Static | ZeroBOX

PE Compile Time

2063-01-17 23:52:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00007574 0x00007600 7.32227427149
.rsrc 0x0000a000 0x000005b8 0x00000600 4.09699405389
.reloc 0x0000c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000a0a0 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000a3cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%-r;
%1ri
%5rE!
%6ro!
%:rY"
%=r-#
%>rq#
%BrM$
%Cry$
%Er/%
%Frm%
%Ir%&
%JrY&
%Mr7'
%Nr['
%Rrc(
%UrM)
%Yr;*
%\r)+
%]r_+
%ary,
%drc-
%gr7.
%hr_.
%kr7/
%lru/
%or!0
%pri0
%tr11
%urc1
%xr12
%yr}2
%|rG3
%}r{3
%rs:
%"rc:
%#rw:
%$r{:
%&rw:
%(ro:
%*rG:
%+r_:
%,r{:
%-ro:
%.rK:
%1rC:
%2ro:
%3rG:
%4r_:
%5rG:
%7ro:
%8rk:
%9ro:
%;rw:
%<rW:
%=ro:
%>rC:
%?rC:
%@rK:
%ArC:
%Br;:
%Crw:
%Drc:
%Erg:
%Frk:
%Gro:
%HrC:
%Irs:
%Lrc:
%Mrw:
%Nr{:
%RrC:
%Sro:
%Trw:
%Ur;:
%VrK:
%Wrc:
%XrW:
%Yrc:
%Zrg:
%[rG:
%]rw:
%^rw:
%_rW:
%arK:
%brc:
%crw:
v4.0.30319
#Strings
List`1
System.IO
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
Versioned
ReadToEnd
Append
IDisposable
ThreadPoolBoundHandle
CallByName
CallType
Capture
HttpWebResponse
GetResponse
Dispose
Create
WriteByte
get_Value
System.Threading
ToString
get_Length
System.Security.AccessControl
GetResponseStream
MemoryStream
get_Item
System
Boolean
AppDomain
get_CurrentDomain
System.Reflection
MatchCollection
GroupCollection
Exception
StreamReader
TextReader
StringBuilder
LegacyEvidenceWrapper
CrossAppDomainSerializer
IEnumerator
GetEnumerator
.cctor
Microsoft.VisualBasic.CompilerServices
Matches
Strings
System.Runtime.Remoting.Channels
System.Text.RegularExpressions
System.Security.Permissions
System.Collections
get_Groups
EnvironmentPermissionAccess
Exists
Format
Object
System.Net
get_Current
set_Accept
System.Deployment.Internal.Isolation.Manifest
HttpWebRequest
MoveNext
System.Text
ReadAllText
WriteAllText
ToArray
System.Security.Policy
Assembly
IEntryPointEntry
op_Equality
RegistrySecurity
!u!q!n!
^h#h\h!h#hTh#h#h$h4h!hfh
SOSVSUS
SRSMSVS
^l^g^i^h^k^t
BGBOBHB{B
BGB{BxB|B|BLBIBXBaB
BoBJBxB/
o6%;%q%d%N%U%5%d%Q%{
-i/i*iSi2ibi,iHi2i^i0iGi
7"7"="
";"$"<"
u~u{uzunu
unuqunumu
5*`^`+`3`.`]`\`r`.`p`^`m
p9]9^9_9]9
;8;K;>;
'+iTi.i,iy
;XPNPfPgPjPJP6P9P;P4P;P4P8PwPLPFPKPr
C\cnc=cxc<clctc~c=cAcrcAc;cd
==9o9>9B9S9>9W9
9n9R9>9=9b9?9P9s
B,C,y,
,S,C,s,F,q,
,C,i,A,S,?,
,d,a,p,H,F,E,a,G,@,
,],R,H,
hch`hch[h
h~h`h^h
hrhxh[h
G80h0<0k0G0i0r0605050>05050K0=0g0n
P$F$"$!$6$[$@$4$
>J>8>G>
}[}Y}\}
}]}]}y}
xSxPxtxRx
~W~o~V~Z~Z~W~
~g~_~\~
~W~h~[~^~
M5"h":"g"6"="6"h">"g"H"6"f">":"9"9":"8"M"]"6"6"o
=lOCO]O)O.OrO+O)O-O)O*O-O)O*OjO1OZOi
m1m#m-mm
K$y$l$p$L$J$
9P9e9o9T9O9
Kc~b~0~8~B~2~b~4~0~X~1~d~C~8~i
/p?>?;?l?t?a?
?;?l?M?r
{zqzPzLz}zKz
=\PQP!P
PaP7PMPNP$PMP#P#P[P?P$P#P"P_P"Pp
v\vTv\v\vWvTvyv
vUvYvXv
QoQqQtQ
QrQqQpQ
QlQnQmQ/
LQQQMQ~QNQOQ_Q
QdQOQQQMQ{QLQ
?7&=&F&F&
&J&H&G&
#=#=+=&="=F=T=[=F=%=+='=(=+=*=H=c=
1yVIV{VXVJV
VOVyVyVGV{VLVlV
VxVzV/
)n)n)e)l)f)
*YVY%YXY&Y<Y(Y%Y]YbYTYkY
G C | A B e _
C`E`s`>`@`A`{`p`
Y)Y@YKYf
=x=w=x=t=u=
G\u1u=uLuhuiu-u.u-u[u)u.u`uDuPur
O,P_P<P\P@P.P,P-P3P.P\P/P[P^P]P^PFP+P^P-
:]:Y:r:g
'$8;8!88d8=8P82
Gbg1g2g1gfglgfgNgxgdg4g3g6gbg7g3
~m~h~f~
^^Z^O^P^
^^%^W^$^P^O^
^&^7^"^N^A^f^
gab
-%i,iZi9i,iIi-iViViJiXi-i^i4
$xax&x%x"xIx!x(x
i02S2O2
2>2!2 2S2!2U222
2C2A2;2O22N2F
9(8(h(=(
(6(q(h(5(N(6(6(5(T(:(T(U(6(l(g(6(6(5(g(~(>(g(l(f(k(y(9(9(
W(WHW.W
WUWHWKW
KvKnKsK
KvKqKrK
O,O/Oh
qGq-q'q(q
q>qIq1qt
+$+(+S++S+'+Q+
,3C3W3
3V3L3D3N3D3
TwTzTuT
TzT{TrT
[$\#\1\
\$\&\7\
1{>9>:>:>g><>\>7>5>f>|>4>0
>"?7?3? ?
lvldljl
lelblcltlble
SkC$C%CKC&C%C$C%CMC%CLC*C-C%C%C)C$C&C(C(C,CUC$C%C$C$C'ClC:Ct
gO4OHO:O<OhO:O3O9OpO5O
VVVZVWV
34_0_._,_^_4_/___T_]_a_-_0_1_S_i
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
fqlan1Law91Pk6b61:08
16d9c541fDb8fe52gL81YXdJR6n85ygcD397p950D04v2R5UB41-0+
$y1Z09dK1ai4bT83z52ZRQn0u654g024sh5Z61"0
c4Uu01cNKc9dbt0tVJ41806
/fcf8J82Hb9oTB8faQ0f58faKScRf16awyzODbfd1djSb5471301
*b7790q6T7pb7F0I6eMR51ae6F4i1bnVok7ecxj58bF1907
0960ef60814f155b1ubcf30ud4acgbUDKha40eb14z09647i91
bvPJY49Rbb5c69j4hf70
210701210154Z
220701210154Z0
fqlan1Law91Pk6b61:08
16d9c541fDb8fe52gL81YXdJR6n85ygcD397p950D04v2R5UB41-0+
$y1Z09dK1ai4bT83z52ZRQn0u654g024sh5Z61"0
c4Uu01cNKc9dbt0tVJ41806
/fcf8J82Hb9oTB8faQ0f58faKScRf16awyzODbfd1djSb5471301
*b7790q6T7pb7F0I6eMR51ae6F4i1bnVok7ecxj58bF1907
0960ef60814f155b1ubcf30ud4acgbUDKha40eb14z09647i91
bvPJY49Rbb5c69j4hf70
g9b"|\
fqlan1Law91Pk6b61:08
16d9c541fDb8fe52gL81YXdJR6n85ygcD397p950D04v2R5UB41-0+
$y1Z09dK1ai4bT83z52ZRQn0u654g024sh5Z61"0
c4Uu01cNKc9dbt0tVJ41806
/fcf8J82Hb9oTB8faQ0f58faKScRf16awyzODbfd1djSb5471301
*b7790q6T7pb7F0I6eMR51ae6F4i1bnVok7ecxj58bF1907
0960ef60814f155b1ubcf30ud4acgbUDKha40eb14z09647i91
bvPJY49Rbb5c69j4hf7
xm7h[7
HW*~qG
20210701210155Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210701210155Z0+
/1(0&0$0"
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}{43}{44}{45}{46}{47}{48}{49}{50}{51}{52}{53}{54}{55}{56}{57}{58}{59}{60}{61}{62}{63}{64}{65}{66}{67}{68}{69}{70}{71}{72}{73}{74}{75}{76}{77}{78}{79}{80}{81}{82}{83}{84}{85}{86}{87}{88}{89}{90}{91}{92}{93}{94}{95}{96}{97}{98}{99}{100}{101}{102}{103}{104}{105}{106}{107}{108}{109}{110}{111}{112}{113}{114}{115}{116}{117}{118}{119}{120}{121}{122}{123}{124}{125}{126}{127}{128}{129}{130}{131}{132}{133}{134}{135}{136}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}
{0}{1}{2}{3}{4}
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}
{0}{1}{2}{3}{4}{5}
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
ConsoleApp1
FileVersion
1.0.0.0
InternalName
ConsoleApp1.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
ConsoleApp1.exe
ProductName
ConsoleApp1
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
SUPERAntiSpyware Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Trojan:MSIL/Generic.99e54a8c
K7GW Clean
Cybereason malicious.239b5d
Arcabit Clean
Baidu Clean
Cyren W32/MSIL_Agent.BZW.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.IFL
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
Paloalto Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
eGambit Unsafe.AI_Score_98%
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
AegisLab Trojan.Win32.Malicious.4!c
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34770.cm1@aC2!b8b
AVG FileRepMalware
Panda Clean
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.