Static | ZeroBOX

PE Compile Time

2021-05-29 13:10:08

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000137a4 0x00013800 7.84154156981
.rsrc 0x00016000 0x00002e2c 0x00003000 6.34158737794
.reloc 0x0001a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016130 0x00002868 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 10240, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00018998 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000189ac 0x000002cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00018c78 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
ffefeefeffe
ffeeffeefef
fefeffeef
`fefefeffe
affeeffefeef
9feffefefefe
ffeeffefeef
`fefeffeef
feffefefefe
feffeeffeef
afeffeefef
ffeeffefea(8
fefefeffeYa*
ffefeefeffeY
ffeeffeefefXa*
(t2ffeeffefeY
ffeefeffeefa
fefeffeef(-
Yffeeffefe
Xffefeeffea
afeffefefea
affefeeffe
Yffefeeffeefa
afeffeefef
Xfeffefeeffehah
afeffeefeffehah
Yffeeffefea
`ffeeffefe_-
Yffefeeffefea
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPm
8'1ijb
m-R 8W
(z(u+h
VXi:\P
JY"?@}K
RiR:3%BT
B>u1(t
z*+BnZes
2-Xc$,
}95Q7Iz
m%%M]A
K5!x^P3
&Y"0Nue$
t>BvfcO
g!vIo60^sC
i [A,i
y};t@I;L
T7|FD
r]$[-r
lq5RQY
\MI9K>
M]@r
EYu&3`
%{&N\~s
;YDFq1
\Z'kH"F'Y
Tv{gEd~
&Uw:\u
srJ+?;
C*5Vxw%
TIxkPi
8~katQ
m_1)J#
yEP]k)
jNj1#bZK
#/=.K>
-sc\0e
o(cBhZ
84/U`%&
RX,*p'+1
bEvQx4
6yYTCy
OAvp7Xn
$<_`eI
]$bkF]
6]%4>G
zK`| q
GGW^=d-{
o|:A/_
#zBe(\~E
Gz[8nzh
z5q5#p~
e!Za%>M
%Qc,&uz
zx"m.G;
k{ZaE=7
c^<--L
E[hXO;?
vV)S?eQ
Pi1jf
zYl{0I
>k:Yl_
K;}W>p?
N{W:9
g7Az1}gCg
1unv5:
"+!of TB
p;a?6_
}C(^8C
j-<'TL
JByB7B
^%4M8@h
M!4S8A
!4[8Gh
;$/PL|
w]Jki(
j@m$43a=
4TB%|
9nx=@s-
nx5@s&
(M~(?#9
h?y9\_
EVjSU9
96}RAQ
[h(kQjqqI
,kTQEa
;EzYYI
kg).(,
G!K!&.
*k*cWd
c3caR`
@ecjNF
:&8mgy>]
\8nIuYa
h$(kr
$/a"m0
PB*I]T34X
8L02HDJ
0l@$FU
dwA"80P
xV0.:0
Ro}=:d
]2/eU%e
AI\.7F
o,FH)Bg!
T8q4Xa
gF/bF/B
!2^$.l
VMn_?k
iv%^-m
4gOmmq
L\nxg<
u %`L\
v4.0.30319
#Strings
ayowa.exe
mscorlib
System
ayowa.Properties.Resources.resources
Activator
AppDomain
ArgumentOutOfRangeException
Boolean
Buffer
GeneratedCodeAttribute
System.CodeDom.Compiler
ConcurrentDictionary`2
System.Collections.Concurrent
IEnumerable`1
System.Collections.Generic
List`1
ApplicationSettingsBase
System.Configuration
SettingsBase
DebuggerBrowsableAttribute
System.Diagnostics
DebuggerBrowsableState
DebuggerHiddenAttribute
DebuggerNonUserCodeAttribute
StackFrame
StackTrace
Double
CultureInfo
System.Globalization
CompressionMode
System.IO.Compression
GZipStream
EndOfStreamException
System.IO
MemoryStream
Stream
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyName
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
MemberInfo
MethodBase
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeMethodHandle
RuntimeTypeHandle
STAThreadAttribute
String
Encoding
System.Text
StringBuilder
Monitor
System.Threading
Thread
UInt16
UInt32
UInt64
<Module>
Settings
ayowa.Properties
.cctor
GetEnumerator
value__
get_CurrentThread
get_ManagedThreadId
get_CurrentDomain
GetType
GetDomain
InvokeMember
Collect
CreateInstance
ReadByte
ToArray
GetCallingAssembly
GetTypeFromHandle
get_Assembly
GetExecutingAssembly
GetName
get_FullName
GetPublicKeyToken
AddRange
get_Unicode
get_Name
GetBytes
get_Count
get_Item
set_Item
GetFrame
GetMethod
get_DeclaringType
get_MetadataToken
GetObject
op_Equality
TryGetValue
Append
ToString
GetManifestResourceStream
set_Position
GetString
Intern
op_Inequality
BlockCopy
Synchronized
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
1.0.0.0
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$8f41c0e9-78ec-4c54-a3c1-9c14376d107b
_CorExeMain
mscoree.dll
s{zs8U!x
!|wtr|
[[gwss;8?tWGsZ
hkg$Wwh
iv8xyu{
5qho{W
V1gsry
54}849?x<k^
|vy{|W
BVfq9x8e
Z%b8su
pwgJg5R^xp
Ufh4sH
XG['Wf
#5x.s>t
32j&{vQ
xyXvvm@7
e33Wxsw7D
uQ~8wx':
W{x&dv
Urt3p[W
RyP9Tz
L1somwx
jHhXZvi
+fvxvu
g5g3AW
wwX'tvu7x
u|bdvsu
|Thx]h^X]z
Xy6xZ%v52
vHg%37th
[XLn(%G
#Su{CXS
ghT}xw
3C'sW<7xmw
uw7689
WSmwXq
&wwp>wwDX
\uw2x#[
[QC<4US
cns1x5W5Zf
v7}3LH;
wT`'wxpq
Zmw8\lf
~8^tQ7
uweg5vU9
33UJ'x
wKm6Sw
fhhxqXs
r>rMx9
#r:XYwG
H3sUVC
uw0'#t6
sdru\}jp4
gux~yX
8ax8w4vcce9
SY7hiU
c7V68S
2pw3ue
cm7g\gCg;
KxxP67
FgfWw'
dvxl7D8hW
Uwfc3W
8wX6w7af
A7Puf'8S
Qj7w:h3
yVWcGC'
cWv83?x
4G'Gn7cw
xh^xMeX
;sHeRx
7Gxx:w
gPvuLxxL
#Qcxlw
Mu%etuF
x<rst4
q7{6l}hf
s6h6'p
hwYdw7
b3wGz}
wu~GMS3*
1=x{]S
{8s!>vQ
tBac(88
93c;hG
8ssZfj
gW*av&
S]~b|i
~NtwWekX
WwwWyvc1w
UzvYsw{
-hevuWI
n5jucw
gg}3:67
br|cu8
uhfVWxxirC
GwSWxm8
tUkn8zw8
edw<RxfB
vhxw\^
w3Wi4]SqX
e5g7cm
vwk<Wz
7xxx67Pu=
hwhzy{wIS'
(gHXw'~Xw'
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Zvafgpxl
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
ayowa.exe
LegalCopyright
LegalTrademarks
OriginalFilename
ayowa.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
AegisLab Trojan.MSIL.Badernet.m!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Backdoor:MSIL/Badernet.90cd40e8
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 MSIL/TrojanDownloader.Agent.IAJ
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.Badernet.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.nc
MaxSecure Trojan.Malware.300983.susgen
FireEye Generic.mg.8b3db2945a73ca4d
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Backdoor.MSIL.Badernet.gen
GData Win32.Trojan.Agent.I0T9IW
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic BackDoor
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Backdoor.Badernet.Eaxh
Yandex Clean
Ikarus Trojan.MSIL.Inject
eGambit Unsafe.AI_Score_88%
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.fm0@aSKKQmp
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.1e8956
Avast Win32:CrypterX-gen [Trj]
Qihoo-360 Clean
No IRMA results available.