Static | ZeroBOX

PE Compile Time

2082-10-13 02:01:00

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000286f4 0x00028800 7.95915015821
.rsrc 0x0002c000 0x0005ae44 0x0005b000 2.40525347614
.reloc 0x00088000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000862e8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00086750 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000867ac 0x000004aa LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00086c58 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
gnkF 6
KyXe xe
*je Yt
Kp:a -Z;
@b<Xf Y
*je #E
gnkF 6
ee X%l
"ff PB
@b<Xf
ce DjV
a ^{,@a
v4.0.30319
#Strings
Invoice~details012
Invoice~details012.exe
<Module>
BaseMethodSpec
Invoicedetails012.Specifications
ValueType
System
mscorlib
Global
Invoicedetails012.Serialization
Object
FilterDescriptorMap
Invoicedetails012.Maps
PropertyStub
Staqwli2.Stubs
TokenizerMerchantAuth
Invoicedetails012.Authentication
Customer
Invoicedetails012.Lists
ErrorResolverRole
Invoicedetails012.Roles
Merchant
Staqwli2.Writers
EventArgs
TagParameterDeSerializer
ServiceGlobalWriter
Descriptor
Staqwli2.Exceptions
AssemblyLoader
Costura
WrapperMerchantException
<Module>{e61647a4-4d14-435c-8fa7-d280eac544ab}
.cctor
_Printer
_Wrapper
RatePrinter
SetPrinter
idx_param
ViewPrinter
ReflectPrinter
instance_Low
CreatePrinter
PostPrinter
AwakePrinter
QueryPrinter
InstantiatePrinter
IncludePrinter
InvokePrinter
CallPrinter
MapPrinter
ResolvePrinter
_Rules
Decimal
second
ToString
String
Format
EventHandler`1
ComputePrinter
ConnectPrinter
op_Equality
Boolean
StopPrinter
Delegate
Combine
Interlocked
System.Threading
CompareExchange
UpdatePrinter
config
Remove
ClonePrinter
Invoke
OrderPrinter
Thread
IntPtr
ConcatPrinter
ClassLibrary
Isetfdvcfv
Console
WriteLine
VerifyPrinter
nullCacheLock
nullCache
Dictionary`2
System.Collections.Generic
assemblyNames
symbolNames
isAttached
CultureToString
CultureInfo
System.Globalization
culture
get_Name
ReadExistingAssembly
Assembly
System.Reflection
AssemblyName
AppDomain
get_CurrentDomain
GetAssemblies
GetName
Equals
StringComparison
get_CultureInfo
CopyTo
Stream
System.IO
source
destination
LoadStream
fullName
DeflateStream
System.IO.Compression
MemoryStream
GetExecutingAssembly
EndsWith
GetManifestResourceStream
CompressionMode
set_Position
IDisposable
Dispose
resourceNames
TryGetValue
ReadStream
stream
get_Length
ReadFromEmbeddedResources
requestedAssemblyName
ToLowerInvariant
IsNullOrEmpty
Concat
ResolveAssembly
sender
ResolveEventArgs
Monitor
ContainsKey
op_Inequality
set_Item
get_Flags
AssemblyNameFlags
Attach
Exchange
ResolveEventHandler
add_AssemblyResolve
m_66facb9171f847fab5b08d2efa9cbaa0
m_4e30a7fcc1234411b8232b17ae83b177
m_13350790d2504342a63a8eeb8cd84d28
m_1147d5f301a94733a3965ef878f1c6d1
m_91846655e7d44c5b9e75be7fc1a93626
m_94e66c1971714786b54ba98eb1fd26c7
m_b37acaf69e2a46f5b3e95e0995fb276f
m_9f62419d14634ecb9175002344c20b29
m_b469b22f64fb434daee0aab88d4f6cdc
m_f89dbe253d434735b2cd143a4eea7608
m_e7685081ecb0454da254b578fe8842ab
m_9860112c90204b15a0592ef6bd8c6218
m_490883004b9c4561875840f275cb9ade
m_ab9f7d95f477474c91b5fecdd527f2a8
m_0b37e9580d09472c9bb150f4f36d8219
m_5be722be239c4bc39adb202f61985dd2
m_9e46204a83eb4013be6115580e45b656
m_b1d7ef4b5f8c40c88ab1391fb10db929
m_970fb02d5e11496d950f09b977ab740d
m_31e1ccd8283447a09096d128e37bbde6
m_89e277625b984ad6a83d13b97d1bdeff
m_8fa71d40f2484f5bb0e349182c8492e2
m_7cbb6ed4e4dd4483b59ffe932b0c33fc
m_298305f5e82f47b68557492606c7d946
m_dccadd74ece64e728e2a870d5005650d
m_279353d1ad4444bb945482c10e6cf90e
m_3b8664a226ad44e7b088f8b96dc65e88
m_6ae40a9053c94fa1b095aeda90878c76
m_837a3e4c83bf42c8bad471ecdb644856
m_2e0ed0ccb49e4617bebf4be2958ae03a
m_52bd8c5234be44a58a715c1d12471182
m_65445a9aa1fc4cca8173db222d91c885
m_0f5136cda1f3400d984bb176680ecae9
m_3472148e1ca347bbbe7aa15b0cbd0d34
m_c45e32b94a22480885424c8c02718d2d
m_6c5ad5c6c5c74362893a56eecfcfd9a8
m_21f8ecaaef4943b09419df52a8fab593
m_ff0b92fed82349ae9133b8dd4c5b5495
m_380b656c09eb49098f2efb3409b24d7a
m_2574c86276024cce9c3860ab9e4fdfc4
m_381134a59e004270984496c83b41181d
m_ca6b2eade7e245b7a55b7853a9b6c1c5
m_b482ec561f9948a081409ffb402add61
m_c74baf2569a1498a9216fae8f72ee9bd
m_34d7e68ca76848f88ac3d491162c3b74
m_6246428fb0094ef1bb08d20c324930d1
m_d2a6e06187944ae99bec62a986888ffd
m_612b52ea7391433587473f2e3c7ed5e5
m_232c4eb1abea4749849ce8c051d740d2
m_ac3ff14e50dd4023ac90386f183a1228
m_d0e0788945d74bb2a66e88b0623c91c6
m_f1eba8f0d82e4258b40049b8907b744c
m_65b81c75809c45139c76aa7f29d24fd2
m_9b5feb9354d74ce39117d4a5b31dcfa4
m_cb133bf1081e41aaa0c1f8acf539fba5
m_aca1414ea415455d88f08d3f1b26ca5c
m_565c91d714864760b6c9ed49fc224b25
m_9d39bf7f7db946b8a03b8ac12be7fbf5
m_ff77e2e396574c0a8049795ca5e616b2
m_b6129eb154dd44fca9fed7e2d0080ebf
m_1836d6f04de241ec8793e33a8930bb6c
m_f110f6cf56c5434dbf71d5ac2333c670
m_31442c8dd2d6475d90642c529a92d94d
m_3f776a529be8407882daaa0bd5977c35
m_f707a7aa45f44035a6a0db2c01954eba
m_f4b2cd23a8e84aa09653a763cb6c54fb
m_71befa5750464a46b7da2797deff2fad
m_81682d32dd354088be295cc4d801e7a9
m_febbfdfe0b4d458dae6d6e39a8334ba3
m_da4d3c94df82442bba802902bd865107
m_7267803987e44fcbb09012870ab35e54
m_c865c773e40c440c8df020960dfad437
m_b40581a5d61c4af8bb2fa1570c4d9ef0
m_76aff83d521240dc8ef6ecacde7631a7
m_5b18bbcd0bf942ff96426dc4fa07aca7
m_ea8a142a70884f038b4c471c5ccf616a
m_36e4fd80a9a949f78e9ff79193d26bd9
m_01452637d9fd44538973049510b3111f
m_639f52903cc740c3aafbb9dfa12b5540
m_555af2b5c3d041009a4279b6245dd830
m_3f3e1900bcb942b2ac214860c5f83065
m_53d5021c380b43a78f97cfad2f369572
m_579e6001ab1b4f7687aa8684d491ef7b
m_5b27b6d55d5d4d48a4ada2362db408ff
m_74d05b53579b47b4b6d83b79115b4846
m_b9c5e0d8719441eca1164696ef9e71f5
m_b15f58691dc54b07b5eaf6a7d32faaba
m_21e6462c9ac44f6eb514dc5650fd891a
m_018374f7b44547ee9a2927c89c4d52af
m_a22e8f581d6942dd90e39b6eb4ddeb6d
m_4911377b6fe442e7b70c91affd64f9fa
m_76768c8041dd4d0cb1277c52c49870c1
m_f049e3eccec84750af10bb463f84f855
m_4166f502e5834389bdeda2fe56a3bb83
m_2867eff4998647e69fd9fc9b026acc53
m_4a10abf452d44a87b4026873426eda9b
m_8649b108055a4d77a1623ff889192f38
m_2070796867434303ad1b276c21af2c69
m_8fd223d12ec449e5ac4fdf014216fff3
m_0e319bdba08a478aade1ecdfddf6a237
m_52ab8912fe1d49498174402d7a09b3b1
m_57acb45e097d4b36b9ac06e50558ba4c
m_b025ac2d774846aead7fcb316d063700
m_01dbe283fcb2480aaf5033776d0c7502
m_b45a6344c7154cb9b0a1ef08a2993c9b
m_eb5def15d3624c1eac3df5e81d50c8f7
m_e50e45be2f454113bd1db9e4fc7908f6
m_97c1053fde6e4b7f898582eefab0aec9
m_694ddd5c823748e5839a82166df7ee4e
m_c9eb70b3000b46a482c9bddf71aaf0e3
m_319e23b64cdd45b7985061d0079c0bed
m_c70de7fc3a75414481d7f54d03d90468
m_d46421518d924c83ac7e2b16866c2863
m_e2b2d643267d4bceb82067ed43978d36
m_10e85122792942738817bc532384eb0e
m_2245ee628c8441e8a504aafd13b79a3b
m_e95f745db964440dbc910475a29b68bd
m_a91fae2e4a39469f8163cb95e4b6d229
m_be7b2d38e8814bf2abd524993473a1fb
m_008219453ef14ff687cc490a63eb00c4
i66ed650f075145aca68c5565b9aad057
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
costura.costura.dll.compressed
costura.isetfdvcfv.dll.compressed
WrapNonExceptionThrows
Adobe Acrobat Reader DC
Adobe Systems Incorporated
Adobe Acrobat Reader DC
VCopyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
$45fb8bcf-a9f2-401f-bf37-d0be6c0574d6
21.1.20155.39962
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
z`W+63,
.6\^xr
7~wX_M
)3BF6e
jY4ha{U[-
.$qir,
??ztel
"5N>>b">m
}r)9vo
}B!:)z
mLB&DT
]#c!+F
1j)G r{
,9W9%l
_i\<)M
ML"bEhI\
7N*%Ra<>50
yBAGDG
s|X"ds
@K8<>,!I
)b1Elpf
yp_B@gq
_xb._B@
A|.De1\
x<T3@N
StBD2Y(
I Kx*`C!
FIhI01
%92ZLJU
X29IJD;
D250n6
Wy_'X
A~Cns/
^My!w)
w>|-oo;H
yL*!2#
Z9ssVl
d{rMikO\
=oSg^v
9}MtKE
F}0}km
D8E9Lu
&C;[s-
JFKnld
e^Y.kL
wZo2Gw
gOZ~8*
i3-]8DC)`R
VpE)<z
'u}QcI
{C96OFy
x|7_/,Um
eVaC;-|
X"#9RN
G[x6!l
@bKJN4
sPhnC8
{hR(o=
&T1Cy9
?!vLT]Ap
}G.)wzn]
oWB|I;
e+Z;/\
GUGN3
D^,:onU
5-%'n
KVWRWG
/5[?'c
nkR9ft
-V_N[1jO
-xwA85
P*wOf:{
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
Sj.Rf_
CmwqJ~
;~Xmwf
l|x$}u
]V6wCo
Q74xoJ
uN}uoo
-LHx_T
[Ys.J
g-_|02vUH
z,S<w|
,W%%Ew
khG5|4
8'c[_D|^
r.l47I
e+X.a9
%ax>cV
:$&$WH
m,>=]k
`O sF_>
ADa4&8
q8[MP/Hf
dDS+91
8Zj1Z,
h+A)/
X2:J$R
/o14]*
0i!&p
([&_rB
"HQ^b!
@g1aj(
z Z,<5
27L0*~
4rPYg.y
C)imA|J
=~6gu#
?y^e,?{
Z5}VcS
';{vo=
ffi1J6
+x;"h^
Yzg9^9mw
fG!N&x
$O4', g
bQHV5c
hNT"&$/
b%='LJa0Q
|8rtnL
6!R<<i
=2sH6y
|BP:/`
-V)@&P $
m`2`U(
oSlfb`
:%PjX>
agVRh3
Xt`xZ4~
R+fU}a
XF\FU
eN&u`N
&p>N"c
N0F]%4
'$\3qA}
{:F0z^,
)BX;<@
{?=<1RS
Q,J4J2HbK4x(
#DuPRE(
Ii8ZQR,
*_V]yq
pf ]0<
@Ph`fE
?~Y)u!
`8qcp.^
`)2E/D
cCbsDm
`G..[T
|U=hZT
jj]0c
JFRAVjARJVjY
MqMALb
M]]~UuE]{
#;LcsR
i ybi
bi 9bi T
b7jX1s
+[8;m*`;
:'mt9!
`~|}VM
z2=O.m6v
[S3`{h
P$Vkc
ZEHGZi
^Dl\oW
=Z#'uhJe
[\RoD
V?6im-c
=%=9%9#94.p
7/.)nhV
xhhor(
J=;w^
59J>Ry
RC87oL
5\)wFe
}Lz%H*T
`[P/fH
$9esO m+z
~=qA>
5#jMl-
5+(sM55+Q=e
!nyC]tU
>+T@Fn
!Y*`rGx
hx(8xU
XT%aAsXT
,*)a~tfm@fV_
CY~]VT
a~hfp`6
yNP:{r
eH%{~w
,\4Gw
<Eu}`g
DF}[hx Vc
Jr"R|9
8{0,hf
76z9lV
RJ8%Qxj
ux"n7m
b{^*Hv
4~2Em|
QGbCHf
)*f3d7~
Bi'Nck
pn#Hr^
?>"Cbj
nq&|G8
%lAl3W
i1OCU|`
QhSn&-
kfUc$5
qWQT7SE
\66L0D
hMsV'
f8*FcW
sv ]G]cT
LpB`s,
vhAW9
PDk33L
(0Kz#M
@Q@m<&
%g~N52
fQ;FKy
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Price is changed: Last {0}, New {1}
.compressed
costura
costura.costura.dll.compressed
isetfdvcfv
costura.isetfdvcfv.dll.compressed
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Adobe Acrobat Reader DC
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Acrobat Reader DC
FileVersion
21.1.20155.39962
InternalName
Invoice~details012.exe
LegalCopyright
Copyright 1984-2021 Adobe Systems Incorporated and its licensors. All rights reserved.
LegalTrademarks
OriginalFilename
Invoice~details012.exe
ProductName
Adobe Acrobat Reader DC
ProductVersion
21.1.20155.39962
Assembly Version
21.1.20155.39962
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.6cad5773b9830105
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.Gm0@aCQRvyd
Cyren W32/MSIL_Kryptik.DYY.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/GenKryptik.FGFW
Baidu Clean
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Clean
Kaspersky UDS:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Trojan:MSIL/GenKryptik.b37e375c
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.ht
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Inject
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/AgentTesla!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXOU-CP!6CAD5773B983
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:Trojan-gen
Cybereason malicious.60b74a
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.