Static | ZeroBOX

PE Compile Time

2021-05-27 11:22:27

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002ba8b 0x0002bc00 7.85324220452
.rsrc 0x0002e000 0x0000476c 0x00004800 1.73562750361
.reloc 0x00034000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002e06c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000320d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00032120 0x00000426 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00032582 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
@+(Z+(Z
+(+-+2r7
p+2&#o
+u+y8~
v4.0.30319
#Strings
ConsoleApp10.exe
ConsoleApp10
<Module>
mscorlib
Object
System
MulticastDelegate
Settings
Coyxbbwm.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Assembly
System.Reflection
ResolveEventArgs
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
.cctor
Culture
Voonmw
Zvskyoku
Default
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Coyxbbwm.ClassLibrary1.dll
MemoryStream
System.IO
ToArray
Stream
CopyTo
IDisposable
Dispose
GetExecutingAssembly
GetManifestResourceStream
ClassLibrary1
StubStatusStrategy
ClassLibrary.Strategies
NewVisitor
ResolveEventHandler
Double
ToString
Console
WriteLine
AppDomain
get_CurrentDomain
add_AssemblyResolve
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
Adobe Self Extractor
Adobe Systems Incorporated
CCopyright
2010 Adobe Systems Incorporated. All rights reserved.
$2b8ee9ac-2d9e-4291-999d-f5b3569b7074
10.0.0.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
H{_q:0
x[VD?qn
8[ TU
NPY<u"H&
$8G`Q3
W,8&8{a
V,)@Gb~
"8{bAK
7}Yl88
PF&L,s
Wfo"A*
9@fi{i
OIaOPe
^I8>P
6$yW`)9PUQ
DdE<5l=
mM!9x\
<-@!Rk
!YUp![
2_4rgQ
)9WD%FaK#V
{~u{iK`-
h~\8O,
$u]EE@F
KJq]0}02Be
8-Sm0x
Ym$pJWAm
F|wf2i}4~
`wqZBA
')jo~-
{\u1~Z<{
dvirds
yw5abQVz
o{/X:8
W1w'6Sx*
y;b_,{
6z}|s)5
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
]_%!>fK
1>e1[/
YFCW}$b
;:bT_v%;
P^@$pu
T+ly4+s9
26{v|T
?;ab?(
QzAs=u
c;[bi8
/E+}/(|Sy
<6cZx
%9nDWs
9[enrm
4\r&';5
7_y}/Z
arq/oh
`y(_wtia
xP?3y
UrtkPI\
=X8y1e
IJI 5$+%!
!He@fD
BEK8y@=
B,qO|B
d2d:d6d
6ET9@-
C;~+`{
@]B6FKP
'z%dc'+
Sb4hPrz
)x%#p7(!
A{xwu'
K.wH[kr
tgFRj;6
a-i.4V
YG=8~j
]]/(;
H+ebbZ
C#H{5S
IRt9MuUt
&Avn`O
)J%GVJ<#
roF=NJ
yr"|yr"y3
5Kh+wU
^3c7_Ci
RZFw8{u
7qF1\TlB|
`;X6X"
`Z`s0M
`X`r0L040
++3d^We
_-):0x
}0"r:Z
Svj[$S
'~9'~*Q
~9~*S
'~9'~*Q
_~9_~*R/
W~9W~*Qw
g~9g~*Rw
?~9?~*V/
W~9W~*Qw
g~9g~*Rw
?~9?~*V/
ig|)Rte
iG|)Pte
i?|)V(
qtoeRlh
IKOKKbV
86!:>2
,ldhll`
An~`yt
}uU]Wf
.-645^
t6^[]>=
QsbnQ6F
_\D2jo<r
3qu|y^
y3o<1x
8y4t<*r(
xqneSM
i:)].D
F:#GD(
p-<@%? -
_5/(GM
[ndtO{
*.-3#
9<vP{?
KqkNG,
)Ai)\n+
l9*aI\(
z=58#+u
-[nw-qXzR|8I
:aUL)=
Fm:hvX
]]]M/gS*O
$Sj`J:HF
9I]0z]
7HT]kT
8bwaAW
NGdL')<|
CELd_i
^XM."4
&cZ4%q{
HmUU m
~)U]DS
z,$_w(L
v:BLh+
$=x}kd6pn#Dq#
0o>.[^W
~)>8@^
Ls[&wZ
FckNMm
U4b/~N
~M{bT;
=Sux#F
H^~#d
PGjvOD
G=^b'`#
}-GIj9'L9
I29',)
i1C%+P
xr6f!X
iOz1hC
U!(+AR
4 3aJq
HRvHZ]
-wQ1`1
x$D0DC7~
`*cq10fTX
:z:;O
PGG3/%
e?WU5+
li]_fw
fBI{ZT
R5WLH+
QeauRX
NR]QUCKI
{eCwZjrQm
BJjzU~g}JX
|R2LD.r
ILLMJ~
A}m6I4
(&" &
otz8?5
IiaVy9&AI)6[
^pn6]l
eUM]C[9
iYK1)%-#+'/.
*,K*(]
xRz/|O
^miuQmz
3xn?o/1q=
YKVQWGVbFueI
pTWh02%
i~>y6v
*I"C%D
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
knaf 3S
Y 9 f"a
Icf b:
YfeffefefeefX
Yffeeffeefefhah
Xffefeeffeefhah
afeffeefefa
`ffeeffeefef_-
afeffeeffefea
Yfefefeffeef
;:feffeefeffe
ffeefefeffe
fefeffeefef
affeeffefe
9feffefefe
;:fefeffeef
feffeefef
fefeffefeef
Yfeffeefef
affeefeffeef
ffeeffefea(J
ffeefeffefeYa*
feffeefeffeY
u{ffefeefeffeXa*
ffeeffefeefY
ffeeffefea
ffefeeffefe(?
v4.0.30319
#Strings
ClassLibrary1
ClassLibrary1.dll
mscorlib
System
AppDomain
ArgumentOutOfRangeException
Boolean
Buffer
ConcurrentDictionary`2
System.Collections.Concurrent
IEnumerable`1
System.Collections.Generic
List`1
DebuggerHiddenAttribute
System.Diagnostics
StackFrame
StackTrace
Environment
IDisposable
CompressionMode
System.IO.Compression
GZipStream
EndOfStreamException
System.IO
MemoryStream
Stream
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
MemberInfo
MethodBase
MethodInfo
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeMethodHandle
RuntimeTypeHandle
String
Encoding
System.Text
StringBuilder
Monitor
System.Threading
Thread
UInt16
UInt32
UInt64
<Module>
StubStatusStrategy
ClassLibrary.Strategies
.cctor
value__
GetEnumerator
VerifyVisitor
PushVisitor
ReadVisitor
CountVisitor
ResolveVisitor
ChangeVisitor
NewVisitor
get_CurrentThread
get_ManagedThreadId
TryGetValue
GetExecutingAssembly
GetCallingAssembly
Append
ToString
GetManifestResourceStream
set_Position
get_Unicode
GetString
Intern
set_Item
get_Count
GetName
get_FullName
GetPublicKeyToken
ReadByte
BlockCopy
GetTypeFromHandle
get_Assembly
AddRange
get_Name
GetBytes
get_Item
GetFrame
GetMethod
get_DeclaringType
get_MetadataToken
GetType
InvokeMember
Concat
CreateInstance
GetMethods
Dispose
get_CurrentDomain
GetTypes
op_Equality
Invoke
get_Length
ToArray
Copyright
2021
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.0.0
$7c158b45-9dc4-4066-8cda-58e028d1a857
ClassLibrary
WrapNonExceptionThrows
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Coyxbbwm.ClassLibrary1.dll
InstantiateProccesor
Voonmw
Zvskyoku
Voonmw
Zvskyoku
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Adobe Self Extractor
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Self Extractor
FileVersion
10.0.0.1
InternalName
ConsoleApp10.exe
LegalCopyright
Copyright
2010 Adobe Systems Incorporated. All rights reserved.
LegalTrademarks
OriginalFilename
ConsoleApp10.exe
ProductName
Adobe Self Extractor
ProductVersion
10.0.0.1
Assembly Version
10.0.0.1
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.36980196
FireEye Generic.mg.d2470e33e04e12bd
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.MSIL.Noon.l!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057d2691 )
BitDefender Trojan.GenericKD.36980196
K7GW Trojan ( 0057d2691 )
Cybereason malicious.6a1a4c
Baidu Clean
Cyren W32/MSIL_Kryptik.EIC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABDT
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Kryptik.4412073a
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Seraph!8.111C6 (CLOUD)
Ad-Aware Trojan.GenericKD.36980196
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
GData MSIL.Trojan.BSE.XNY6ZA
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/GenericU
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34692.mm0@aOhw@tg
Qihoo-360 Clean
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.