Static | ZeroBOX

PE Compile Time

2103-04-21 00:37:10

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005b990 0x0005bc00 3.89963711491
.rsrc 0x0005e000 0x000002a0 0x00000400 2.15770893948
.reloc 0x00060000 0x0000000c 0x00000400 0.0558553080537

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005e058 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
InvalidParameter10
SystemNetWebSocketsWebSocketHttpListenerDuplexStreamWriteAsyncCored35720
SystemServiceModelPeerWireStringsDictionary43940
SystemDataCommonNativeMethods24550
SystemServiceModelComIntegrationIContextSecurityPerimeter72670
SystemServiceModelChannelsReliableChannelListener14580
<>9__1_0
<SystemServiceModelComIntegrationComCatalogCollection39714>b__1_0
<>c__DisplayClass2_0
<SystemServiceModelComIntegrationComCatalogCollection39714>b__0
AbandonedWait0
InvalidParameter11
SystemServiceModelSecurityBasicSecurityAlgorithmSuite26351SystemServiceModelSecurityBasicSecurityAlgorithmSuite26351
<>c__DisplayClass2_1
<SystemServiceModelComIntegrationComCatalogCollection39714>b__1
Func`1
InvalidParameter1
AbandonedWait1
InvalidParameter12
SystemServiceModelComIntegrationITransactionVoterNotifyAsync13032
SystemServiceModelChannelsSecurityChannelFactorySecurityOutputChannel95032
SystemServiceModelChannelsReliableSessionBindingElement2132
get_SystemNetDelayedRegex62932
set_SystemNetDelayedRegex62932
kernel32
SystemConfigurationSchemeSettingInternal46372
cbReserved2
lpReserved2
InvalidParameter2
AbandonedWait2
SystemServiceModelSecurityWSTrust76503
SystemServiceModelComIntegrationTOKENINFORMATIONCLASS7413
SystemServiceModelComIntegrationIChannelCredentials74813
SystemServiceModelChannelsTransportReplyChannelAcceptorTransportReplyChannel333
AbandonedWait63
SystemCodeDomCodeNamespaceImport68583
InvalidParameter3
AbandonedWait3
SystemServiceModelDescriptionXmlSerializer62504
SystemServiceModelComIntegrationComCatalogCollection39714
SystemDataFunctionNode92654
ToInt64
isWow64
SystemServiceModelDescriptionMessageContractImporterStyleAndUse7174
SystemServiceModelDiagnosticsAcknowledgementTraceRecord34284
InvalidParameter4
SystemComponentModelDateTimeConverter59125
SystemServiceModelFaultReason61035
SystemNetUnsafeNclNativeMethodsHttpApiHTTPAPIVERSION55335
lpProcesSystemServiceModelSecurityUserNamePasswordClientCredential52055
SystemDiagnosticsConsoleTraceListener56675
SystemServiceModelChannelsPeerTransportBindingElementBindingMulticastCapabilities79995
InvalidParameter5
SystemDataSqlSqlNotificationRequest16606
InvalidImageWin16
SystemNetWebClientcDisplayClass5146
SystemServiceModelDispatcherXPathMessageFunctionIsActorUltimateReceiver69646
SystemServiceModelSecurityIdentityModelServiceAuthorizationManager68996
InvalidParameter6
SystemComponentModelListSortDescriptionCollection84307
NewtonsoftJsonFormatting53507
SystemServiceModelChannelsPeerNodeImplementationSimpleStateManagerIOperation49027
SystemServiceModelQueuedDeliveryRequirementsModeHelper92047
SystemServiceModelDescriptionWsdlExporterNetSessionHelper29057
SystemServiceModelDispatcherStringPrefixBranchOpcode70587
InvalidParameter7
get_SystemDataDefaultValueTypeConverter82408
SystemServiceModelMessageContractAttribute24518
SystemServiceModelChannelsRequestOneWayChannelFactoryRequestOutputChannel70718
SystemDataSqlClientSqlInternalConnectionTdscDisplayClass27028
SystemComponentModelIDataErrorInfo84128
SystemGenericUriParserOptions23078
SystemXmlXmlBaseReaderXmlEndElementNode41788
SystemDataSqlClientSqlCommandcDisplayClass52398
SystemServiceModelDispatcherMultiplyOpcode13998
get_UTF8
InvalidParameter8
lMicrosoftWinSessionEndedEventArgs78829
SystemNetCacheHttpRequestCacheLevel5539
get_SystemCollectionsGenericTreeSet64889
set_SystemCollectionsGenericTreeSet64889
SystemRuntimeSerializationDateTimeFormat89499
InvalidParameter9
<Module>
value__
SystemServiceModelSecurityBasicSecurityAlgorithmSuite26351a
base64EncodedData
NotMappedData
SizeOfRawData
PointerToRawData
NoTxfMetadata
PagefileQuota
mscorlib
ProcessInJob
ProcessNotInJob
DifferenceAtDc
BadInitialPc
e_magic
KernelApc
UserApc
dwThreadId
dwProcessId
ObjectPathSyntaxBad
hThread
RecoveryNotNeeded
PagefileQuotaExceeded
ArrayBoundsExceeded
SemaphoreLimitExceeded
SuspendCountExceeded
ThreadWasSuspended
SectionNotExtended
AccessDenied
RangeNotLocked
ServerDisabled
AccountDisabled
ServerNotDisabled
TimerNotCanceled
RequestCanceled
IoPrivilegeFailed
LogGrowthFailed
TransactionPropagationFailed
TmInitializationFailed
PrimaryTransportConnectFailed
Cancelled
FileRenamed
NotAllAssigned
TransactionNotJoined
Abandoned
ProcessCloned
MutantNotOwned
NoneMapped
SomeNotMapped
Clapped
ProfilingNotStopped
RegistryRecovered
PasswordExpired
RollbackTimerExpired
FormsAuthRequired
SynchronizationRequired
CheckOutRequired
FileForcedClosed
FileClosed
HandlesClosed
PortClosed
PortConnectionRefused
VirusInfected
PipeConnected
PipeDisconnected
RmDisconnected
LpcReceiveBufferExpected
LogCorruptionDetected
ProcessIsProtected
FileDeleted
VirusDeleted
LockNotGranted
NotImplemented
VolumeMounted
ProfilingNotStarted
RmAlreadyStarted
Alerted
TransactionAlreadyAborted
CtlFileNotSupported
EasNotSupported
TooManyGuidsRequested
TooManyLuidsRequested
TransactionNotRequested
GuidsExhausted
LuidsExhausted
AgentsExhausted
RxActCommitted
NotCommitted
TransactionAlreadyCommitted
lpReserved
TransactionalOpenNotAllowed
LpcRequestsNotAllowed
InvalidCid
InvalidSid
HandleNoLongerValid
StreamMiniversionNotValid
CurrentTransactionNotValid
TransactionRequestNotValid
FileInvalid
ObjectNameInvalid
ObjectPathInvalid
PrivilegeNotHeld
<SystemCollectionsGenericTreeSet64889>k__BackingField
FloatDenormalOperand
Append
ResourceDataNotFound
ResourceNameNotFound
ObjectNameNotFound
ResourceTypeNotFound
ProcedureNotFound
ObjectPathNotFound
OrdinalNotFound
DllNotFound
CrmProtocolNotFound
StreamMiniversionNotFound
EntryPointNotFound
method
IllFormedPassword
WrongPassword
SystemServiceModelSecurityIdentityModelServiceAuthorizationManager68996asd
Replace
NotSameDevice
NoSuchDevice
NoMediaInDevice
exitCode
InvalidReadMode
PageFaultGuardPage
SizeOfImage
SectionNotImage
LpcInvalidConnectionUsage
InvalidMessage
NoSuchPrivilege
WorkingSetLimitRange
EaTooLarge
FileTooLarge
EndInvoke
BeginInvoke
InstanceNotAvailable
PipeNotAvailable
InvalidHandle
RuntimeTypeHandle
GetTypeFromHandle
ProcessHandle
InvalidPortHandle
handle
EndOfFile
PageFaultPagingFile
NoSuchFile
NoEasOnFile
TmVolatile
lpTitle
hModule
InvalidEaName
procName
fileName
SystemServiceModelChannelsPeerNodeImplementationRegistration36236tionName
lpApplicationName
InvalidComputerName
InvalidAccountName
WrongVolume
lpCommandLine
Combine
BadFileType
ValueType
SecurityProtocolType
AllocationType
DllMightBeInsecure
LogonFailure
Signature
ResourceInUse
TokenAlreadyInUse
ImageBase
ImageNotAtBase
Dispose
Reparse
DataLate
X509Certificate
MulticastDelegate
NothingToTerminate
DebuggerBrowsableState
InvalidPipeState
CannotDelete
PageFaultCopyOnWrite
TransactedMappingUnsupportedRemote
TransactionsUnsupportedRemote
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
TargetFrameworkAttribute
dwFillAttribute
SecurityPermissionAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
set_Expect100Continue
RmNotActive
TransactionNotActive
DebuggerInactive
Clapped.exe
dwXSize
dwYSize
LogResizeInvalidSize
RegionSize
SizeOf
CantTerminateSelf
SectionTooBig
System.Threading
DeletePending
Encoding
PipeListening
System.Runtime.Versioning
Warning
FromBase64String
xoredString
ToString
GetString
PipeClosing
ThreadIsTerminating
CouldNotResizeLog
ObjectTypeMismatch
InfoLengthMismatch
RevisionMismatch
RemoteFileVersionMismatch
RecursiveDispatch
get_Length
AsyncCallback
RemoteCertificateValidationCallback
get_ServerCertificateValidationCallback
set_ServerCertificateValidationCallback
callback
BadStack
BadInitialStack
FloatStackCheck
AllocHGlobal
FreeHGlobal
Marshal
Informational
InvalidAcl
BadInheritanceAcl
InvalidVolumeLabel
BufferTooSmall
kernel32.dll
user32.dll
DiskFull
get_SecurityProtocol
set_SecurityProtocol
Unsuccessful
DirectoryNotRm
UnableToFreeVm
System
hToken
NoImpersonationToken
NoToken
hNewToken
CantRecoverWithHandleOpen
lpNumberOfBytesWritten
TransactionsNotFrozen
X509Chain
LastAdmin
ObjectNameCollision
UnknownRevision
NoSuchLogonSession
get_Location
GuardPageViolation
SharingViolation
AccessViolation
FloatInvalidOperation
InvalidWorkstation
SecurityAction
MiniversionInaccessibleFromSpecifiedTransaction
InvalidTransaction
EfsNotAllowedInTransaction
CannotExecuteFileInTransaction
UnableToDeleteSection
System.Reflection
InvalidPageProtection
SectionProtection
PasswordRestriction
AccountRestriction
IllegalFunction
PrivilegedInstruction
IllegalInstruction
PageFaultTransition
TransactionRequiredPromotion
EntryPointNotFoundException
NonContinuableException
MethodAccessException
System.Runtime.ConstrainedExecution
DataOverrun
lpStartupInfo
PageFaultDemandZero
MappedFileSizeZero
IntegerDivideByZero
FloatDivideByZero
IncompatibleFileMap
SingleStep
CrashDump
LongJump
lpDesktop
NotifyCleanup
NoSuchGroup
SpecialGroup
MemberInGroup
MemberNotInGroup
InvalidPrimaryGroup
MembersPrimaryGroup
InvalidSecurityDescr
FileHeader
OptionalHeader
StringBuilder
TransactionInvalidMarshallBuffer
ServicePointManager
InvalidOwner
NoSuchUser
SpecialUser
InvalidParameter
GetDelegateForFunctionPointer
LogonServer
NotifyEnumDir
EnlistmentNotSuperior
DataError
CrcError
hStdError
InPageError
InternalError
EaCorruptError
.cctor
IntPtr
System.Diagnostics
TooManyThreads
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
NoMoreEntries
bInheritHandles
TooManyOpenedFiles
NoMoreFiles
TooManyPagingFiles
System.Security.Cryptography.X509Certificates
lpThreadAttributes
lpProcessAttributes
dwCreationFlags
ContextFlags
dwFlags
CantCreateMoreStreamMiniversions
System.Security.Permissions
NumberOfSections
get_Chars
dwXCountChars
dwYCountChars
SizeOfHeaders
FileLockedWithOnlyReaders
FileLockedWithWriters
NoLogonServers
SslPolicyErrors
InvalidLogonHours
InvalidInfoClass
CallbackBypass
Success
hProcess
ThreadNotInProcess
GetProcAddress
lpBaseAddress
VirtualAddress
OpLockBreakInProgress
ZeroBits
ObjectNameExists
GroupExists
ObjectNoLongerExists
UserExists
TransactionSuperiorExists
CrmProtocolAlreadyExists
MaximumNtStatus
InvalidImageLeFormat
InvalidImageFormat
ReparseObject
object
InvalidImageProtect
FileLockConflict
TransactionalConflict
System.Net
TransactionScopeCallbacksNotSet
PortNotSet
PortAlreadySet
CantWait
op_Explicit
BadWorkingSetLimit
CommitmentLimit
ControlCExit
IAsyncResult
FloatInexactResult
result
DatatypeMisalignment
lpEnvironment
TxfMetadataAlreadyPresent
CantOpenMiniversionWithModifyIntent
EaListInconsistent
FileIdentityNotPersistent
AddressOfEntryPoint
Breakpoint
SpecialAccount
NoQuotasForAccount
RmMetadataCorrupt
TxfAttributeCorrupt
Convert
InvalidDeviceRequest
IndoubtTransactionsExist
get_Host
set_Host
MessageLost
FileCheckedOut
IoTimeout
hStdInput
hStdOutput
System.Text
pContext
NotMappedView
e_lfanew
GetConsoleWindow
wShowWindow
nCmdShow
FloatUnderflow
BufferOverflow
IntegerOverflow
FloatOverflow
InvalidParameterMix
CantBreakTransactionalDependency
Consistency
stringKey
GetExecutingAssembly
PartialCopy
CantCrossRmBoundary
LoadLibrary
FreeLibrary
NoMemory
CantDisableMandatory
lpCurrentDirectory
NonExistentEaEntry
DeviceBusy
PipeBusy
op_Inequality
InvalidSubAuthority
InvalidIdAuthority
System.Security
System.Net.Security
PipeEmpty
TxfDirNotEmpty
VolumeDirty
InvalidImageNotMz
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
SystemSecurityCryptographySafeCertContextHandle73696
ServiceModelSecurityIWSTrustFebSyncContract7786
VServiceModelSecurityIWSTrustFebSyncContract7786FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUtiZTdaNEFBQUFBQUFBQUFPQUFBZ0VMQVRBQUFHd0JBQUFNQUFBQUFBQUEwbjBCQUFBZ0FBQUFvQUVBQUFCQUFBQWdBQUFBQkFBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFEZ0FRQUFCQUFBQUFBQUFBSUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFJQjlBUUJQQUFBQUFLQUJBTlFFQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQU1BQkFBd0FBQUJrZlFFQUhBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFpR3NCQUFBZ0FBQUFiQUVBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQU5RRUFBQUFvQUVBQUFnQUFBQndBUUFBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQU1BQkFBQUVBQUFBZUFFQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQ
UgFKZSqfkSZCal
NServiceModelSecurityIWSTrustFebSyncContract7786FUQMjg+JxUmKRM2OystFA==
NServiceModelSecurityIWSTrustFebSyncContract7786wkUIDgUBhMxFCIw
BServiceModelSecurityIWSTrustFebSyncContract7786FQMJwMLIwo+GxA1OF4DHSV7NiYVIT0qOC4nHwMQe3Y=
AServiceModelSecurityIWSTrustFebSyncContract7786yAQMjgEHRMyCwgvNCQfER95DCkSEVZu
BServiceModelSecurityIWSTrustFebSyncContract7786FU+PTlhJy8yBG8oAysAWg==
BServiceModelSecurityIWSTrustFebSyncContract7786j8IEzhgElQlFRg6A14bCyV4F24=
AServiceModelSecurityIWSTrustFebSyncContract7786QkUCTgUCRAyYRxzOzoPFyUlCGIoMRMdABRQGjYJLXY=
AServiceModelSecurityIWSTrustFebSyncContract77861QMOz4UJzcIPmMpOzQbHRIcDCcTVSFm
AServiceModelSecurityIWSTrustFebSyncContract77861V/eBQ5Iy4xCwgWACQfCx8cCBcTVF5jABsJXA==
BServiceModelSecurityIWSTrustFebSyncContract77861UQewwUGR8xBBwoMF5sEiIMDGcVJ1Zu
AServiceModelSecurityIWSTrustFebSyncContract77861V/eBQ5IzIxCwgWACQfCx8cCBcTVF5jABsJXA==
AServiceModelSecurityIWSTrustFebSyncContract7786FUQewwUGR8xBBwoMF5sEiIMDGcVJ1Zu
AServiceModelSecurityIWSTrustFebSyncContract7786AoQMT4EQAo9FDI6OzsTDA==
AServiceModelSecurityIWSTrustFebSyncContract7786QkUHTg+QA4IFQAzOzQxNxwnFD8oVTkjOHFVUQ==
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Clapped.exe
LegalCopyright
OriginalFilename
Clapped.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46504688
FireEye Generic.mg.fb68c8251f6b0ce4
CAT-QuickHeal Clean
McAfee GenericRXOX-MJ!FB68C8251F6B
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057e2801 )
BitDefender Trojan.GenericKD.46504688
K7GW Trojan ( 0057e2801 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Generic.D2C59AF0
BitDefenderTheta Gen:NN.ZemsilF.34744.xm0@a8LwC5k
Cyren W32/MSIL_Kryptik.ENZ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABNH
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba Trojan:Win32/Kryptik.ali2000016
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.MSIL.Reline.i!c
Ad-Aware Trojan.GenericKD.46504688
Emsisoft Trojan.GenericKD.46504688 (B)
Comodo TrojWare.Win32.UMal.uvuuf@0
F-Secure Trojan.TR/Kryptik.dixyz
DrWeb Trojan.PWS.Siggen3.109
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fz
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
MaxSecure Clean
Avira TR/Kryptik.dixyz
MAX malware (ai score=89)
Antiy-AVL Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Reline.gen
GData Trojan.GenericKD.46504688
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4527753
Acronis suspicious
VBA32 Clean
TACHYON Clean
Malwarebytes Spyware.RedLineStealer
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CFH21
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
eGambit Clean
Fortinet MSIL/Kryptik.ABKY!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.69bd77
Avast Win32:PWSX-gen [Trj]
Qihoo-360 Clean
No IRMA results available.