Static | ZeroBOX

PE Compile Time

2021-06-21 13:46:42

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000443d4 0x00044400 7.64611709128
.rsrc 0x00048000 0x0000054a 0x00000600 3.97396605132

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000480a0 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00048360 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
D/d:12
xU;Fz(%
j &fU^
0J#Xgg
&iLKynQ
pxiHaA
`mSu-w
6gRwINGn
~Z[7!y
xB\+Y;L
99HUzC*
6aZ;?=
Ih[-K3J
A9s.XE
)l}v*0|
q~K]z'
rp=;qR
_ia\C!I
ADu0Sq
JOSZ v
jYNy28
HC"bq)
I:UI1!dq
!M3YKxS
0e0/wK
J*gQP<
w,PW%
\;[)&&
nY^}cR
FzM[q#
C9,dC}
(c`%TR
CO*Lvz
zpP.O;
P-<w-pDJMB
bS`V$`
bT=k:;
s*][G[<g
wliqdi
l9ELJW
(#3$=G
+o?nO)
EwArsD
t#kLc(
bsc>xy
*)qX+>H
et DSD
mR7oO}K
AeV0h|
giQMBJN
53FYWT
n0\~}_
dH>aV*{
5Q`o{3
tro+QM
~d+d|&m
qK\C/ B
|z{=E8
!A7kI#
<'r9Rr
QUYY%#
yU`g56-q%h
PvdN*2
O3)+GL
d"1G]9
"Y"}uoj+4
'|:Pa+
-%`bjv
0|D`w6
p7m8GY
_K_E]
!f-9jy
v#;"=k
De_"tL
}g*"(a
.bDT}l'
wL9F&d
#~GL%M
ELn>O7
^<@=8fZ2z
/ljX>?
:C?]f
)XdG7P
}8_Euj_
%=]<YT
]4AE/8
/QArm}
$L7`s
x*Zt\0
}5)7UU
0`l/<5
[.(i)#
wsT;<bi6}P
+sH?8j
|T{03,
5mE J !!bS
sR8+K#
'h*~Q %
=i0~I:V
Em;-2y
F?lE$x)N
)M9:V,
\=i,i`aTBW
@\cEao
RHJ*l|
voX4l/XW
v)v3Rn=1
&Y\:aec*
i3d fh4`
;GwfFS
w=@3u5
[57k,U
jBH9\i
/CYNDA
iWLz/"
Wu7:1D
MLi+<1
Icw_}G"j
1Pc}u>B#
3P7n!pJ
Y(JPz;N
-A|>|^s
<W1]OmX
Mn^|Mf
gb9{Db
d:K7Wu
$qIV@T(`
`%%Q\U
vK3I\-
5=^9`ydv
^9<ntT9
Rewp=/)Z{sRyur?
tp`s1g
=j4z`
'qQV|c
TdcAM@=
D*K|a11S"
fuE}l
!%@Vgt
+*k^k
W$n0Am
h<`a3=b
rRTzN]
Z8Z3gAy
K7E>fa
zCrY?t
7e'OK-
vtET1y5
rUrjRM
5h][zf
&^Lx^eq
v?@O2X
u%3}wT
V8O&LV?
[!Y2^/
Qzl8\J
G%!K@KW5<
psA{u:SW
x9moV/
B9#k/5
#:ed/0$
BOrs6L/r
k8}y@3xV
<$vC:4
/b&=M1
6D5o%GJ3
a[DT[|
!)drF1
`hEo!y
H J,[]+
??km6
bLylAn
/=kWGvL>^
0C0 8h
,^r!k*
)<#.2.$
EiH_dg.
wAnc(X
?i?\a?
}R+?e !
f'|eV\
EH:K\G
~t<.t|(Cn
XbIU,3
/~k".J
&LG7GDOl
<(MyS}
Bl+Bw*%
{hA;j!?
8KkISn
gKrD8Qg
{?}P4c
}+V~x(r`
SGgEH[I1
`Af55k+
jCW~lDG
hf6G(A
!i&| eR
15F`Vqa
t,j{q%
"hvgi$
;`[)d#
c`W"d!%8
o/%aiE
o:;hJw
sp>(yc
Bea{QU
ilHt2)
'10/6-
k#ukF.
oQ|DY
t!bH)]hO
k".Mu$
0qu[L1g
d$(Iyo
{K.bq!
cq;}AM
?'ZG*Q
(1&(F|;7
(mTm#V
k[~Q@w
.3^&si[
5Q6sWS
|3SXf]
7"QPOF
5X@ai$
ZHpdW
h{Ed!2
-Dd^6,
#aQ"Vo
[NH8 4trJ
j,NzA,:
5P@-Qa
2R]8UN=V
@8B[OO
;*>s/4
m`~[!S'
~i[q&W
Ip6f=rZi
-Yo}-4DA!
wC"8-y
So],v+
Q!#KJ"
9M{489b0e
p!Z$5~v
FaRwD@
JAIPLa
cvPg8~f'VLn
])Ag_j
tiXE;zc^#a
XVeLy
ysI;DILw
;@o#MI
XnL@}g
QKSY}m
8f.yt1:
_,'E:|#
/;|F>op
]zl<R_
AnfmPa
# qm)n
0hASM>
u(~^Hx
}ZUNHd&
.[LUN/D
6M<+A(Z
0`3mjYo
D%r8lL
gsd-$P
K/A7!.
tk>_h#
0c?Mkz
{jc`zhd
L~EH%N
$FEyL&dC
x#$gU`
|N9x"O
+|k?*q
h37Aw9
]YcnV/"
Q~\F5O$=T1T
]HW9eM
hM$9K7
pt4 r%
;w}D>\
ZD/)z$
|DiTw7b
(nj1AY3
,^&z4h
vFDGUDE
f-MtSH
mdFg-+
$KT23I
7&V-J/mkd8J
M%h%Mm
vdW;}E
cb&bGe
tWI!EdrW
EBa&eMg
&\KzfVaM
ZJ:xF0~
L9#_"i
1N*hP
*CGa9a
YrzK=G.
{D7R>A
*}LdM
h:'=AV
y[z)eK
WfmyPB
EC *B'K
L7/@cO
>w_0Kj
RI]&E.,
31!&?(4
{JB%N3
@Z~= +
]Bu":5=
%qbB=C
T3OK#{
?rblQi
(=a2Bn
34l{$i
WfBN&5
1B-+`I
u+Aza.
gE"cZf(
/V%T5K
ObS"2g
5=>=;?
9zFJ}b
<{Y@o?
@_8bT
nJj9NC
)3y{kK
"6NHE.
eAQ#W}
!8A~?h
uKDaEI
4"Jv==#
#}[ri=?
"wIx}J
Os}D&"
<gaG0p
MUg|#n
z3A*4l|
L&A+vW
(kI`E/{
aZu1Rr
*uCPU,
,Tu%8uH
X$8}#ZnYa}
^M-Sl&wCT
jDl\?_
T(/Zq*
$#05k]Y<QF+;
.NO!7C
_-*rw\o
a3N}9.6
SACut?
KU<a8r
$sEa8:
NtCoT
X ntinT
R4Z C
(XGR %
5=Za8<
9 4W7gZ
ZZ {|t
X ntinT
)_EZ f
t$fZ 0
F7Z 'FE0a8
X l.dlT
-\6v%&
ntdlT
-iIZ Q
9 iC%%Z
ntdlT
9 "(v|Z :Zx#a8`
X l.dlT
&Z M{H
9 +`H?Z 1o@
OcXa8i
NtCoT
4jZ }~
fhRZ OS
ywnZ "<"
Z?_b`
/ll #V
1:3tZ
2z'%&8
n(h-Z !?
Z E;&!a81
Z gK6Ya8,
F7Z o"W
?fV1Z
_bj2
_bY*
xTT%&+
DFmk%&8
5e#Z
T Z <IN
B9Z BR
;>Ka8]
m]Za8@
E`xZ Hj
Z_bX
c=-a8
<nZ &a
{:Z ` r
'AUEZ T
N]<Za+
Z ^0S|a8
fR=2Za8
7:\vZ
Y_cX*
<:&k
$O~X%&+
%jC%&+
:Qoa8N
7: ILIT
NNEZ Is|
*:z:
0m8vZ G
E.=8+
?a3W+
1qm)+
QqV$+
krmT+
AMqBZ
krmT+
j?%&8w
kP#Z
Q*ZWZ
Z :ZFya+
v4.0.30319
#Strings
#Strings
#Schema
List`1
UInt32
Dictionary`2
get_UTF8
<Module>
GetHINSTANCE
System.IO
uIlbEkxjdKmqwCjHvqfsAbTpaMpU
value__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentThread
SHA256Managed
get_IsAttached
set_IsBackground
GetMethod
Notice
CreateInstance
GetHashCode
ZipArchiveMode
get_Message
Invoke
IEnumerable
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Module
get_Name
get_FullyQualifiedName
get_FullName
DateTime
Combine
ChangeType
ValueType
GetElementType
MethodBase
ApplicationBase
Dispose
EditorBrowsableState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
GetObjectValue
ZipArchive
get_IsAlive
add_AssemblyResolve
dtkYSds.exe
Serialize
System.Threading
NewLateBinding
Encoding
IsLogging
Warning
FromBase64String
CompareString
ToString
GetString
get_StartupPath
GetFolderPath
get_Length
Critical
Marshal
ConditionalCompareObjectNotEqual
System.ComponentModel
LateCall
kernel32.dll
MemoryStream
System
Boolean
TimeSpan
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
Application
System.Web.Script.Serialization
System.Reflection
get_Exception
add_ThreadException
add_UnhandledException
Intern
MethodInfo
DirectoryInfo
StringBuilder
SpecialFolder
Buffer
ResourceManager
Debugger
ResolveEventHandler
ThreadExceptionEventHandler
UnhandledExceptionEventHandler
System.CodeDom.Compiler
ToGenericParameter
Computer
JavaScriptSerializer
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
IntPtr
System.Diagnostics
dtkYSds
FromSeconds
get_TotalMilliseconds
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
aEdlcvdMpbIa8EiHyi.resources
ReadAllBytes
WriteAllBytes
GetBytes
ResolveEventArgs
ThreadExceptionEventArgs
UnhandledExceptionEventArgs
Equals
System.Windows.Forms
System.Web.Extensions
Conversions
System.Collections
get_Chars
RuntimeHelpers
Operators
Concat
Format
ConcatenateObject
get_ExceptionObject
GetObject
VirtualProtect
LateGet
LateIndexGet
System.Net
op_Explicit
WebClient
Environment
get_Current
get_EntryPoint
ParameterizedThreadStart
Convert
FailFast
GetWebRequest
set_Timeout
MoveNext
System.Text
get_UtcNow
LateSetComplex
InitializeArray
Emergency
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
CreateDirectory
ZipArchiveEntry
op_Equality
1.2.3.4
WrapNonExceptionThrows
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.2.3.4
InternalName
dtkYSds.exe
LegalCopyright
OriginalFilename
dtkYSds.exe
ProductName
ProductVersion
1.2.3.4
Assembly Version
1.2.3.4
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37132346
FireEye Generic.mg.2afd27e1cdcc4289
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee Clean
Cylance Clean
Zillya Clean
SUPERAntiSpyware Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057cb891 )
Alibaba Backdoor:MSIL/GenKryptik.aa9ee665
K7GW Trojan ( 0057cb891 )
Cybereason malicious.7016ff
Baidu Clean
Cyren W64/MSIL_Kryptik.DJR.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/GenKryptik.FFJK
APEX Malicious
Avast Win64:Malware-gen
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Mokes.gen
BitDefender Trojan.GenericKD.37132346
NANO-Antivirus Clean
Paloalto generic.ml
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37132346
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen9.48175
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Trojan.GenericKD.37132346 (B)
SentinelOne Static AI - Malicious PE
GData Win32.Trojan-Stealer.FormBook.PWLKG6
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Trojan.GenericKD.37132346
MAX malware (ai score=85)
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Backdoor.Mokes.Hvjx
Yandex Clean
Ikarus Trojan-Spy.Agent
eGambit Clean
Fortinet W32/Mokes.FFJK!tr.bdr
AVG Win64:Malware-gen
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Clean
No IRMA results available.