Static | ZeroBOX

PE Compile Time

2021-07-11 04:25:50

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006f060 0x0006f200 7.83686749265
.rsrc 0x00072000 0x00000552 0x00000600 4.00509393088

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000720a0 0x000002c8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00072368 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
V1]D$*
gC0[EKe
\.{Aei5
=dcQL
rGTHJ$I/
}6rt-,
j\<e}I
>"nzrD[
ygmpU_
/37_p|
%gNrF&
wF|E@3
AB\d>7
\rm3WL
)li&'E
>[2#F8
1dM3=H
&AHd<N^L
B80JR45d
x$<Kc2(
$5ooRW
w~o\Hz
*T="e:
_"3QQh?6Z
976WLp
/9-wxQ
cW}SN/
J#MAiT
Z&Uym#MO
OtJikq
\eZ<"<"
BRxpL<;
z<Kb8RPt
Z-4.cI
u&^gVi
<;+QPL
z;(Zm&
1D0m!M#
GC\v3[
q-|%Op
b2iJ9r
W[6&3L
(-]Y*+
x+1j8'
j#3I("N
:SL}*i
)OG_eo
UF8F{H
NSH[K_J
t4@X$BLE
;Vs+9c
V|.!>q?
E>:8q5pi6p
"\kcaT
]FO[u
{_wN'B
]T6`~u-
SF1&%4t7{
w[t$fg
]9x[iJ|
sp}M!S
l5a9U%
{%Q*AWQ
RO,60*
5P>i}$
U6:Z&q^
2\[!$L
$+g/ZOH
aHjQTI_
ZQ=xw{!AU
&cKSdT
T*d7;M
+,\b%uE
h4.({B
,575%Z
Z,|[a6
B<HCo~
NrnFl
$J?#}W
LD, #G
84M_(1
T6\|Zb9o
4V&t iS
t6`dJe
T`Tg&U6*J
7,Ru<m$i
rO_wmhI
$wFWFy
c_%IvR
n'6`Fd
rZ{;pV-
i`HXOV<\
WwthUGL
xdzz(C
aBXfNk
,SogaG
<)@:s1L
?Wzp<4
y8*]TC
6NeaX~g
%D!pFI
^"Ijf|pT
EIx51$
NgVU$D
Hcc`w8
5xuJ+m
B!dviH
1<\FD]e
c$yi+C
GyN<LT
"2FICf
3st4MT
Yn`pK
cQXL Q
CU_Kjv
i9*zLZq"
hr0`I?
|q]TEBI
2wKVG%
N")R68
XF^o,x
|N:aL<
,doXs5
Y5QZAq
%Vo$p/
egYNF!
..n_Uo
|EvG3.Avf
tQuP8+
"?f7lh
;tkf&P?.
0)h~c*
'|_Oi;
9N$/=_
0'V*Hu7
{ntXJ%
TFi>rw9,
@DY+[
kT>jRm
m/>z'TDL
8n}+N"I
CiZD\0
@ /GG/\x
od"yjlr
^om$#[
(IVf0$
m\h>TQ
[eMTRv
hIiA,
7.g=m7
f/U12KF
;!)qdc
|7QI$PW
;,$`cnt
w"ZJ.G
*vrg;N
"`7CK
pBjI f
Qt~M0r
E>-pEF
Fpy|4;
iN}c|o2;1
+gsT'r
\0A&&qT
)PJ'qK?
KIRqE{{&bL
5K9{?]
b,w|,GV
6(O`P:i
*.Z0:{
(u}tpZ
vx8 rNH|
0`u[JtY
2~Su9_
zw],ywR
H]*wU&
0M)#8N
0@R;SH
`=|rXW
7H!D|
|Bob.vG3
I(cBaN
kG&F9w
{2sz9}Y
/EE^`DC
`D0sg@u
e>=56#
~ D^9F
fPu-R9
6NWwms
;#~;0!
/QN}*^
GkBKa$H
p06}|k
1GzFt3
G7SrH^
re}U)g
WNiAVs3O
I7eAxv
c(8cb0
EbAk+X+
2R,pj
xU|z$s#`8
w$zO._P
U[J} ah
ER@|@hj
l;-e9;O
XJ'a+P
iQ&1V*
+V<p/`
FF@Q#+b;
~p~X:w
Vzne}'O
dQ{MX)~
yT cH_ST
U$'8(P+$
f5\UT&O/
M{O(3H
Cv;aozU
xj4An1
>B@$?u
Gr,-Q6
)GswB!
Yxk$kYw
SwcfJ
~'K++r3J
KX5PtT
W0"mOf
HiZw-2
]]li8+w4
M|rou
8]C_MB|
/!L[l
QSu{))4
#ku/atJ
#5gkob)
BW=.UE5m~v
6M"Xdk
7L=?uA
vgDZs{
:e{WW
pj<^ld
:w~!HIL
ir8S7w
k'(U75
$vR8&_3
?{%6%CC
hoSh+#q
Hx,khd
g-eZ&<l
DnvR45
6Bo&qd@
rf:/b@
@-HFze5Q
KSAn :R
z$oHN:
l@RWWPk
v;+Ztc
oc\7Br=
?g<z7o)
NLcpFf
W4(Kh\
k~%/\s
^g`leF
/(3-FZ
L/F+k
&LPB0rv
Rqplv)/
8%y]Fr
@nBe{AC=^B<A
D\XhF
DjZ;Vax
@v|7s?
B)Go+G
N2asq}
`U-M(e~}
/%R^1zV
#$3<fL
.2_Tq<4W
|GNR4C
r?$H>1}
vQCf7MM
|OU&{:
>6Rt<;z
1mSjr^
!}tO:z
iz2L)5D
link0;;
LsqQ*CP
5VNFbC
^s?Ns%
x|"i$AJ
.C)/Z$:
'M#j]n
COC>s9
.u.oYf:
QYm?yb
OSqwle
p@8?hJ
<s[nK
${\*H]
COsZP6
u)x/qClL
g0#tVs
|/L!C8
~5?`!XT
(Qbk3]
O9glB/@
<uh.rQ
f8_4r"
~X7z}#
TV:f:2
_?D|x)F~Y
$_neyiiV
T/juon
v\"OGg}%
)cM~dG
ryWo#'
KeAx<'kUa
b[wM,P
8gn;K|
W$SEyg
&t;BUCjCS
Rb]4Y8
#`d~WV
b`{r_t
9#eF{:
ph\2=
x -I8>o
[ut?M/u
bv}saw
@=X9&U4
wY~Ccf{=
|(i_k*ft
8KOe'pl(
)5:AI;j
W5DSob,6
.\Mj%^
6gndyN
Nss+G#
w<s~<d
Vw+C@mhY
va=E3Pn)
'`&~*^
ME-_|
X(ODutR
v1nE6aob
i/LSkl
J'MPn
DOt2o%
"jvk"K
aQ!:/z
F}V8?Q
o@ks,
h-M ?7
yV5ne
)r]DO{^
z76(t_e
42 :zgv
!i,w%?K
:PJj#I9
y:'>\2
L[emhL
kHn6Opj
O?Q|d?
|S<eC=
,?L!]*
F/&usL5hg
lH8xl:h
#y"l'i@GC
$~R]Zi
@Bvfr9g
iuMH?&
z4N[[6
Le1P~0
{5>'`D
oKP!
'tVeF}
agqXjzW
`T}%9i
-Py6&I(
$NP</S
/<MbL6
L>#0akx
<Q&(<J
Y+}mj?
gB}ZB.c
Topk*e
Qa>T!Mmu}
lf}kh,]
)mU3@M
KS5Wn/#
neu}D
y|e3'Y>p
J(&Vq/
J7W\Wo
q4cAq_
DqYTk3
^OQTG)
w%>eYx
-?U,+x8
s"EP*>t
ol/Rm^
9KVa6(
{z;0%W$
mU\mWDY
&cP&8Am
J6i$<G
=-f)3N
"0Og\o
qr{$_|
8Q| F/*j
pyWFi X
`m-]G
4GYSw+
Ji4w9{
[$Au\P
{@NafS
JXl3ux(
NW1Q%p
uWI(%~L{(
a|4ab4
9/<>#JF
R8VqPL
;Q.Cgw9
V[d`cs7
|El=g~
+p!gwMxN
vSd+Ms
}$<)hN
:}j<_H
&JhOXp[N8
"ChYv}
N<%nL$&
UTG'|V
#yt-qY
FsJJi->}
<dM&{e
>(<(fl
PU)yd5
\AAZZy1
L2<"A[}
Pzon"S
""JiOa
7L0511
bxngi`
U9bfx
MQSqOx
]a4o]vC$u
!x,S)W}
%B~N4+W
($cmr~
ZE{2%}
WA"M5$d
dlDo1&
8E,; s)
RL@3g..2
bjjhXa
92D=r r+
[4%Q]"MU
;[KvG=
;OE|"{y
hR/odA
:}Pxa
&PHhf,
QiW~ }
9IwfCZ
a4G8R5)
+rp7$P
"FK[2
#~}GR~
hJ{64?u8
8i_p?b
hT%RE
c>5xv{"
j%"wck
U5"Rm3!J
ZG/ZpN
`5DxEz
OGmwQ5
h@F?PX
9ZY&-e
0EcZ1
w7 K3E
|$4E_Ja
Db4)K{K
dwjXyj K
m9c&q`d
Z7(pgE9
,5)6$q-^
Xd)Z!m
*zZhX;&
(Kll372
5~,EcT
QkXO5Wr
yF:hw
d"@A%$
O{o$n*3
Ch4;9e
%V5/LD
wefY)*
N\>WjN
St7~@x
Hpn_L0
b<<v$[G
T,C#TH
zEQE2a
@Vg9FS
(yT%R%g
/+;Z~t
b]Su.l]
}QN~
#?=wYJ
P%ty4h
!2{XW*
LTTG'\-
Ks6^K
m%QNe;
>wpG5^$
P"^,%>
SSA^/)
CPlu|s&
\Fc*Pe
gW`ZO5
~VmTQGp
MO.r3r
>o_EB\
qVeDKQ
27I=zV
bWHxmFD
Ze}2Gh
2%5WnD
Oz/|Hd'
6K z[
j:wIwi
d@Xu,'q*
]uM,bI
Sjc&)*q
H?i#;a
m[-M:4
6C'Cz475U
AIR2/(
v6VFwV
:i~\;<
_J8h_|
.>feUq
#d-V4XGuM0^
m]yA_#^
|{fr{jf
DA,+JF
x!n8=W
7UG`rC
#M#FSI
Gi3M#qJ
B -S[N
r]8]2]m
t<&{'Ai_
K!JHg4
pzrlps
8a4oEo
DOod`hR
[R8FqI
~A|Yd,2
$|OT<`
u2`W#x-
FT#FlR
s7,)@"
G/C]=:
y[vM@Y
GfdV(e
j`"BL+/
B5J*Wr
poGH?f
Y[P6*/
fSl[n+
DY7OA=
*\/as9Y
7-y+0t
x{{c9Aj
DC1?P'
:e}[%9r
vdRTuAMf
#+Whq`
p02L?P
E767Wc
wZ .>k1a+
Z?_b`
V8&Z :
VD0Z b
vZ SNB
7 Rpo|a%
V)|a8R
7va86
2-ha8D
D1Z aX(}a8
ap\Y%&8
b@>a8/
!lQZ l`'Ga8
k;Z s(1ia8
yRPZ V
_bj/
$Z Z(H
_bY*
acN<%&8T
+q%&8f
kx`jZ
XlZ W]
SR%&87
Z_bX
]q/S%+
+d <M&
dIda8d
Y_cX*
}D }Za+
=:URZa+
z "^KI+
lS'+
*8'Za8
,? Huz
5's%&80
Z 1Ckia8E
Z Illra8
v4.0.30319
#Strings
#Strings
#Schema
List`1
UInt32
Dictionary`2
get_UTF8
<Module>
wcLSybMZK
System.IO
value__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentThread
SHA256Managed
get_IsAttached
set_IsBackground
GetMethod
Notice
CreateInstance
GetHashCode
ZipArchiveMode
get_Message
Invoke
IEnumerable
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
MsgBoxStyle
get_Name
get_FullName
DateTime
Combine
ChangeType
ValueType
GetElementType
MethodBase
ApplicationBase
Dispose
EditorBrowsableState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
GetObjectValue
ZipArchive
get_IsAlive
add_AssemblyResolve
wcLSybMZK.exe
Serialize
System.Threading
NewLateBinding
Encoding
IsLogging
Warning
FromBase64String
CompareString
ToString
GetString
get_StartupPath
GetFolderPath
get_Length
Critical
ConditionalCompareObjectNotEqual
System.ComponentModel
LateCall
MemoryStream
System
Boolean
TimeSpan
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
Application
System.Web.Script.Serialization
Interaction
System.Reflection
get_Exception
add_ThreadException
add_UnhandledException
Intern
MethodInfo
DirectoryInfo
cxjmPMcgBzSfgzXIzHBNAQTYuYDq
StringBuilder
SpecialFolder
Buffer
ResourceManager
Debugger
ResolveEventHandler
ThreadExceptionEventHandler
UnhandledExceptionEventHandler
System.CodeDom.Compiler
ToGenericParameter
Computer
JavaScriptSerializer
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
System.Diagnostics
FromSeconds
get_TotalMilliseconds
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
rg5gica8dHWHGFbN.resources
ReadAllBytes
WriteAllBytes
GetBytes
ResolveEventArgs
ThreadExceptionEventArgs
UnhandledExceptionEventArgs
Equals
System.Windows.Forms
System.Web.Extensions
Conversions
System.Collections
RuntimeHelpers
Operators
Concat
Format
ConcatenateObject
get_ExceptionObject
GetObject
LateGet
LateIndexGet
System.Net
MsgBoxResult
WebClient
Environment
get_Current
get_EntryPoint
ParameterizedThreadStart
Convert
FailFast
GetWebRequest
set_Timeout
MoveNext
System.Text
get_UtcNow
LateSetComplex
MsgBox
InitializeArray
Emergency
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
CreateDirectory
ZipArchiveEntry
op_Equality
WrapNonExceptionThrows
1.2.3.4
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
>|Y:n=F
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.2.3.4
InternalName
wcLSybMZK.exe
LegalCopyright
OriginalFilename
wcLSybMZK.exe
ProductName
ProductVersion
1.2.3.4
Assembly Version
1.2.3.4
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Stealer.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46611262
FireEye Generic.mg.d7f0e7382a50544f
CAT-QuickHeal Clean
Qihoo-360 Win64/TrojanSpy.Generic.HgEASYMA
ALYac Trojan.GenericKD.46611262
Cylance Unsafe
Zillya Clean
Sangfor Trojan.MSIL.Stealer.gen
K7AntiVirus Trojan ( 0057f2f81 )
BitDefender Trojan.GenericKD.46611262
K7GW Trojan ( 0057f2f81 )
Cybereason malicious.368449
Baidu Clean
Cyren W64/MSIL_Kryptik.DJR.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/Kryptik.ABWR
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Kryptik.3a0ee58f
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46611262
Emsisoft Trojan.GenericKD.46611262 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro TROJ_GEN.R02CC0WGD21
McAfee-GW-Edition BehavesLike.Win64.VirRansom.gc
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan-Spy.Agent
GData Trojan.GenericKD.46611262
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/AD.StellarStealer.aouju
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.Generic.D2C73B3E
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft PWS:Win32/Racealer.GKM!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!D7F0E7382A50
TACHYON Clean
VBA32 TrojanSpy.MSIL.Stealer
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R02CC0WGD21
Tencent Msil.Trojan-spy.Stealer.Wuqq
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Stealer.ABWR!tr
BitDefenderTheta Clean
AVG Win64:Malware-gen
Avast Win64:Malware-gen
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.