Static | ZeroBOX

PE Compile Time

2063-01-17 23:52:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000085e4 0x00008600 7.36112318739
.rsrc 0x0000c000 0x000005b8 0x00000600 4.09829613722
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000c0a0 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000c3cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%$r<
%(r,
%)rH
%*rl
%2r,"
%3r`"
%6r:#
%7rh#
%:r*$
%;rj$
%?r6%
%@rt%
%CrX&
%FrL'
%Ir6(
%MrR)
%Pr<*
%TrJ+
%Ur~+
%Xrb,
%[r<-
%\rp-
%_r .
%`r`.
%crD/
%gr>0
%jr.1
%krz1
%mr&2
%nrj2
%qr,3
%rrp3
%ur64
%yr25
%zrp5
%}r(6
%rx=
%"rh=
%#r|=
%&r|=
%(rt=
%*rL=
%+rd=
%-rt=
%.rP=
%1rH=
%2rt=
%3rL=
%4rd=
%5rL=
%7rt=
%8rp=
%9rt=
%;r|=
%<r\=
%=rt=
%>rH=
%?rH=
%@rP=
%ArH=
%Br@=
%Cr|=
%Drh=
%Erl=
%Frp=
%Grt=
%HrH=
%Irx=
%Lrh=
%Mr|=
%RrH=
%Srt=
%Tr|=
%Ur@=
%VrP=
%Wrh=
%Xr\=
%Yrh=
%Zrl=
%[rL=
%]r|=
%^r|=
%_r\=
%arP=
%brh=
%cr|=
v4.0.30319
#Strings
WhenAllPromise`1
List`1
Microsoft.Win32
System.IO
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Versioned
ReadToEnd
Append
IDisposable
CallByName
CallType
Capture
HttpWebResponse
GetResponse
Dispose
Create
WriteByte
get_Value
ToString
get_Length
System.Security.Util
GetResponseStream
MemoryStream
get_Item
System
Boolean
AppDomain
get_CurrentDomain
System.Reflection
MatchCollection
GroupCollection
Exception
StreamReader
TextReader
StringBuilder
Partitioner
BitConverter
IEnumerator
GetEnumerator
.cctor
UnsafeNativeMethods
Microsoft.VisualBasic.CompilerServices
Matches
Strings
System.Threading.Tasks
System.Text.RegularExpressions
System.Collections
get_Groups
Exists
Format
Object
System.Net
StringExpressionSet
SharedInt
get_Current
System.Collections.Concurrent
set_Accept
System.Deployment.Internal.Isolation.Manifest
HttpWebRequest
MoveNext
System.Text
ReadAllText
WriteAllText
ManifestEtw
ToArray
Assembly
op_Equality
!m3mcm*mTmUm*m*mWm7m$mRmUmXmVm%mYm*m*mUm
uOuIuLuQuPu{u}uzucu|u|u
@w@w@|@x@y@w@t@
@|@z@w@|@
9kPKP8P?P<P6P;P{P6PlP?Pt
71a_aOa]a1a-a[a)aj
_TCzCSC
CTClCRC
CsCbChC
i\i^i`i\i
rNrMrKrLrPrTrMr:r[rLr!rbrNr
3Q3D3G3E3
[s[K[F[_[e[u[I[|[x[
{${2{N{0{
* D ] Z + - , ( [ / . * +
.2N2"2R2$2-2
?|?S?J?]?|?R?
?d?|?~?m?
?L?R?|?L?
?S?O?f?
@>@=@@@
@?@H@@@
C?#8#;#=#>#S#<#_#k#<#x#:#@#m#\
STSeSmSVS
SVSSSTS
bVbZb[bXbVbZb
bWbdbTb)
A}AkAmAlA
AgAiAkA
CuCu=u:unumuCuouBumu^uBu
}LmLgL6L>L^LlL?L
=v=v=:
gmgmgtgtg
gsgqgqgvgtg
--.'.*.2.*.).
zAzEz@z=z
z/zBzLz
<3g3F3G3o373y3h3r3
sWsIsHs/s
sJsPs=s0s
sIsIso
?N?N?R?J?
?M?b??\?
"j"h"p"
6*6(6&6
5)656)6
6;6(6'6
-|-t-t-
m?q?q?p?
?h?|?{?o?k?
hb^b}b_b_bvbsb
bVbYb_b
b^b]b\bjb
2BEB'B
B/B0B B'B6B
5+*0*2*4*0*o*3*n
#X2XX2XOXBX^Xe
'1S@S7S7SUSwS4S/ScSdS/
OsORO[OYOt
#;U;(;,;,;+;
PsPoPsP
0 : ,
>v>]>_>~>w>^>w>G>G>v
G~EHEyEGEOE|EzExEPExExE^EyEIEeEKEgEzEKEe
OkOVOYO
J)J;J*J
X3X6X(X
+x+z+}+
(p(g(h(
5Ks{sbs|sIsNs|sbsesKs
sGs{sGsr
3Vr`r*r&rVr)r#rVr"r)rJrTr8rWr-
;jijwj=jtj=jejQj<jhj
5u5p5o5u5
H%HFHVH2H
[x&c&I&z&M&{&z&N&L&M&{&z&F&\&w&N&z&{&J&x&v&M&y&i&E&i
asWsNsas
sTsRsOsRsRs
sosQsosNs
@*@;@&@
?*@'@*@
+9+9+)+;+;+7+
Z|s|H|~|r|s|p|?|s|r|
Mb?a?4?b?a?,?.?5?.?_?A?/?j?a?_?m?b?n?,?4
Q'QFQ3
*m*\*`*`*
`{`w`u`
`T`]`]`Z`
`z`X`]`
%Q@J@]@Q@N@
7y7[7n7T7E
)s)])])
/#)Zj,]#VW(+&+1
)BXB+BaBHBcBXB
Y4F4$4M4f4
4#4#4T44#4%4c4O4
4U4R4P4O4
Z|!|&|%|!|H|)|V|Y|T|!|%|W|;|!|4|"|T|T|!|
SB)B)B=B$BRB BSBQB
g6h63676S636Q6m6<686\6g6]6G6
;`][]/]+]3]^];]1].]]]i]1]n]/]m]_].]/
gRgIgFgEgHgFg
#QQMQ:Q
QMQ QKQ6
2[2`2s2
slhl,l+l^l`l4l]l=lel0lrl
+P+P-PmP.P_PAP.P1P1P3P1P1P3P+P*PfP
e\eSeVe
f?Z?-?\?]?+?^?m?_?_?2?2?1?]?_?
?(?$?6?
+o*o&o<o`o,o.obo'oWo*o
;n{={o{
{F{z{p{r{Y{A{s{r{n{E{n{p{>{z{1
2a2a2X2
2`2_2X2`2X2
M|MwMb
FvFwFpFqF
FrFoFnFrF
%|#|$|
|"|%|8|&|"|
+l+}+u+
OPOMO_OoOOOVOiO
OvOMOROsOy
zTzlzcz[z
zRzSzRzqzZzYz[z
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
b+$n2z
6009Yi971
koWt73VM1sf1eltAffh1
idc9WpG8Pn9Na981&0$
f270edZaeTq8010m1fewe8810
e0r0636Efdb6fdf69iX90a1
h9aceN1a1(0&
Cc7c7b7TUfye0f60Kb9el34A9u9e7ec1
i9dAW7Lfe440
210701205808Z
220701205808Z0
6009Yi971
koWt73VM1sf1eltAffh1
idc9WpG8Pn9Na981&0$
f270edZaeTq8010m1fewe8810
e0r0636Efdb6fdf69iX90a1
h9aceN1a1(0&
Cc7c7b7TUfye0f60Kb9el34A9u9e7ec1
i9dAW7Lfe440
M3wyY|
6009Yi971
koWt73VM1sf1eltAffh1
idc9WpG8Pn9Na981&0$
f270edZaeTq8010m1fewe8810
e0r0636Efdb6fdf69iX90a1
h9aceN1a1(0&
Cc7c7b7TUfye0f60Kb9el34A9u9e7ec1
i9dAW7Lfe44
b+$n2z
20210701205809Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210701205809Z0+
/1(0&0$0"
@1}Nt&1
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}{43}{44}{45}{46}{47}{48}{49}{50}{51}{52}{53}{54}{55}{56}{57}{58}{59}{60}{61}{62}{63}{64}{65}{66}{67}{68}{69}{70}{71}{72}{73}{74}{75}{76}{77}{78}{79}{80}{81}{82}{83}{84}{85}{86}{87}{88}{89}{90}{91}{92}{93}{94}{95}{96}{97}{98}{99}{100}{101}{102}{103}{104}{105}{106}{107}{108}{109}{110}{111}{112}{113}{114}{115}{116}{117}{118}{119}{120}{121}{122}{123}{124}{125}{126}{127}{128}{129}{130}{131}{132}{133}{134}{135}{136}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}
{0}{1}{2}{3}{4}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}
{0}{1}{2}{3}{4}{5}
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ConsoleApp1
FileVersion
1.0.0.0
InternalName
ConsoleApp1.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ConsoleApp1.exe
ProductName
ConsoleApp1
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren W32/MSIL_Agent.BZW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.IFL
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/Kryptik.a5bcd047
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34770.cm1@ayh3YPg
AVG FileRepMalware
Cybereason malicious.83cc4f
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.