Static | ZeroBOX

PE Compile Time

2021-07-08 03:14:16

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000191e8 0x00019200 7.59230479946
.rsrc 0x0001c000 0x000005f6 0x00000600 4.24833773539

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001c0a0 0x0000036c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001c40c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
d,{EBb
eMcZrmuM
;Tpp3F
+~J-/b
|'s?@o
2GOL<G
[H@s,"
@3}GB#)I
oZ"0?,
U-HEB$;
Z9(h>%$
^WAm#}:
:09D}ly
}h 1|8
K~h=Or
t%P~qSy
jH|^]O[;f
iGkobq
J\A!S7q
Uu&<s;m:
\vM"y/
XAR8u+
e2=2 N
g4khH:MN
2KVn/X:
Xh0m~x
<)#iS?
?f[,hw
p*s~0d
@5G@XI-
r_{<nEK
Ofi>aQV
xxeO8G
*E2?|Kd
rE['bL=f
fraWep
Y>mjl4$
4s|Y@A
j~viNp
<>_Bpc
Y\:\o,
MWtfYG
=9mIVci!-I
Rh7N,e-AIN?
,M)"]\{9V
jLE%^-
\:km?3
if[ceA
He^Jcy
yE_k6n
%HC:_+
a1$>!L
E({}Q
W/vh4u
2me?Q.
PM@jg$
%v(&Tl0
NKb@{F
#{"KSBh
8v%Qj%z9
?j(%Y,
BRf4k
~kuN%Vz'
k;2niz
6BWtJ+U
1(^QUwW+
5cXD:X
F1!=kY
8QL1p/
{+\4e|
wM^4dm
9GeV#t
d{L/W1?
4Os18cs
|+LRPPxF
v;|Ud{
w-AP$u6
7XlU!=
4KoqI<L!
Sj2[4w
nLQu@h
.sf{[I
\GX'z)st
$AG/w<
1bJ.@r g
v]kYK*C
zinq'?
Lp5VK0
"cS17o
y{(-P(
mTGQSf
b>Tv5hs
grA`mF
\7qjSY
B+{ ~n
}i=+G
McV- '
E\fik}
T iluJ
u6"Hz[{lHy
+2=chu
ZVS!73}
S(|6Pe
0p{X0\
Qa&i6j
.i`cw@
x;0AhJW
C='nbDn[
8sStuz
,J!S3#
w=%GhWs
+b]f -
E:tD^E?
#K6Q7F
8:muRLS
zpDJwq/|
55o']#
XrQ=8
@;Iqay-
0cl&xf
zlKqQ:
Y/`4=x)=1t
1-D~26
IKi&I"
Z7{\:2JC
|:1iV2 {
Z?_b`
rZ Ra~
cz%&8N
f[]a8)
Jm%&8m
bZ fwoNa8e
{*_C82
xgx9Z
;AKZ zd
(P%&8<
,7 ?Z!
3VHZa8Z
_bj2
_bY*
*zZ Xn
Z u0%qa8
{UL_%+
#Z mOl
Z h;T[a+
Dg(Z *X
g-(C%+
smH28M
PZ Edvaa8
Z_bX
OWt%&8
k.brZ
Y_cX*
 d&jXa%
c#Za8u
TSl++
Cx8Za8J
7: w!B
v4.0.30319
#Strings
#Strings
#Schema
8j`u_*gs
IEnumerable`1
UInt32
get_UTF8
<Module>
System.IO
ArNJxnWVgxpBdMWsgyVDzctYhKxT
mscorlib
System.Collections.Generic
get_CurrentThread
get_IsAttached
set_IsBackground
GetMethod
CreateInstance
Invoke
Enumerable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
get_FullName
ValueType
GetType
GetElementType
System.Core
MethodBase
TryParse
Reverse
GuidAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
get_IsAlive
add_AssemblyResolve
r4f3e.exe
System.Threading
Encoding
IsLogging
GetString
get_Length
MemoryStream
System
AppDomain
get_CurrentDomain
System.Reflection
Exception
Intern
MethodInfo
System.Linq
Buffer
ResourceManager
Debugger
ResolveEventHandler
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
mqungzonstqhaxuzixwaoudoixv.Resources
ResolveEventArgs
Equals
RuntimeHelpers
GetObject
Environment
ParameterizedThreadStart
FailFast
System.Text
InitializeArray
ToArray
GetCallingAssembly
GetExecutingAssembly
BlockCopy
op_Equality
Confuser.Core 1.5.0+b5197549e4
chrome.exe
Google Chrome
Google Inc.
/Copyright 2017 Google Inc. All rights reserved.
70.0.3538.110
$4502d206-1d2e-4576-a733-dfe01c515355
WrapNonExceptionThrows
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Google Chrome
CompanyName
Google Inc.
FileDescription
chrome.exe
FileVersion
70.0.3538.110
InternalName
r4f3e.exe
LegalCopyright
Copyright 2017 Google Inc. All rights reserved.
OriginalFilename
r4f3e.exe
ProductName
Google Chrome
ProductVersion
70.0.3538.110
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
FireEye Generic.mg.0a22bbcf3c149176
CAT-QuickHeal Clean
McAfee Artemis!0A22BBCF3C14
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_80% (W)
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/Kryptik.ABVL
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Miner.gen
Alibaba Trojan:MSIL/Kryptik.752117e4
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.FakeChrome!1.9C7B (CLASSIC)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Miner.gen
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenKryptik.FHGF!tr
AVG FileRepMalware
Cybereason malicious.4638e3
Avast FileRepMalware
Qihoo-360 Clean
No IRMA results available.