Static | ZeroBOX

PE Compile Time

2056-01-16 19:04:32

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00058ef4 0x00059000 3.76417883291
.rsrc 0x0005c000 0x000002a8 0x00000400 2.17819904384
.reloc 0x0005e000 0x0000000c 0x00000400 0.0558553080537

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005c058 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
SystemNetMailQuotedStringFormatReader94410
SystemServiceModelChannelsPeerIPHelper19660
NewtonsoftJsonSerializationJsonStringContract16480
<>9__1_0
<SystemUriTemplatePathSegment33766>b__1_0
<>c__DisplayClass2_0
<SystemUriTemplatePathSegment33766>b__0
NewtonsoftJsonJsonTextReaderReadStringValueAsyncd52351
SystemServiceModelChannelsUseManagedPresentationBindingElement33751
SystemServiceModelChannelsCertificateNameStringType53171
SystemServiceModelChannelsTransactionChannelFactoryTransactionDuplexSessionChannel210281
SystemDataSqlClientSqlColumnEncryptionEnclaveProviderConfigurationManager11681
SystemServiceModelDiagnosticsPeerSecurityTraceRecord955291
<>c__DisplayClass2_1
<SystemUriTemplatePathSegment33766>b__1
Func`1
lSystemServiceModelDotNetOneWayStrings5702
SystemDataForeignKeyConstraint14432
kernel32
NewtonsoftJsonConvertersXDocumentWrapper87542
SystemServiceModelConfigurationXCertificateTrustedIssuerElement11842
PrivateImplementationDetailsStaticArrayInitTypeSize362
SystemNetMailMBUserType87972
PrivateImplementationDetailsStaticArrayInitTypeSize41292
cbReserved2
lpReserved2
SystemServiceModelChannelsTransactionChannelListenerTransactionInputChannel76013
SystemServiceModelSyndicationCreateReferencedCategoriesDelegate63613
SystemNetIntPtrHelper45223
SystemServiceModelChannelsFramingDuplexSessionChannelFramingConnectionDuplexSessionSecureConnectionDuplexSession62233
SystemDataCommonDBConnectionString10633
get_SystemCollectionsGenericSortedSet58024
set_SystemCollectionsGenericSortedSet58024
ToInt64
isWow64
SystemServiceModelDispatcherNumberEqualsOpcode87884
SystemServiceModelConfigurationWindowsClientElement74094
SystemXmlValueHandleConstStringType39605
SystemServiceModelSyndicationCategoriesDocumentFormatter3615
SystemServiceModelComIntegrationWsdlWrapper28615SystemServiceModelComIntegrationWsdlWrapper28615
get_SystemNetUnsafeNclNativeMethodsHttpApiHTTPREQUESTHEADERS56775
set_SystemNetUnsafeNclNativeMethodsHttpApiHTTPREQUESTHEADERS56775
SystemSecurityCryptographyOidCollection54716
SystemRuntimeSerializationConfigurationConfigurationStrings64936
SystemUriTemplatePathSegment33766
SystemServiceModelChannelsEmptyBodyWriter61127
SystemServiceModelDispatcherBufferedReceiveBinderRequestContextWrapper52227
get_SystemServiceModelChannelsTypedFaultHelperAlreadyClosedAsyncResult88227
NewtonsoftJsonUtilitiesCreator9037
SystemNetCERTCHAINELEMENT43057
SystemServiceModelSecurityWSTrustServiceContractConstants72457
NewtonsoftJsonLinqJsonPathFieldFilterExecuteFilterd14408
SystemServiceModelDispatcherDispatchOperation50318
SystemServiceModelChannelsTransactionChannelFactoryTransactionDuplexSessionChannel21028
lpProcesSystemServiceModelChannelsReplyOneWayChannelListenerReplyOneWayInputChannelReceiveAsyncResult11338
SystemTextBinHexEncoding36248
SystemSecurityCryptographyAsnEncodedDataEnumerator56948
MicrosoftWinIInternetSecurityManager81068
SystemServiceModelChannelsMsmqReceiveHelper23968
SystemServiceModelSyndicationAppConstants92188
SystemComponentModelBindingList32288
NewtonsoftJsonConvertersUnixDateTimeConverter2898
get_UTF8
SystemServiceModelDiagnosticsPeerSecurityTraceRecord95529
SystemCodeDomCompilerHandlerBase39649
SystemServiceModelSecurityReceiveSecurityHeaderEntry13479
NewtonsoftJsonJsonReaderReadAndMoveToContentAsyncd53879
<Module>
SystemServiceModelComIntegrationWsdlWrapper28615a
base64EncodedData
SizeOfRawData
PointerToRawData
mscorlib
e_magic
dwThreadId
dwProcessId
hThread
Ringleted
lpReserved
<SystemNetUnsafeNclNativeMethodsHttpApiHTTPREQUESTHEADERS56775>k__BackingField
Append
method
NewtonsoftJsonSerializationJsonStringContract16480asd
Replace
exitCode
SizeOfImage
EndInvoke
BeginInvoke
RuntimeTypeHandle
GetTypeFromHandle
ProcessHandle
handle
lpTitle
hModule
procName
fileName
SystemDataCommonSingleStorage53521tionName
lpApplicationName
lpCommandLine
Combine
ValueType
SecurityProtocolType
AllocationType
Signature
ImageBase
Dispose
X509Certificate
MulticastDelegate
DebuggerBrowsableState
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
TargetFrameworkAttribute
dwFillAttribute
SecurityPermissionAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
ParamArrayAttribute
RuntimeCompatibilityAttribute
set_Expect100Continue
Ringleted.exe
dwXSize
dwYSize
RegionSize
SizeOf
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
xoredString
ToString
GetString
get_Length
AsyncCallback
RemoteCertificateValidationCallback
get_ServerCertificateValidationCallback
set_ServerCertificateValidationCallback
callback
AllocHGlobal
FreeHGlobal
Marshal
kernel32.dll
get_SecurityProtocol
set_SecurityProtocol
System
hToken
hNewToken
lpNumberOfBytesWritten
X509Chain
get_Location
SecurityAction
action
System.Reflection
EntryPointNotFoundException
MethodAccessException
System.Runtime.ConstrainedExecution
lpStartupInfo
lpDesktop
FileHeader
OptionalHeader
StringBuilder
ServicePointManager
GetDelegateForFunctionPointer
hStdError
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
bInheritHandles
System.Security.Cryptography.X509Certificates
lpThreadAttributes
lpProcessAttributes
dwCreationFlags
ContextFlags
dwFlags
System.Security.Permissions
NumberOfSections
get_Chars
dwXCountChars
dwYCountChars
SizeOfHeaders
SslPolicyErrors
hProcess
GetProcAddress
lpBaseAddress
VirtualAddress
ZeroBits
Object
object
Protect
System.Net
op_Explicit
IAsyncResult
result
lpEnvironment
AddressOfEntryPoint
Convert
get_Host
set_Host
hStdInput
hStdOutput
System.Text
pContext
e_lfanew
wShowWindow
nCmdShow
Consistency
stringKey
GetExecutingAssembly
LoadLibrary
FreeLibrary
lpCurrentDirectory
op_Inequality
System.Security
System.Net.Security
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
SystemNetUnsafeNclNativeMethodsWinHttpAccessType5077
DataResDescriptionAttribute51163
JDataResDescriptionAttribute51163nEfGzQBPyY1ETwAHQQxEQ==
FDataResDescriptionAttribute51163XEfUgdeUCAbWUwGHRUtEjQBOyMcHEhI
IDataResDescriptionAttribute51163xsHDjUGJCw0BicGJQJ0Xw==
EDataResDescriptionAttribute51163nEhFDJdDSUaBicDIzR0Xw==
VDataResDescriptionAttribute51163FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUVhemFlc0FBQUFBQUFBQUFPQUFBZ0VMQVRBQUFHd0JBQUFNQUFBQUFBQUF2bjBCQUFBZ0FBQUFvQUVBQUFCQUFBQWdBQUFBQkFBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFEZ0FRQUFCQUFBQUFBQUFBSUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFHeDlBUUJQQUFBQUFLQUJBTlFFQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQU1BQkFBd0FBQUJRZlFFQUhBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFkR3NCQUFBZ0FBQUFiQUVBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQU5RRUFBQUFvQUVBQUFnQUFBQndBUUFBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQU1BQkFBQUVBQUFBZUFFQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB
GCIbVliUxkuu
JDataResDescriptionAttribute51163S0bCTQrHiAiLA0G
FDataResDescriptionAttribute51163nADDg80OzktIz8DHnEfGDVcBSAcLCMMJS4PEQAbVGg=
EDataResDescriptionAttribute51163QQfGzQ7BSAhMycZEgsDFA9ePy8bHEhI
FDataResDescriptionAttribute51163nExFDVePxwhPEAeJQQcXw==
FDataResDescriptionAttribute51163BsHOjRfCmc2LTcMJXEHDjVfJGg=
EDataResDescriptionAttribute51163y0bIDQrESMhWTNFHRUTEjUCO2QhPA07HRR4FDUCAmg=
EDataResDescriptionAttribute51163XADEjIrPwQbBkwfHRsHGAI7PyEaWD9A
EDataResDescriptionAttribute51163XFwURgGOx0iMycgJgsDDg87OxEaWUBFHRshUg==
FDataResDescriptionAttribute51163XEfUgArASwiPDMeFnFwFzIrP2EcKkhI
EDataResDescriptionAttribute51163XFwURgGOwEiMycgJgsDDg87OxEaWUBFHRshUg==
EDataResDescriptionAttribute51163nEfUgArASwiPDMeFnFwFzIrP2EcKkhI
EDataResDescriptionAttribute51163i4fGDI7WDkuLB0MHRQPCQ==
EDataResDescriptionAttribute51163y0bNDQBWD0bLS8FHRstMgwAJzkhWCcFJXF9Xw==
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Ringleted.exe
LegalCopyright
OriginalFilename
Ringleted.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.9f45e62d5df98c83
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee Downloader-FBZC!9F45E62D5DF9
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (D)
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of MSIL/Kryptik.ABNH
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.fz
CMC Clean
Sophos ML/PE-A + Troj/MSIL-RGQ
Ikarus Clean
GData MSIL.Trojan.PSE.1E9KLTU
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/AgentTesla.BNH!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes Spyware.InfoStealer.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ABKY!tr
BitDefenderTheta Gen:NN.ZemsilF.34758.wm0@aCQZvIi
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.211ab7
Paloalto Clean
MaxSecure Trojan.Malware.121218.susgen
No IRMA results available.