Static | ZeroBOX

PE Compile Time

2021-05-31 21:20:58

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002679f 0x00026800 7.91986666847
.rsrc 0x0002a000 0x000046b4 0x00004800 1.69894681331
.reloc 0x00030000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002a06c 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0002e0d0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002e120 0x0000036e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002e4ca 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
,>&+>+?+Dr?
-.&+.+/+0t
-.&+.+/+0t
v4.0.30319
#Strings
ConsoleApp1.exe
ConsoleApp1
<Module>
mscorlib
ValueType
System
Object
MulticastDelegate
Settings
Qoouqwctcdctzr.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
ResourceManager
System.Resources
CultureInfo
System.Globalization
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
Assembly
System.Reflection
ResolveEventArgs
blogName
articleName
.cctor
BlogSubscribeEvent
BlogName
BlogSubscribtionService
ReaderName
Culture
Ttntkyuefu
Qxcdjvcwg
Default
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Qoouqwctcdctzr.ClassLibrary1.dll
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
MemoryStream
System.IO
ToArray
Stream
CopyTo
IDisposable
Dispose
GetExecutingAssembly
GetManifestResourceStream
Interlocked
System.Threading
CompareExchange
Delegate
Combine
Remove
ClassLibrary1
ClassLibrary
GetValue
Console
WriteLine
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
GetObject
SettingsBase
Synchronized
WrapNonExceptionThrows
FileZilla FTP Client
Tim Kosse
FileZilla
$0ce3912c-612b-433b-84cb-94cf667d5f63
3.48.1.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 7.5.2.4508
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
[J)-**
:<y6p/
6uEODq"
B{J#kZ
0{A#)X
zclQ>
]7I#ud
RTC\o6d
U&*Ljo2
8![$$6
uTy(]V
Mb_Xsg
En=q0:
{"|S'J
*py(N
Y:nPf~
Y\k8a=1k
,PVDhc
N}y\;j
%}.RA;
03vjT' j&
kl|QBm
C*oquv(
nuN+q5N
W#|3LM
'Wo,sx
33ZS8Q
]\06Dk
s Z;pD
C?zxon
X{E3E%
W|[YvT
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
5[2wG`
4)8c^l|
R'[uxn
-nYnpo^
)ON=}7
bq`]s?
T[{+=3`
Fu}X:"(pC0
;nD'ul
=3v3mS
<Wx]vf
;}Yq7I
ms02^tb
qlRb>J
0`h k@
APFp6k
T.r%zgI].
+X.ar%+%
41H5>O
4S5IS5]S
*F.bAl
fAU>F*
pbUW/iX
E+U]E2
4A-;<N.
EVxk'-V'/$g
wh@qH%g7
&bQ,dU#C
-,,:Z(
+W=j(8
1<X9ZlS
JRU-=8
IHhSg/
g.Ws7[
H]AD/o
y/k\QP
p;!=)Y$o
`j0|0U
~2)_$N{01
8Dtm|T w
[}Fv8A
xg91C|
&E*v.HX<
>qy*2&
G~9G~*Pw
G~9G~*Pw
_~9_~*W
o~9o~*W
_~9_~*W
o~9o~*W
iKC29e'
}1~^F[,
3R.Q'_
ylB%jH
:7GZ7=Z
mL|M]O
c5te=
iR([ww
ckU/*O
n8]p1
\<{,]xH
x_P+~h
uV>bM
x3E+>?]
o?;&>&
~3U-`/\
8}roD):
RN=a|H
A5voZ+gymKe
I0G4 (
_vF4',b
nocw ly
F$f#1M9
zEU;<c
-qhzbl8I
z9&"7w
&.M,]H
]7\^T]
1|xJ"Y
6H5g~"
;2fXVf
$=x}kd6pn#Dq
4<Qr"5
u3t?Dv
~=mp 3*
Bs0{es&
xd#^a|N0
Qt[+3(
I29&,;
jLxv?g
#hm(C_G
O#J%!X
7S,Y@r
KBJI Y
HRzHZm
&(a1R{
tAye~1i
!,LL\~L
=m1j\`
UgbagL
2&p\^ZS
=#.(s:
iQIC4=u
mMILvB
wYYS0Z
:~>HJ/
ESO[C^LD_
12ozsV
USSSWT
>=6_?W
Yw}~Mb
5:"<=")r
"<"!>:x=
tXXWSHC
k?.-)O
a:>12(
~&/]%
5cQm[II
NQzzB~|
>qPT8~
cxSO[og
oss}SOA
*3:"!#(
clXo7y-
AmUinB
IqvVIN
\rnXZYE
KS}C{[@
xjZ*FP
6)%2}W
;f)I!IQt
1G9&ai
K>+#$).++'-
rR|rsSL
%>1<5""{
WYGKAP
UMaU^x
OWZDZUcA@
bbbebe
!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ClassLibrary1
ClassLibrary1.dll
mscorlib
System
Boolean
Environment
IDisposable
CompressionMode
System.IO.Compression
GZipStream
MemoryStream
System.IO
Stream
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MethodBase
MethodInfo
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
String
Thread
System.Threading
<Module>
ClassLibrary
GetValue
buffer1
buffer2
GetExportedTypes
GetMethod
get_FullName
CreateInstance
Invoke
get_Length
ToArray
Dispose
$7c158b45-9dc4-4066-8cda-58e028d1a857
Copyright
2021
ClassLibrary
1.0.0.0
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorDllMain
mscoree.dll
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Qtra]PI
GlobalSign nv-sa1
Root CA1
GlobalSign Root CA0
110413100000Z
280128120000Z0R1
GlobalSign nv-sa1(0&
GlobalSign Timestamping CA - G20
&https://www.globalsign.com/repository/03
"http://crl.globalsign.net/root.crl0
GlobalSign nv-sa1(0&
GlobalSign Timestamping CA - G20
160524000000Z
270624000000Z0`1
GMO GlobalSign Pte Ltd100.
'GlobalSign TSA for MS Authenticode - G20
1R(n]@r<
&https://www.globalsign.com/repository/0
1http://crl.globalsign.com/gs/gstimestampingg2.crl0T
8http://secure.globalsign.com/cacert/gstimestampingg2.crt0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
160615000000Z
240615000000Z0n1
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G30
QAY3yd
,X,*o5-
"http://ocsp2.globalsign.com/rootr306
%http://crl.globalsign.com/root-r3.crl0b
&https://www.globalsign.com/repository/0
J1 ~O]
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G30
180201225327Z
201013150902Z0
Private Organization1
03-05049501
Florida1
Florida1
Sanford1
1573 Katie Cv1!0
QFX Software Corporation1!0
QFX Software Corporation1&0$
qfxsoft@qfxsoftware.com0
Bhttp://secure.globalsign.com/cacert/gsextendcodesignsha2g3ocsp.crt0>
2http://ocsp2.globalsign.com/gsextendcodesignsha2g30U
&https://www.globalsign.com/repository/0
4http://crl.globalsign.com/gsextendcodesignsha2g3.crl0"
qfxsoft@qfxsoftware.com0
,X,*o5-
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G3
GlobalSign nv-sa1(0&
GlobalSign Timestamping CA - G2
200805000853Z0#
GlobalSign nv-sa1(0&
GlobalSign Timestamping CA - G2
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
160615000000Z
240615000000Z0n1
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G30
QAY3yd
,X,*o5-
"http://ocsp2.globalsign.com/rootr306
%http://crl.globalsign.com/root-r3.crl0b
&https://www.globalsign.com/repository/0
J1 ~O]
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G30
180201225327Z
201013150902Z0
Private Organization1
03-05049501
Florida1
Florida1
Sanford1
1573 Katie Cv1!0
QFX Software Corporation1!0
QFX Software Corporation1&0$
qfxsoft@qfxsoftware.com0
Bhttp://secure.globalsign.com/cacert/gsextendcodesignsha2g3ocsp.crt0>
2http://ocsp2.globalsign.com/gsextendcodesignsha2g30U
&https://www.globalsign.com/repository/0
4http://crl.globalsign.com/gsextendcodesignsha2g3.crl0"
qfxsoft@qfxsoftware.com0
,X,*o5-
GlobalSign nv-sa1D0B
;GlobalSign Extended Validation CodeSigning CA - SHA256 - G3
20200805000859Z
-0+1)0'
GlobalSign TSA for Advanced - G2
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA256 - G20
180219000000Z
290318100000Z0+1)0'
GlobalSign TSA for Advanced - G20
&https://www.globalsign.com/repository/0
5http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0
<http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0<
0http://ocsp2.globalsign.com/gstimestampingsha2g20
<W"=0
GlobalSign Root CA - R31
GlobalSign1
GlobalSign0
110802100000Z
290329100000Z0[1
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA256 - G20
x"6kwy
&https://www.globalsign.com/repository/06
%http://crl.globalsign.net/root-r3.crl0
=dj;^NF
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA256 - G2
200805000859Z0/
ahBPD5?M
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA256 - G2
Events in .NET
Dot Net For All
Reader1
Reader2
Qoouqwctcdctzr.ClassLibrary1.dll
CheckInfo
{0} is read by {1} in the blog {2}
Ttntkyuefu
Qxcdjvcwg
Ttntkyuefu
Qxcdjvcwg
`.#k.+
.3`.;`.C`.K
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ClassLibrary
FileVersion
1.0.0.0
InternalName
ClassLibrary1.dll
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ClassLibrary1.dll
ProductName
ClassLibrary
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FileZilla FTP Client
CompanyName
Tim Kosse
FileDescription
FileZilla FTP Client
FileVersion
3.48.1.0
InternalName
ConsoleApp1.exe
LegalCopyright
Tim Kosse
LegalTrademarks
OriginalFilename
ConsoleApp1.exe
ProductName
FileZilla
ProductVersion
3.48.1.0
Assembly Version
3.48.1.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.b9e9adf06ee8e96d
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee RDN/Generic.rp
Cylance Unsafe
Zillya Clean
AegisLab Trojan.MSIL.Seraph.a!c
Sangfor Trojan.MSIL.Seraph.gen
K7AntiVirus Clean
BitDefender Clean
K7GW Trojan ( 0057d5821 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABEZ
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo TrojWare.Win32.UMal.xerpr@0
F-Secure Clean
DrWeb Trojan.PackedNET.783
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
SentinelOne Clean
GData MSIL.Trojan.BSE.XNY6ZA
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=70)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34692.lm2@ai6dzNo
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.F0D1C00EV21
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.ABEZ!tr
AVG FileRepMalware
Cybereason malicious.14cb8f
Paloalto generic.ml
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.