_Length
MemoryStream
Program
System
Boolean
Interaction
System.Reflection
Intention
InitializePacker
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
packerBytes
get_Chars
RuntimeHelpers
Concat
Object
intent
InitializeRoot
Convert
ToArray
op_Equality
Func`5
IReflectableType
TypeLibVarAttribute
String
Stream
.cctor
Format
WrapNonExceptionThrows
astarata
Copyright
2021
$3d079790-d72d-44b7-bb93-932ef9d8599b
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
FULL_TEXT
totallist
yy Vw SUU w n w w w U w w w oAA oAA w w SRU w w w w w w w lU w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w SoR w w w SU nS SRl SU w SRw V owA nn SRU S yl owA nn RU SwU SwA SSA no SSo SSU SSS Swn SSU Vy SwV no VV Vy SSw SSw SSS SSl no VR SwS no SSU SSy SSw no SwA SSw no lR yV Rn no SwV SSS Sww SwS Ul Sn Sn Sw nl w w w w w w w Rw lV w w yl S n w ooU Al VV Slo w w w w w w w w ooU w nU w SS S Rw w w Ao A w w l w w w w w w yR Rn A w w no w w w Vl A w w w w Sl w no w w w o w w U w w w w w w w U w w w w w w w w Slw A w w o w w w w w w o w lU Snn w w Sl w w Sl w w w w Sl w w Sl w w w w w w Sl w w w w w w w w w w w oUR Ro A w Rn w w w w Vl A w Snl n w w w w w w w w w w w w w w w w w w w SoR A w So w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w w no w w R w w w w w w w w w w w R no w w yo w w w w w w w w w w w Ul SSl SwS Sow SSl w w w RU AS A w w no w w w Ao A w w o w w w w w w w w w w w w w w no w w Vl Ul SSU SSA SSU VV w w w Snl n w w w Vl
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}
{0}{1}{2}{3}
{0}{1}
{0}{1}{2}{3}{4}
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
CompanyName
FileDescription
FileVersion
4.771.258.759
LegalCopyright
All Rights Reserved
InternalName
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
4.771.258.759
Assembly Version
4.771.258.759
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.58dac0
Baidu Clean
Cyren W32/MSIL_Kryptik.EKB.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABDX
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/runner.ali1000123
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.Win32.Malicious.4!c
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.vz
FireEye Generic.mg.ca1cad0dfeee9119
Sophos ML/PE-A
Ikarus Clean
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!CA1CAD0DFEEE
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34692.uo0@aW5eEpji
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Clean
No IRMA results available.