Static | ZeroBOX

PE Compile Time

2021-06-07 19:53:36

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00010f04 0x00011000 7.40551902713
.rsrc 0x00014000 0x00010ec0 0x00011000 4.38835876568
.reloc 0x00026000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00014180 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000249a8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000249bc 0x00000318 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00024cd4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
\t|1f'
eA2Wq`
7}mUgU
(BpbK*
z}Mk) [
$HG|K{>
+!;Zj+
HN{?4,
iS}Ch`
?6N-pe`
A$+<]W~
Ey$U,Be
D)8Jdu
%unC7K6
8'VZ$ ]
7^0XZ
TtlMr
#u~yOd
vL#C=;
l8GZ"4
D&^p(G
hXPscpu
n[>z9r'
B1Isik
I}LlmY
e*WUOH
s,)fHa
IFeN-z`
JxVD\w\
cr"vQT
<A9s}~
>FiY(Q
DWUT:R
^a;)XP
%9pJ!t
l6ih<ZY$$|I
EO<MeI
5Y^{5w
y!?.u.
4])cn%
c.W-+*
`YNpHb
i{"Im6
5B!tyv_
4Vx*0L
ir.iz}
Z-&=y
SZ7T&TU
t<=qM>
#$Y~D$,
;p7LgZF
`b1"^(
#LS1'$
nQA(LU/
2CrCu(8
Y_cX*j
Y_cX*j
VMDj^m
Z?_b`
Z?_b`
p:Z 2
_bj2
_bY*
Z_bX
_bj2
_bY*
Z_bX
v4.0.30319
#Strings
#Strings
#Schema
SystemSocketTasks.exe
<Module>
rWNbJPCoptCAkomlKqQdkUYhbjbDAAb'rBJ[qoP9&g1jn55{hag /(
AAmdhJitLNbgvzwLBVmmqQzDIFzuAHfS3-HoXhu{a[^x*R/`AT)~,%
Decrypt
mscorlib
GCHandle
System.Runtime.InteropServices
Resolve
Assembly
System.Reflection
ResolveEventArgs
System
Decompress
.cctor
TOtFqZLngqQEFHDidRzMdJLtQjnq^pge4X9mG~>B2WGO^( TYWYC$
FOKsLyZUpfTFZdhkwscnIemTMHpP2D6RG>>;_R~6{A/(IwxArlGW&
nfyFvlGkTztEJrpjgqfIEyCHjEaHbI)U_=\])Yh|M""SG{jO%hH23#
ibKukkHQGDwltBcxoCjyjEtURhSf]/|("J>vfcA`3EWXM(}[tNd^!
maDIfkrGvqEPdBMzqnFHUdpqQQyQA};!?g Re;d/Q-oy%|Y_[IhL{#
ekiVZICNqozbUNqXhjNpYaegyHDd5A[H!<+k*,*: &q=Hhbiiq:~
fonWcoBoxdKONrpAMcHauLXoSZCl/}m$(7j7*d\uan'zIo,2wB!%$
weIRxWVMNkPHZlXGxPzSskCCDMEB_h)^MhR=*r^Oru%^A5gbD0v=
wWDYIiWPddlTZewErkEXRGdguIgoaEn\,E0Cy4ha}p,J4a~"74/>"
DataType
ValueType
BitDecoder
Decode
BitTreeDecoder
Models
NumBitLevels
ReverseDecode
Decoder
Object
Stream
System.IO
ReleaseStream
Normalize
DecodeDirectBits
LzmaDecoder
m_IsMatchDecoders
m_IsRep0LongDecoders
m_IsRepDecoders
m_IsRepG0Decoders
m_IsRepG1Decoders
m_IsRepG2Decoders
m_LenDecoder
m_LiteralDecoder
m_OutWindow
m_PosDecoders
m_PosSlotDecoder
m_RangeDecoder
m_RepLenDecoder
_solid
m_DictionarySize
m_DictionarySizeCheck
m_PosAlignDecoder
m_PosStateMask
SetDictionarySize
SetLiteralProperties
SetPosBitsProperties
SetDecoderProperties
GetLenToPosState
LenDecoder
m_LowCoder
m_MidCoder
m_Choice
m_Choice2
m_HighCoder
m_NumPosStates
Create
LiteralDecoder
m_Coders
m_NumPosBits
m_NumPrevBits
m_PosMask
GetState
DecodeNormal
DecodeWithMatchByte
Decoder2
m_Decoders
OutWindow
_buffer
_stream
_streamPos
_windowSize
CopyBlock
PutByte
GetByte
UpdateChar
UpdateMatch
UpdateRep
UpdateShortRep
IsCharState
lmAMCaEACDRWIxKcMKFnBrxZMjMiWC!T$tlHr8t,8w2lc:bCf0Dv
RdfCgEwaKVFlOosFayRuFOvrmqHU+GqAB7)PPk8VU2m6sH-]=EUj#
OHiVhrOmpxvkWKHrDovRDRiEwHsr0vYII-VU/G%z`*6EZ%rCV9#"+
frjEhgHEeRgUtMXarkkfBguFLmPEauDD]<R72e-v8gES*x7&rp\&!
KSlLuwgEBqbjBJMOXwhSpdZYIBdCA2mi]K;R4,Q'ObT0}+TUnPJ'C$
ZwYOFwJbVSnppvQqYxPcMlDECHALzN'v7@,@b(s"u_~9S%lz@R3V$
KAPquzOUmcuQhRSfYGEkKSpsUWUul4+9m0'5/D1>VwTXZe6 o'PP#
VUEozCBzSSqhfYmBzGkLlSsRtTPtF-FCt0%8Hq2YbVeOph7Q0fL!%
AszuVtRcrhAhwasgbVPXqMCNKDgcbdd"f{?:9U?3~mC,~0M|%0>\G%
CGEwVentnxKdjmtAQASKVkOCEKvKAlt'L}7*=}(5> t\@ftN)L@-/(
DFcddzvIRBqMuGPoiwzIXBOEeSnkAXIAK(S7%:0eUn(?sNsp#4t_e!
IheLaeeyeSfDXGeldcTZKUZDXefEbo%|;iY&>{t857=IZnYN0b7}
PkietHhPXefjaOrtAtqdXscXbKQFh9,}huhD; _'N #*mbtS@54-!
XduujaqRBMyVSlUjsgUpDYKSMIcKZTw=c:$)'NXLw[ES<5^~XT'5&
wCoqoxVzilPBxnpFiCgFqyCmqNvdSCXMsb_9$N0wE)C+L?R/UYS*!
dmdixSMgDwSNTeYKPukdIfdlHzYUy|$[^'b'GLje_4tG*/@}G$6,"
vGgbDJnsOKiERFAtuogBdLxDZHHxAePwLB@SX^@%:`Wa&O@2w'?zb6
ODUjTTfAEVwqSNUtlXQqQYUifelKAVE\l~bJ@+12UXCADZk2%{Gv5%
dqqTszSGZpQUchbZGFHLvutHXJbRUb;E_5!`e!$aEJ>4aF](TT}$#
oLXyMotGBLdtDJjHRBLBAQXJlfQYwtJMY ^FTuJn>@dBVJ+tZo'l!
GcFNprrcsZYdfZmNMfyuCVbEhlEmAZw-}kgO <AOOZ<xaS0PoVSK!$
CcSnfizyZTilfLSneKxHZkUWUDCF0j`_Ms*H0;i<]?a'l=b{:fj("
oqSgvqgdOROuoXBWaFBHMNIvkknBA[6~_q[$|Z93?l2s\y\6B_1E3&
bPSoqQGPGduyLBEdiEezKkjsXQbPI'b[R/nD 3h_BsCU/3|?E:E;&
EKFfPgLjfhnPeggSHnxSNqwYefOUvkv~QD}{u~=SV8\i883*);d\!
UOkifheWxZgBAgJxKvXVUFFEvKBLTFiO3iHFdM@1Om^&!'|)^}'/!
PYNZSRZHwWWGYFdOSDvruYaRLgXB|-Jr~<!+v:VFWctVE13j|n]{
NesilaMoNKLVIhhptfXoPlqBgrVu`"Oa("4~Z8$<aw&&:afe@qkb+
VzaeyjHOfDXkHyxlrNKaiFYcWmct|"*7M`:K0o2j?( !3%yNS{>e$
GQLcxYequxdMkFmXTCkieMzinlMjbnUJ$xc!Q{TYO2z>OY |(mWc+%
eVOOFweORkowtnDHWBgZEjkQVviDA,/0+97EzqsKIUz6EW@,Yp"YW%
bMgfcxOVmiVHAMQCPThLdjtYVssn$nw9]n&$i6)k%f@ !Bc9r{-Y&
EBPlWAovCqPbKcWufTQZtdwwyDfU8Z>-PoR2"MvS"o;J7:=O}3Pu+
LWJOKAlKdsHhLCaCapojsLQnsAGk|k-Tn=w*Obfv"xWqG5}j[=v}
VIayqnyHVujyfiGpCKdikneKQeEmb\$*Iy(jqC53z]X4o?-k+hDP!
GCRgdnNBDUpCFpMgfGWZHECwHFnK|8D{sL~D8=J=`KS^^Bj#wt$%!
nWvtDmZeKoWdcLPcTnDhlipMTZlCyyT}j\cM{4qx4$@,CIOXJTqL
tiWqjyQuqjvCOclpLjRLPcBCSSkv;=:"70<="x:8o,DP/%h<j[nU,
PmESEyVuTtrveUJqvmoBIuwsGitg4}fb}x f;y"Zu5g{bt^{_V]%!
xJduMOSvMIYEyvCinMrQYVamvGjI=#w[\'"ef<*KSPaz0V_s1,&a
PjQCNfioOtQPXInroHOowiqOKlub%0-b-9W%o-^<E^uv\cD&RJ;c
LAsAsDnwalAKsXmplNmdwUxpvmWlL&]5XI4Sy6[6hu? mF/(U,TN$
GDRVOXkPafjLPyauQdJUfzbduKGrD26)DQc}y_4QUQnxPL,Ik46@%
fpRYSVvxjYXUKplliCJVuFxiebWIC7HF~5t[hP%eDe --+?c_U,J$
uTrSedLlRjzIrvCbvuTgdjQiuEvCSc=BKbI>53("/#G}IC5uI{;Y!
yqhGIEjUBzmJGovjgPhmdxmBPbyvbo6=`Dd>j"#NU/"}1xw=7L]~"%
tcoOrhnwLSNWAsjQxvOzYGXdKfYwswIg(9dDr4r=$X/P% XXao{'#
fJPWyWiUhvilXXUXqkruveUIsNRlgU`!<OP, }P5x~o/;4arv]';"
QJOFVgIvgMDVyPEkEmqjbihZnGoj~U)Zi0Fu-4&rz}r={GM"2,Qw
ICPdamRNulsRhmEyqhEocnacTNXTDF\;UV0{ei"&qcQdyYGG5D7!#
xoADYdiocvlOgfdaFxohuxkHLwItGSrveu7[/#c-={J*:ia,d"hr$
yCOjTqLXeqNDslNHqdurNkKuTBld$d[YvX!i_|I$#3X_=L}EE@12
fMFfnGeReSGZMBgBELsYUCSCVNsnbU2Z5~SB(6h*~5jd3Z4hdpSj_)
BrKImLKxrofIpGeQLexexXWyAyDr4AR%ZXPA=/S1vJJ{KZi\A1W:%
XyFQKFuPlHWsuEDapALvHIBOhVpYA'OLP</*g>&"DDk{ZRo@nt!Bu)
wspTPxNXTBJagsdLlEywhKDpAAMlA1e9jG3pZXg%qUhcma"t2CSrl%
XBVECHVVGkCJztDnQFkyGULgMarb0|v;|nrW4``iv>3LgVBAuX/4
XSqKXNktXYkqpKIUZyvOzjbFumeubPOZp&$|LW=BX`-yT@]?l$*s%
HzfnKxtsncFqmloxntASzUUGjrLF2JGOq[=/u>m"[]k*R[{x\,T3!
jLVFekIIBsfgmPzuNCGPGRVlFiahK<$'9^bMyS"\_[V4ZB_%kDUo
AOHSDrEFOigvkzclKDOFzNzJKYCQ2[Z<Ehd+i$q*w/'HzOMU'bl<!
shzpLrjKbZWZrgdXRVMqmhviFREc_]tw+9|\C'-meTu-FeA0YV~D
ORrRxjIaZpcGsFVcLhDjpjklVBru@:QPet%\a#(C2G4Z65I&W:0/&
SljFwHKEOgYicBwLilidOPQDUogf0|1L-x#p/R1h-x37SV8lVnK<
VzEFxCBaGfoXisqHdMUIbeRDmQVFBf@-Y>Ysd]nM"$JYfoB1!;x\b%
QuGfVrFOOvdyeQpCtAvqWifkHMIcA`vx!i' FwWqI`>;&w|VE(z$x#
GPTCuEySJjdrKnnOPclaPdftRLFXdT0cPQ3<_IJI*p>9GNR{CJ2@$
TkestqVvVsOBEjfeECFLgsZiDwbpp9$;?ftte@8#AuLl|m$\m5yT"
JtkMJKiGxNrqVChNzVURozMqoCWb~mIp8=|L{I_8Cs}-6 *=_eV7
SaWtbtQtIfZxaHDnpZnFfeXxSlhAv/]5DeqL<3g)B=6Nui(FRr7,
xtBRDzBlfSDvEMbeaAmUfJPpcNZwASIN|a0D3#")aPs]&Rjb^*pQB'
ltFCCaAANnErxbBFKtRMTMPMbdejB*{pd3:~!Kk9FjJ=pc^<#?"UM&
ayJnEXuigfpoRvGUvAOpdVpVAbPFb$sF^p$}97W^NsZa8KEt_DK #$
HCfwaUbpultsGwiEsUCDONaOfWfKNp( 67s*GW%0M6K+tV-?nc/;&
uCBmJgYlOAOssLDUPdcxSiCzLpSwU1jC*:3<6H5?L|HAKU`lW[&z"
kUZELhIfGkpjPiLCefqWZMpXRzrM(wjB/j$:A9~H&roc-%R{D&=g(
gNIRVfBLAshQvIGSBXmNdgDXMQaPA(C\V/9:!sh:5vJj"j-u%l/hQ*
iVzVYJKioVHNRmvBxkGLAhofKVMSU(k!80H1h>X&`fEE-XD5y0?F$
riJgQIHGVupOTmRFENGFhTcvdazq1')vBnJXUNTM/HB`):u([&?&*
wAnsOMczQTBmNIKtGqqoBHaYJFVwwhio2[R+BTzv{El7k:6Mv\d9"
DGHReUUCICGIgYLGxGMvAIxEnjKhbFR0nvja^PFi|TH]Ti`0YF{7r"
GALdvHWueBubzoFfrPAMKVSxFORN+DTox+<?|]&Ym7$lXP<4QL8H$
WgPWiJPtEJNEBmIWRwyqInGmyNOL^DsH'fe8h%<K+Td OxJ+CC8:!
djqdfLuQveawJHIXuRIXghmFAhjNKM]E)y3}7Mt5:vi#R%O{Z{&7$
ovGNSJPOYkKZAhuvuZpuPAXLZyDHuE)\l|gzU#`q^yC~13-n~F4x"
kXPdzOivyRrJPzmEICKdyMJzkYnHAe`c`?NEVmtOKbn6M@}l*U ,#
DDbvwnUkFKIFUdKFnQAFgRWFLUCTPquwm!`XPl:/*-]fol3!l$>L-
WFygVbUPMLLvgtLwewgRBgpXizlPbQ=[U%CbNl{]B[cSte<{FK"i#
gZLzMhhlyJjCRCedmnYIIiEobryfcJT{=aHexw-+>E7 !#%Xk{S0!
RxDXbCUzfmjStMvnsIMvRugGmrAM-Fd3b;xW(8m6P][4`{#$8Siz"
iwHaeobkAPajdMwYRMPopwgyVWdAAYap=$;S~~{_mA:-@"m{Ao0BY'
pFmPBpothevJVNahEEXMGiUSsILI vA#k_Mbg"`>+MRd^^s>Xe2t
hmGTlaIIJrwRHciZNAcPypkxAZAM?uRdG^O!G72(uBT?2C2g30%;!
SystemSocketTasks
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
ComVisibleAttribute
AssemblyCompanyAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
STAThreadAttribute
UInt32
GCHandleType
Module
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
MethodBase
GetParameters
ParameterInfo
Invoke
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
MemoryStream
ReadByte
MethodInfo
Environment
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
Concat
Equals
FailFast
ParameterizedThreadStart
System.Threading
Thread
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetString
Intern
GetElementType
CreateInstance
asdasfsa
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.0.0
WrapNonExceptionThrows
adasda
_CorExeMain
mscoree.dll
ALm'ALmWALm}ALm
ALm!ALm
ALmGALm
ALmALm
ALm5ALm
>Ik8AMmKALm.EFp
CNomALm
V`}xMWv
U_|zOYx
JUtVALm
U_}xLWv
U_}xLWv
U_}xLWv
U_|xLWv
V_}yLVv
7@\q6=X
5>ZB3;U
4<WQ3<V
5=Y)5=Y
6?Z!5>Y
4<WM3;V
4=Xg3;V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4=Xh3<V
4<W_3;V
3;VE3;U
5>Y)5=Y
@KlqAMn
8A^(7@\
4<WZ3;U
5>Z#3;U
4<We3:T
5=Y/2;T
4=XM3;V
4<Wd5>Y#
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
&NOTEBOOK_ADDRESS_BOOK_BOOK_ICON_188783
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
adasda
FileVersion
1.0.0.0
InternalName
SystemSocketTasks.exe
LegalCopyright
LegalTrademarks
OriginalFilename
SystemSocketTasks.exe
ProductName
asdasfsa
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.ef4cd87768670dbe
CAT-QuickHeal Clean
McAfee Artemis!EF4CD8776867
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Win32.Malicious.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Trojan ( 0057310a1 )
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Packed.Confuser.DY
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Trojan:MSIL/Confuser.05e28375
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34722.im0@a4T2Job
ALYac Clean
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Confuser
eGambit Clean
Fortinet Clean
Webroot Clean
Cybereason malicious.266b7a
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.