Static | ZeroBOX

PE Compile Time

2105-05-13 17:04:13

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00029ef4 0x0002a000 7.87836383075
.rsrc 0x0002c000 0x000046c8 0x00004800 4.31956851434
.reloc 0x00032000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002c130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x00030158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003016c 0x00000370 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000304dc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
FmW&
rf FRSdY
C*#e 1
0dae I
{!e q
TfY e?I
v4.0.30319
#Strings
asd80.exe
<Module>
Facade
Xouncqmw.Shared
ValueType
System
mscorlib
ContainerConfigurationRule
Xouncqmw.Rules
Composer
Object
WorkerDescriptorResolver
Xouncqmw.Resolver
MerchantStructException
asd80.Exceptions
SchemaDef
Xouncqmw.Definitions
WatcherStrategyProperty
asd80.Properties
TestsSingletonPool
Xouncqmw.Pools
CollectionSingletonPool
Expression
MulticastDelegate
TemplateDatabaseRole
asd80.Roles
ComparatorTestsConsumer
Xouncqmw.Consumers
Repository
Thread
Database
Resources
Xouncqmw.Properties
Settings
ApplicationSettingsBase
System.Configuration
<Module>{62da6ed1-509c-459c-b2fe-0bb6ab1ae53c}
m_Tests
m_Collection
RegisterAuthentication
ExcludeAuthentication
LogoutAuthentication
spec_count
SetupAuthentication
ResetAuthentication
num_reference
MoveAuthentication
CreateAuthentication
Boolean
QueryAuthentication
m_Specification
singleton
PushAuthentication
ViewAuthentication
ComputeAuthentication
columnsetup
SelectAuthentication
RateAuthentication
no__init
TestAuthentication
ConcatAuthentication
DestroyAuthentication
SetAuthentication
InsertAuthentication
ConnectAuthentication
WriteAuthentication
CollectAuthentication
CloneAuthentication
RemoveAuthentication
CalcAuthentication
GetAuthentication
InstantiateAuthentication
VisitAuthentication
LoginAuthentication
ReadAuthentication
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
m_Configuration
String
_Descriptor
RevertAuthentication
FlushAuthentication
CompareAuthentication
FillAuthentication
InvokeAuthentication
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
PopAuthentication
Assembly
System.Reflection
ResolveEventArgs
MemoryStream
System.IO
Stream
CopyTo
ToArray
IDisposable
Dispose
GetManifestResourceStream
SetupBroadcaster
IncludeBroadcaster
WriteBroadcaster
GetExecutingAssembly
CalculateBroadcaster
CustomizeBroadcaster
reference
second
blogName
articleName
_Struct
VerifyBroadcaster
ForgotAuthentication
Interlocked
System.Threading
CompareExchange
Delegate
Combine
ValidateAuthentication
Remove
VerifyAuthentication
NewBroadcaster
InsertBroadcaster
_Iterator
DeleteBroadcaster
EnableAuthentication
CustomizeAuthentication
ClassLibrary1
ClassLibrary
GetValue
DisableAuthentication
FindAuthentication
visitor
Console
WriteLine
PopBroadcaster
MoveBroadcaster
_Adapter
RunBroadcaster
config
ManageAuthentication
RegisterBroadcaster
PublishBroadcaster
ValidateBroadcaster
CreateBroadcaster
_Order
ResourceManager
System.Resources
CultureInfo
System.Globalization
InvokeBroadcaster
get_ResourceManager
get_Assembly
get_Culture
set_Culture
get_Aaykdum
GetObject
get_Amzfnjaruhew
CloneBroadcaster
RuntimeTypeHandle
GetTypeFromHandle
QueryBroadcaster
PushBroadcaster
Culture
Aaykdum
Amzfnjaruhew
defaultInstance
CancelBroadcaster
get_Default
.cctor
SettingsBase
Synchronized
ConcatBroadcaster
DestroyBroadcaster
Default
m_ba98692465034ba291437d7fe291a139
m_d342b1e248ec4dc9988cb9e63631f38a
m_12640a5d81764753b7016e1b8ecdd4f8
m_a50bc43189974141b66ed1810500c8dc
m_d5bf010ba86b4ba6a98828601187c9ce
m_d6279429b2394f49b772d55d744d5527
m_78fd5363b92e46669e1da2bccb14570e
m_063d2bc305604a85929d674c339ac45a
m_acb8527a8b854471996e72ebce01a116
m_6fefbe8e72c14b27b04484b4dbcba95d
m_cac0fbc1cfd544aa9bc7a9c22a48734b
m_a7ae36919cc14d70b20d5397ba8cbe0a
m_01abe6fdcab34d6a8fb6e2ad7eb1342e
m_280555ed06f24948b3e6fd0dd93501a4
m_459b2769950e41a8881ad16a28ea525d
m_4e5d2998bd904ce08f2b8e88e667203e
m_59b7bc1021da44d8ac2b6b9ab9b36e1b
m_d89e81ddb7764a80a2dd8a298de3d2bd
m_8e0d87fe22ee43a29b9681463b6e5cb1
m_fe5a107fd83c4980bee60be2bef2d719
m_05ad34115f1b487499809ea483af0fb5
m_160e2a1119ec4a40b7d5b1fea6524d53
m_80b5747620bd4d86ba299a9934d1fe71
m_c5f791b7908749aaa08299544b3c9516
m_b8f90121e7c04a9d9968b411ac882492
m_f70f594df4d54647819bf152e051894c
m_4a5e89cbbd634bc294d031e4cbe0dc0b
m_59bf1e28c8cf499388e7ab358914cb6d
m_95208e5cc3b341f783379748115fff94
m_cbdcb9e639e04b59be01bafd4619862e
m_fd8e88fd7a93426daac0e01469752056
m_a0b7e02666514f408c73554af0e999ce
m_122fc35386974d0e84561705f5b7daac
m_97c374abdf834e4ea5d2a815a8070d36
m_c14e356120cd4911bc27ea9937e28381
m_fd770d3d3be54eb3878001a6f5b8cd93
m_4626e2f66e2041c0bd329a0843db5023
m_ba79e3896c3d430ba63315b903b27417
m_4d99d5c648014e31947b5e8f0a1815d2
m_6cbff76bc26043bca96e3dd30bb28bb0
m_5ef12448cee84369a6075fa0c8fdb638
m_523e46746c134fdeb3dcece490cdc068
m_b3e77f5b8e8c47298193b278755eedb1
m_eb002ccc4ee441e88656244b43203cf5
m_e775ee8e86884d81b898d3bc8e8c7f18
m_89f9cf82089040ce8855d9356d538bce
m_3dafeaf5c643409abb33fa2fc0ccb252
m_95d08a9029914939a003eb46817a5e14
m_abb283b91f7e4e4f99957c71e0acea50
m_dc40a520da614a0fbb2da4cfb9679705
m_41940d54d9824e20ac07e27be0cf09b8
m_b9767185008d4ccfaa4ab3681cf74fed
m_37144f28958d4cd7af7de8a00c86b3a7
m_edbc61473f5e4c9b84d2ea787c222d13
m_c2c9b8b2af6f4c17bd2c232e984bfefa
m_d5541e88823a4fffa50971c2aec5730f
m_895b02c23b964133934c1023b3006106
m_073d4e0fe27c42cabaac997878aebf68
m_5012ec1e70d94bb08c66d7d633e56f9a
m_170d5029fd844fd58d0e5826f5cf38dd
m_5d544b11eed74fa18545be47e4e1bb91
m_0ccfc2d57c6242f692ebd03b8325c9a8
m_c1f91ec9cc6244eaac956cb8de2b2010
m_caf0cdfdaf5e426f81be55c7bdd0c78a
m_ee79528df4d544c0893d9b8faadd2468
m_f6f76ba8b3464282a62ed3ec0bf4dfd1
m_58c6221b810a4ac997efccc1868785a2
m_5d4c429b68724b9e8228b4dc01e51d12
m_3fac33694ba5472db0799d63b90b7046
m_c6cd48017975428c8ea3dc06fcf2ff09
m_dcb5f96a570e41edb14fc4a6aade0a4b
m_94d6f88c551e41d480b524afa053627f
m_3f4a85cd382e405bbf89bdf028c12d3e
m_a16c465e436445258f7ff3bbc3dd2ac4
m_9d41caf98f1f4744b1117d9886094a89
m_713a9efd05f043ceb2bd6d6ea98e13a0
m_177b8c3884654927867b70a1120acab7
m_e33dcd587e8d4cc78939c450a21ea4d8
m_4da3ac0ce3ef4f61a099d748801c01c4
m_7923832b859f4959b44d1bb4c44bf454
m_e67902a55c184a6ab3d6f9a6fd03883f
m_789321ba69914fa0a948e5c4d92f34cf
m_3a31b21ad66b4438a05006e36891ab3f
m_a151c4554cb540be80209358246493e9
m_458599d3b7464b5cb393c271c2c357f5
m_ff69d5099f2a46d5baf00c8663851305
m_ac4c1aab1f774df9a2f1a1e8bc2fde42
m_1535f114ae2f418386630ad44ca93238
m_53fdd4cccbc44297bcaa92f133ba81a3
m_df4d59ae24eb489d8a727b886a728881
m_b1d914a1dfd44b5682223e5871941b15
m_8fa15904a73a422d91ff1c4774ddf9b8
m_9e286120a59a40ed961863ad6e05be17
m_7ccfee7f7dc4449f89c2bcaafc3ec926
m_50bb0aeeddd94dbd98f6176774745258
m_aba0bf106ed84fa99fe8a6e929711a0c
m_b7f58dc6b9374abcb2b225e6c59ad7fb
m_cabc52b3a2f04e5786bb7a424989116c
m_98373a4c52844bf1a5202ce73829fadd
m_12397743d84845eca74eb0ef13899c41
m_aa43509906a1421e8d3f36f7b0e96821
m_7d5bf49bb5284868a44cf383c6e3cf7f
m_d9098dd2c3c74bb3aad58056e2546745
m_492938c56f01409e89ba270b7b186579
m_68f4084706e443488e4f1172b7ddb0ad
m_aa96d6da1ae44e6ba7f3e3aaa44e609f
m_7625915dbba04edcbfbc81defbfb1e54
m_b7252723558a4b1d9127fe1b05b4693c
m_0e2d9a5cb16b4eaba1a32fff08daee4e
m_4f7c6176c89a42849a1d72c1d72cdef4
VisitBroadcaster
ja22fc6c627fd4d2bb5cc418caa1ead10
CheckBroadcaster
ComputeBroadcaster
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
CompilerGeneratedAttribute
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
Xouncqmw.Properties.Resources.resources
Xouncqmw.ClassLibrary1.dll
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
Skype Setup
Skype Technologies S.A.
(c) 2021 Skype and/or Microsoft
$2f76e12e-6bfd-4483-849f-e284df7fe94c
8.68.0.96
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
9txB29z
X<&mr*z'
6b}@u%
lv*$h9
d[az%"`
Z> 3Nf
CYgNc1
6C7%i3m
WM#tT=
H!,.1=.
od\%jS
!0dHt0
s~&HI7
b-hSh|r
Urj)XbX
,knC:H
]qb{tW,d
BpTLFh
'xHsd6Q
.6F/NQl
9ab0'"e
x"!7@{
b+j&aL
{ax?`K
RK`3-O
REB|HbJ=Q
3.jdBt
'N,~~o
./}gV|
zWPf?F
t\aZG{
sCoy?.=
*[~1+T
3+w^j
M6<_;)
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
UDZQJT
?mypF#<JRV
iXnZBT
mGN~^ty[
TjSu)8
(O-zi2Ph<
oQ7U_{3x
,t;$W|K
Er#??Q
8z1=o7YoB
QK==2&
nn}<IY
'qI+wD
<U+I'U
(Y5KrL^
z:#pzg
=_Ar_D
%RRjaw
r*}%OBv
F)?fe+
e$bPfF
bfA2!v
2h^:d$hFx
8`D6dU
pmB44@h
:$;?(0
lC*IH%
"120us
7&t_2v
L`&Cb
b[ec?A
9B,BW:o6
ANf"p@
U(L8_L
8&452
wxF|N9
]]/(;
H+ebbZ
C#H{5S
IRt9MuUt
&Avn`O
)J%GVJ<#
roF=NJ
yr"|yr"y3
5Kh+wU
^3c7_Ci
RZFw8{u
7qF1\TlB|
`;X6X"
`Z`s0M
`X`r0L040
++3d^We
_-):0x
}0"r:Z
Svj[$S
'~9'~*Q
~9~*S
'~9'~*Q
_~9_~*R/
W~9W~*Qw
g~9g~*Rw
?~9?~*V/
W~9W~*Qw
g~9g~*Rw
?~9?~*V/
ig|)Rte
iG|)Pte
i?|)V(
qtoeRlh
IKOKKbV
86!:>2
,ldhll`
An~`yt
}uU]Wf
.-645^
t6^[]>=
QsbnQ6F
_\D2jo<r
3qu|y^
y3o<1x
8y4t<*r(
xqneSM
i:)].D
F:#GD(
p-<@%? -
_5/(GM
[ndtO{
*.-3#
9<vP{?
KqkNG,
)Ai)\n+
l9*aI\(
z=58#+u
-[nw-qXzR|8I
:aUL)=
Fm:hvX
]]]M/gS*O
$Sj`J:HF
9I]0z]
7HT]kT
8bwaAW
NGdL')<|
CELd_i
^XM."4
&cZ4%q{
HmUU m
~)U]DS
z,$_w(L
v:BLh+
$=x}kd6pn#Dq#
0o>.[^W
~)>8@^
Ls[&wZ
FckNMm
U4b/~N
~M{bT;
=Sux#F
H^~#d
PGjvOD
G=^b'`#
}-GIj9'L9
I29',)
i1C%+P
xr6f!X
iOz1hC
U!(+AR
4 3aJq
HRvHZ]
-wQ1`1
x$D0DC7~
`*cq10fTX
:z:;O
PGG3/%
e?WU5+
li]_fw
fBI{ZT
R5WLH+
QeauRX
NR]QUCKI
{eCwZjrQm
BJjzU~g}JX
|R2LD.r
ILLMJ~
A}m6I4
(&" &
otz8?5
IiaVy9&AI)6[
^pn6]l
eUM]C[9
iYK1)%-#+'/.
*,K*(]
xRz/|O
^miuQmz
3xn?o/1q=
YKVQWGVbFueI
pTWh02%
i~>y6v
*I"C%D
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ClassLibrary1
ClassLibrary1.dll
mscorlib
System
Boolean
Environment
IDisposable
CompressionMode
System.IO.Compression
GZipStream
MemoryStream
System.IO
Stream
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MethodBase
MethodInfo
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
String
Thread
System.Threading
<Module>
ClassLibrary
GetValue
buffer1
buffer2
GetExportedTypes
GetMethod
get_FullName
CreateInstance
Invoke
get_Length
ToArray
Dispose
$7c158b45-9dc4-4066-8cda-58e028d1a857
Copyright
2021
ClassLibrary
1.0.0.0
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Dot Net For All
Reader1
Reader2
Xouncqmw.ClassLibrary1.dll
AssetFilter
{0} is read by {1} in the blog {2}
Events in .NET
Xouncqmw.Properties.Resources
Aaykdum
Amzfnjaruhew
Aaykdum
Amzfnjaruhew
`.#k.+
.3`.;`.C`.K
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Skype Setup
CompanyName
Skype Technologies S.A.
FileDescription
Skype Setup
FileVersion
8.68.0.96
InternalName
asd80.exe
LegalCopyright
(c) 2021 Skype and/or Microsoft
LegalTrademarks
OriginalFilename
asd80.exe
ProductName
ProductVersion
8.68.0.96
Assembly Version
8.68.0.96
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.b7c53f778e82c159
CAT-QuickHeal Clean
McAfee Artemis!B7C53F778E82
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34692.lm0@aaGfqyn
Cyren W32/MSIL_Kryptik.EIC.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/GenKryptik.FGBB
Zoner Clean
TrendMicro-HouseCall Clean
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData MSIL.Trojan.BSE.XNY6ZA
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Inject
eGambit Clean
Fortinet Clean
Webroot Clean
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.