Static | ZeroBOX

PE Compile Time

2098-05-07 10:29:12

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000a114 0x0000a200 6.7120724853
.rsrc 0x0000e000 0x000005e8 0x00000600 4.18635440638
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0000e0a0 0x0000035c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e3fc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
IEnumerable`1
CallSite`1
IEnumerator`1
List`1
ParallelLoopState32
ConvertFromUtf32
ToInt32
Func`3
ToInt64
Func`4
Action`4
get_Br9d16Nce1515y3b0o326daqo6dab34behq4
set_Br9d16Nce1515y3b0o326daqo6dab34behq4
FindSymbolByRVA
FindLinesByRVA
get_8g5Jm4f4cnfXbd04a929c9x79G
System.IO
Internal.StackGenerator.Dia
LoadDataFromPdb
mscorlib
get_Klrc2al87beZy603w1eeh26004PVe4ceq7jPac
System.Collections.Generic
Thread
MemberPrimitiveTyped
System.Collections.Specialized
Synchronized
Append
GetDataKind
GetReference
IID_IDiaDataSource
set_AutoScaleMode
System.IO.IsolatedStorage
Invoke
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
IDiaSourceFile
TryGetFullPathToApplicationModule
FileName
GetName
BasicType
GetBaseType
SecurityProtocolType
GetType
System.Core
Capture
ApplicationSettingsBase
Dispose
X509Certificate
Create
EditorBrowsableState
CallSite
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
LoaderOptimizationAttribute
WriteByte
ToByte
get_Value
set_Expect100Continue
Remove
set_ClientSize
LastIndexOf
GetSymTag
System.Threading
DownloadString
ToString
GetString
Substring
disposing
System.Runtime.Hosting
System.Drawing
GetTempPath
get_Length
GetLength
RemoteCertificateValidationCallback
set_ServerCertificateValidationCallback
ITupleInternal
System.ComponentModel
IDiaSymbol
set_SecurityProtocol
ContainerControl
IsolatedStorageFileStream
MemoryStream
get_Item
System
SymTagEnum
FindChildren
X509Chain
AppDomain
GetDomain
IDiaSession
OpenSession
System.Configuration
System.Globalization
System.Reflection
NameValueCollection
MatchCollection
GroupCollection
WebHeaderCollection
MissingManifestResourceException
SignatureDescription
StringComparison
CultureInfo
CSharpArgumentInfo
Microsoft.CSharp
System.Linq
InvokeMember
GetMember
IDiaLineNumber
ColumnNumber
IsNumber
StringBuilder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
ResourceManager
ServicePointManager
UCOMIMoniker
System.CodeDom.Compiler
IContainer
GetModuleFromPointer
IEnumerator
GetEnumerator
System.Private.StackTraceGenerator
.cctor
IntPtr
DiaSource_CLSIDs
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
.Properties.Resources.resources
Matches
GetLoadedModules
System.Security.Cryptography.X509Certificates
CSharpArgumentInfoFlags
CSharpBinderFlags
System.Threading.Tasks
Equals
IDiaEnumSymbols
System.Windows.Forms
System.Text.RegularExpressions
System.Collections
NameSearchOptions
get_Groups
get_Chars
IDiaEnumLineNumbers
get_Headers
SslPolicyErrors
Internal.Runtime.Augments
RuntimeAugments
ActivationArguments
Exists
Concat
Format
Object
System.Net
Target
op_Explicit
IsLetterOrDigit
WebClient
get_Current
Convert
ToList
MoveNext
System.Text
set_Text
ReadAllText
WriteAllText
ToByteArray
ToArray
System.Security.Cryptography
get_Assembly
System.Runtime.Serialization.Formatters.Binary
op_Equality
op_Inequality
System.Net.Security
IsNullOrEmpty
{P{N{K{p{L{R{K{\{^{
{}{e{T{Q{\{
{Q{M{N{N{t{
{^{q{N{
8z8z8z8
z+{*{${
z"{${2{
# $/$>$
A9A(A6A
(L'L*L)L
+[+\+v+Y+\+
+{+\+{+_+
GUGYG\GzG
A$g!g#gQg&gbgQgDgSggDgUg#gUg$g"g'g'g#g&g&gTg4g g$g'g$gQgRg#gPg`g
;xO4OBOdO5OLOVOJOeOOOIO9OeOhOfOgOcOwO9O5O6O1OaOfOUO8O5OaOXO
LBLEL-L&LELCL
SdSbSwS
SgSzSbS
7776767(7E7J787
74757=7
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
$4P46pddALBuF301D43Es05N53dz2D0HDRbc71$0"
47c2e84bmU29e6bV2i066d1e05X100.
'3TQO3NBbLxy271df629au5M7b672l7IfW5Zdw211/0-
2323aubv63Yy04489fe33bQaP2f710451 0
08k6HodZ0edm2bfuDfb94p61
Qfwa3gfXKfdFPfn34d1
e0a2cO12haC51+0)
"999ctYd6e8n417aw0fc9QA43s81HV7YQae0
210708162502Z
220708162502Z0
$4P46pddALBuF301D43Es05N53dz2D0HDRbc71$0"
47c2e84bmU29e6bV2i066d1e05X100.
'3TQO3NBbLxy271df629au5M7b672l7IfW5Zdw211/0-
2323aubv63Yy04489fe33bQaP2f710451 0
08k6HodZ0edm2bfuDfb94p61
Qfwa3gfXKfdFPfn34d1
e0a2cO12haC51+0)
"999ctYd6e8n417aw0fc9QA43s81HV7YQae0
$4P46pddALBuF301D43Es05N53dz2D0HDRbc71$0"
47c2e84bmU29e6bV2i066d1e05X100.
'3TQO3NBbLxy271df629au5M7b672l7IfW5Zdw211/0-
2323aubv63Yy04489fe33bQaP2f710451 0
08k6HodZ0edm2bfuDfb94p61
Qfwa3gfXKfdFPfn34d1
e0a2cO12haC51+0)
"999ctYd6e8n417aw0fc9QA43s81HV7YQae
20210708162503Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210708162503Z0+
/1(0&0$0"
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
<meta name="keywords" content="([\w\d ]*)">
WindowsFormsApp1.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
WindowsFormsApp1
FileVersion
1.0.0.0
InternalName
WindowsFormsApp1.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
WindowsFormsApp1.exe
ProductName
WindowsFormsApp1
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.20816
FireEye Gen:Variant.MSILHeracles.20816
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.20816
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.DSF.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan-Spy.MSIL.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.MSILHeracles.20816
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Gen:Variant.MSILHeracles.20816 (B)
SentinelOne Static AI - Suspicious PE
GData Gen:Variant.MSILHeracles.20816
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!901CB4E371CE
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
Ikarus Trojan.Dropper
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 HEUR/QVM03.0.76B7.Malware.Gen
No IRMA results available.