Static | ZeroBOX

PE Compile Time

2061-02-16 16:51:48

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000e3f4 0x0000e400 7.45647763448
.rsrc 0x00012000 0x000005e8 0x00000600 4.44944525752
.reloc 0x00014000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000120a0 0x0000035c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000123fc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%)r0
%*rt
%-rN
%2rB!
%6r "
%7r^"
%;r0#
%<rl#
%@r^$
%Cr$%
%Gr*&
%Hrp&
%KrF'
%Lrn'
%Or.(
%Pr^(
%SrL)
%WrH*
%Xr~*
%[r"+
%\r^+
%_r*,
%`r`,
%dr6-
%erv-
%hr@.
%lrV/
%or 0
%srH1
%vr$2
%wrF2
%zr83
%{rn3
%~rL4
% r,?
%!rr?
%$r&@
%%rn@
%,r.B
%-rlB
%0r2C
%3r(D
%4rrD
%8r|E
%<rnF
%?r4G
%@rfG
%Cr.H
%DrvH
%Fr$I
%GrRI
%Jr6J
%KrlJ
%NrPK
%RrpL
%Tr7M
%Wr3N
%XreN
%[r;O
%\r}O
%_r5P
%`ryP
%crKQ
%dryQ
%grCR
%hriR
%kr?S
%nr;T
%orkT
%rrEU
%srmU
%vr%V
%wryV
%zr)W
%{ruW
%~r=X
%"r8d
%#rxd
%&rJe
%*r$f
%+rvf
%.rBg
%/rng
%2r h
%3r~h
%6r^i
%9r>j
%=rVk
%Brdl
%ErPm
%Hr.n
%Kr o
%Lrjo
%Or8p
%Prdp
%Tr0q
%Ur|q
%XrDr
%[r*s
%^r,t
%_r|t
%br^u
%fr4v
%grdv
%jr w
%krZw
%or:x
%sr:y
%vr(z
%wrdz
%{rN{
v4.0.30319
#Strings
<>f__AnonymousType0`1
IComparer`1
List`1
System.IO
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
FileEntryFieldId
Versioned
CreateActContextParametersSourceDefinitionAppid
ReadToEnd
Append
RSAEncryptionPaddingMode
IDisposable
FileSystemAccessRule
CallByName
CallType
Capture
HttpWebResponse
GetResponse
Dispose
Create
WriteByte
get_Value
ToString
get_Length
System.Security.AccessControl
GetResponseStream
MemoryStream
get_Item
System
Boolean
AppDomain
get_CurrentDomain
System.Deployment.Internal.Isolation
System.Reflection
MatchCollection
GroupCollection
Exception
IsolationInterop
StreamReader
TextReader
StringBuilder
IEnumerator
GetEnumerator
.cctor
Microsoft.VisualBasic.CompilerServices
Matches
Strings
System.Text.RegularExpressions
System.Collections
get_Groups
Exists
Format
Object
System.Net
get_Current
set_Accept
System.Deployment.Internal.Isolation.Manifest
HttpWebRequest
MoveNext
System.Text
ReadAllText
WriteAllText
ToArray
System.Security.Cryptography
Assembly
op_Equality
BbBbbbAbebAb@b
bjbBbAbeb
bAbFbqbFb
HmHmHkHlHkHoH
HnHnHnH
sms~sjs
slsnsjs{s
+0nZnYn)nYno
i3i5i?i
i5i4i&i3i5i
-^^A^
].^*^@^
9vevevgvLv8v|vFvgv6vTv:v
vRv{vOv
vPv}vdvqv
vRvSv`vOvRv}v
v|v{vQv
scsfs=
W*w+w)w)wBw=w
v,w/w+w w
rtrprmr
rr#r$r7r#r r.r*r!re
3!3;3y
#)%)N)6))O)N)R)O)$))"))$)
$j$Z$i$I$h$V$i$K$<$h$h$o
o797-7M7'7Z7-7,7
F?K?I?w?y?c?G?y?y?y?y?
SWaW>W&WYWIW!WW!W8W W'WRW
D~D~t~E~~~s~@~w~q~o~x~
 & 
! % 
Y >#> >
Uk0:0b050403020m0g0102060d0407030d0X0y0E060b0W0109020d0\
,},z,d
98B8c8I888Q8F8H8e8h8A8X81848
#D)D,D%DmD*DXDTD$DKDWDZD(D
EzeNeyeNeye
eHeJePehe{eMePeHeIe~eLemezeQe
eNezeLe{eret
;' $ c ' P d [  " $ W
7A<9<w<k<^<?<t<P<:<:<[<n<9<o<k<A<?<r</
X-XBX<X
X@X(X<XNX9X
/,,[,Z,',X,Y,+,),-,o
c{d
[KeGe`eLe|eVeJeIe
eHeweVeYeleHe
eEeKeZeueweDeve
3.3A3"3;3
3;3M3m
S\SYSYSWS~SVS
SXS{Sq
P0&0#0_0g0]0&0#0H0 00V0#0%0&0'0<0S0$0 0
+F1F1u1E1H1s1G1w1}1H1C1
1{1z1f
,4-)-e
+-30313-313P323L323q3_323e
dVdrd=dAdDd=dYd
;z$|$x$|$
$x$w$-
x+y(y*yr
GYheh'h]hqhZh*h\h)h(hlhZhMh]hZhXh9h/ha
Aho>ovoUohoko^o
o:o~oioiojo=oWoIohoyo=o9o=o8o7ohod
V6U6v6h6W6g6
qpk
R,T,:,(,R,#,3,
"X"Y"Y"R"
"Q"x"l"
-!f!.!4!2!>!_!_!
WRWcWKW
k5*5!5
5+5J5@5=5W5
575M525K5+5
5Y5N5K5V5
5N5 5C505`5\5u
OzO[O[O
OfOYOXO
OWOTOe
!g!N!M!~!}!L!t!T!
7k4k+k<k
5p[s[Q[s[r[F[B[i
)#d%d&d%dUd%d$dYd+dVdfd9dh
06010#0
/ 00020
EV)l)?)A)?)
):)l)k)>)>)A):)B)j)A):)j)l)t)7
K{sLsysNsmsNsHs}sGs|sOsysJsJsKsMsJsGs1
&+'5'('
&('<')'
'+',')')'
[3\'\#\#\A
NVMVOVLV$V
VNV#VPVNV$V$VUVaV8VQVQVQV VDVNVAVLV]VUV
S8O;OJO9OiOkO=OjO?O>OhOlO<O9OhO^O7O7OZOgO7OTOh
]U]V]\]]]Z]
]W]q]t
`L`U`K``)`X`I`9`_`J`
`M`U`L`
c't,t;tLtMt(tZt,t7tXtmt'tmt&tetZtUt)t+tJtUtMt$tWtWt*t-tMtk
.3.\.C.
.D.W.E.H.E.
$ ' %
SJSJS<SLS
S?S_S6S
&t&z&{&
WkWjWqWiW
FTbTUT8T8T3TnT9TcTdTPTi
O.!.2.J.
.-..Z.O.!.C.L.".
G:<L<<<:<:<9<?<_<m<><f
-|sTsNsSs~s
sLsTsKsNs~s
b2#2T2)2$2U2R2%2S2B2V2B242T2D2"2
= =K==
=H=Y=I=
=J=I= =A= ==Z=
I{Z~ZPZ{Z
ZPZsZMZKZ|ZOZdZRZ
%I}J}=}y}v}6}X}=}/
3c3`3]3`3
b]bcb$b%b"b4b?b%bRb
9:FtF8FgFjF8FxFZFMF?Fv
e0e'e)eYeFeBe+e
DdDeDrD^DtDdD
hzhOhzhMh]h
D\D\D\D\{\r\F\[\B\D\g\q\
RCRFRCR,RURFRBR
=kxnxlxnxrx
9s9w9q9s9w9
9s9u9v9
9q9x9r9u
a|coc[c
cZcScXcUcrc
cZcScSc
cTcucRc[cwc
cRcucg
868E828
0709080<090N0
23"303
6L:LwLqLdLOLMLkLeL6L7L1LMLvLjLbL3L9LNLfLbL:L7L:LcL
lzlVlslRl
lmlZlblRlWl
-Y<j<Z<*<+<-
9LRbRoRcRcRcRtR9R1R0R1R0R4
=T=TmT?TpTDT=TcTfTmTUT
#|#{#v#
|#})}$}
o2(2.2j2L2+2-2(2f2X2X2&2i2@2&2Z2
*:*3*?*
r~ryr~r
ryrxr8
2.4.6.[.g.d.h.d.f.5.4.5.g.
Y8S83868L848
=e7_7`7
i^iyiVi[i
i[i\iXiVi
U*k7k7k
k6k5k4k
O3P(P%P8P:P
MrMYM[M
MXMlMjM
M[MZM\MsMtM_M
M\M|MXM
MWM|MZM
;Z#]#X#M#x#z#y#y#z#I#P#
{k{T{T{
SLS"S6S
= j?jAj
j1jLj.
o'p&p(p
o%p1p(p
/m%C%r%
%C%n%o%B%o%<%A%D%e
}v}w}i}l}
}h}d}e}
W_*_X_+_U_(_<_)_Y_A_c_B_$_&_
+sHs%s]sms`sXs-s%s's+sEs+s
Cc#!#[#%#!#_#&#"#
#G#'#B#"#%#&#/
G-K0KOK[K\K-K=K)K@K1K=K0K)K,KPK\Ke
7-"("-"X"["+"Y"e
"xVxIxGxTx?x&xr
1<1L1 1
1I1^11;1
1B1^1M1K161V1
1Q1-1r
5T0T0U0Y0X0W0U0
&m&o&n&
GYQ(QWQIQXQ-QoQ[QcQ%QVQlQi
OouuukuYuUuWu
)iVjViVhV
VjVcVaVbVr
/VS!S'S"STSgS$SRS#S>Se
KDzozDz
zDzDzqz?z`z-
p.q-q.q
Ir@rnrkr_rmrWrurkr@r<rkrYr
CF"s"\"I"A"A"G"-
=7=3=G=C=
=@=3=4=
QN:N8N<N;NlN<NfNfN;N<N;N4N
:qiq5q:qqqgqeqiq=q5qUq<q:q
e434J4`414c4b4c474b4
INW_WQW0W6WqWiWUWaW5WdW`WfWaWTWE
!F!v!g!G!F!E!
!I!H!e!
!F!M!L!M!
xTxXxYxjxYxnx
W4747484749424
] ]*])])]
@#@"@C@@O@Q@!@"@d@$@
@!@4@#@!@!@M@"@P@8@"@$@/@
@M@P@"@Q@%@`@
252=222
"M"~"e"S"
"L"R"P"M"U"R"U"d"T"h
M$5
uoupunutuqupu
uqururu
5lGgGkGl
17=g=v=5=3=F=G=r
[yWyVy
yxyWy^y
^RKRrR[R0R[R@RoRZR.R[RYRKR^RAR
)&)$)3)
JqJ^J\J
`A~A_AwA
A_AaAbA
A`A\A`A
~B}B}B
ByB|B}B}B
cnclcnc
iWqUq&qTq#q'qTq"qTqiq`qXqUq#qfqSq)qbq*q/
MTt&tXt:t+tCtgt+tYtXt#t)tTt)tTt=t7t]t>tGtf
\#'#(#"#'#V#L#T#*#W###+#X#=#W#X#)#
~?n?P?
o=c=4=K=3=5=4=l=3=;=
hQhOhUh
hQhOhVh9
$6%)%!%"%
B}B}^}?}m}p}C}R}O}
-&ZOZ\Z&Z)ZVZ&Z,ZXZ.Z%Z6
*q/qWq-q<q(qlq+q&q,qZq?q
9jGlGmG
GhGoG0
DEDnDzDJDhDuDaDED
?0j0l0?090o0:0j0A0:0j0:0B0j0
0<0A0A0?0?0c0k0
_sKFKwK~K[KCKsKfKKKFK
KwKJKtKsKIKUKvKZK}K6
>AbAUAWA*ATA6A*A$ARA*AFA&A
7 K 1 J d a 9 o 5 1 c e 3 8 1 w 1 O c 2 4
-w<5<9<Z<o<8<g<7<6<f<E
Fz?zqzEz{z^zqz
zFzqzBz
?FaGapapaCaraBa}a^ayat
CbD.DuD_DpD2D-D_D5D^D-DADgD-DJD.D1Do
x.\.]._._.x.
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGX
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}{43}{44}{45}{46}{47}{48}{49}{50}{51}{52}{53}{54}{55}{56}{57}{58}{59}{60}{61}{62}{63}{64}{65}{66}{67}{68}{69}{70}{71}{72}{73}{74}{75}{76}{77}{78}{79}{80}{81}{82}{83}{84}{85}{86}{87}{88}{89}{90}{91}{92}{93}{94}{95}{96}{97}{98}{99}{100}{101}{102}{103}{104}{105}{106}{107}{108}{109}{110}{111}{112}{113}{114}{115}{116}{117}{118}{119}{120}{121}{122}{123}{124}{125}{126}{127}{128}{129}{130}{131}{132}{133}{134}{135}{136}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}
{0}{1}{2}{3}{4}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}
{0}{1}{2}{3}{4}{5}
VS_VERSION_INFO
StringFileInfo
040904e4
ProductName
Ad Muncher
FileDescription
Ad Muncher
CompanyName
Murray Hurps Software Pty Ltd
LegalCopyright
Copyright
Murray Hurps Software Pty Ltd
LegalTrademarks
a9729ddf 8a39 41d0 9473 cf78548f0dc9
Comments
b58578a0 3fc5 4a48 a2e8 4f6ec9731a3a
de0e7e7e-f9a3-4a00-bbb6-7381888bb9eb
VarFileInfo
Translation
Antivirus Signature
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.d83c2c4caf2fa8d3
CAT-QuickHeal Clean
McAfee Artemis!D83C2C4CAF2F
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.MSIL.Stealer.l!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.34790.dm0@airtctmi
Cyren W32/MSIL_Kryptik.ECN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.IFL
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/Kryptik.799a8347
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_92%
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Bomitag.D!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet MSIL/Agent.IFL!tr.dldr
Webroot Clean
Cybereason malicious.90782d
Paloalto Clean
Qihoo-360 HEUR/QVM03.0.531B.Malware.Gen
No IRMA results available.