Static | ZeroBOX

PE Compile Time

2021-07-12 04:12:36

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006ee48 0x0006f000 7.83696755715
.rsrc 0x00072000 0x00003219 0x00003400 5.55079491623

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0007213c 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000746e4 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000746f8 0x000004f4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00074bec 0x0000062d LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
[Qw,}Q
EX)U|y
RE`fNk
/|b=7j
O4iAY
h?U?kO
SF*<+6p
OdUp^b
1Y=,'Bx
(m%<=b
Qb%&.v
3t$iu
he`VXJZ
[_c,aA`N
<_fzO6
ga^`++
/7P X_c!
Zl|#to!
'bd.6!*Z
+&zi'Z
cVSky~Vy
~)haZ5
,3))d:
yyt:l\4
g_d`/!
9OkyMP
%eZ~?ml
H!O#yI/
I)LuAht
B[;{\v
&"8A#Q
v!s,29
ixM1Ql
[1#V`t
D_`SS\
F~ 5F,c_
3z>&mS
w.0YT?3
a<P!%%{
BU`N$q
t4Eul(
Og%*]
v+H)RH
;DFK>Q
B~:D?1
~h-J\N[|
\Y$BWI
dYs-/U
"wj2cR
}a i;
Z1q>r<
an~2K-5k
GR2_"x
}Kd:zGY!
a3Pz|"
hC/<QP
69LL,O
8z_1St
(DpOY|
T>?h0f
Kdns&xI
FOh_Ru
/-~]a3
GFq;Gf
Dt%oJu
Sdvi?%b
/D Cg2
A:&1:Q
d^.QDd
9fbdm>
I#D=:r[
[+ixc
d_c8/Ip
Hf%`^,
I_6#tWD
~C#OTj
2(A)72
:R!-lPQ
eiJPQv
3|`1qF
1v)!YSM
rP%:p7
d'b9RrE'
o;i1f=
D=&Y6y=
fq^(7 G.
Uoda-(4C
pEo\vS
"2bE42
Nt&6\RoE
sIg6e`
"#~F5~\
vN<zQR
fO6PgH6
prynMx
bF^:5m
V,EKq;{:
!)i;se?:@
^Ig#va
*m6Vo?
\;Ov!<
_$"%FnM
k$j471A
RkO:J=
.N2z!qlW
1H=N<5
P~D*Ve
ymQpVXH
TE>f{
h"k"1>
f[J!Sy
ldu|7O2
A~FH
^]`Xj|V&
aMD>el
QDO@gj
g;P}C$j+
XFRtJ
oc%u&G
R#dIUy|
58TlOX2
AE@vS[
w+/jw[s
nNH`}I
|E\OW;kG
-O-me\\
g>|b'I
|>)>.
2R F.
HA.'$fo
)@OH"N
v1A8%Nme$
#TZNl!
i;EJ,N
TD-kX|
izoPzn
G0h5!
i%f8y%
,W\VCq
S|E&}zO
Q|j,=(TS
KLDA0i
,h@*1C^
U/&.`x
/tZBB%
Q[#'la
OP$V0L-
<Tk8,:e
r?S~O*
#U%u`zb
YbN[A
mDv"j^
zcKZ8'
Bh1c~dU
U|.KK`Q
*gY1ol
heCEC6
B9djwK
FzE{?Fg;
\jC9z5
iI;%_(2
qcZkfQ
Rg);*t
z;0.68
au!s3:N
$cq3EN
D*$/`V
tS,L/8U
_}'0A-V
zY3h:*
j;G>~po7
zR3rU9
3IfuY@=
G ';<`
jCl#i(q
NPH0Ld
X7{QJN
gXF{`J
qF.pvBX
["(E^wwpB
keA6H0G[
biA\/L
"pN~TbS
x."8$R
<|_*g7
l HDHh
C*zEstf<
2/H!`)
XNx,FE
Mf6x^z
(GI$`!
U B{9ox
+(vf<t
Rw$RyP
s1Ti.
+=63]gs
p#t4E49
B1wJ+f
iy5xt]a
)xctID
r&gt1/t>$u
&;.c 1
]nbh&&
^D[nh`
*/*a3s
CE+U{E
sHxRqP
@l[/>
x?Zcz`
HO22<_
T=Yu4q
b&~<%42uA_
kw`phJK
2~t6+T
5^bteo`
%]gbv!~
-8%G,(h
~nU03|
we'ZXy
-y2Ak0
mf=>Vd
R2I`kV
%%_@Ox
@0jC0'
L/!w_F
gfEy>;
.gM.c/6m9
C=%a8r
Cpn*@d
YNl7Eh0h
A<~Tvg
`P8d0jp
3wCX'\R
fzUm\8
:$KO#N
Dd*>uf9
~RmhMi2
'VsA>w+
\H973)
LSn"~T
nNjz'
{3R_W4vG
6Z1|n:
&\Q`@ulxx
f 1^""
z4&jic=
L[WO} e
#h@Q_M
v| _[u
H_!H:C
(TM~,$0
\!1"^v
]<\6p
?),}Mh
DUZa}u!h
2qcq/w
TgU;vT
gucEP6
*61'Wd}ifY`
CxW]^]4
0'=cL6
YY62n(`e
"f66^<
1!T"\I=
98hAkN
X^<~>.5
D.}?-L
)(WsSb
:IbhH
{<0YF9
\k F}D
NB`MzE
Ggbix)+$
qXnAUj
c~Q7u
iMM"/[
1}C,=i
^Z/!1X-
~FA\w8C
_<Hd0=
?Ooua@=
99ENa&
I$S6$-
qei<#p
gY'4i
Hc^PUp
X]em7qv
DeeE
DwJF(A
x{QPbE
+W=`zg
98Gi43
IN~C1?j>
:.1`W{?/&y
X6"EgYGn
`Wrd#3mo
%WsP29
It}C&
q"7`qn
wH9ZN(
6t)+'\
/X++f<!
gH<wRQn
$7}p>s
]r*d:.
[BFw+l("
OC!p.
R!wFFG
F=%<$AseD
`b`k+)
"s!eU=7
2.ZrX|
alU.aJ
1lsN{n
^DOr\#
^\G+yQ
*Q<60^
{Loa7C3e
Q-~!7)
fBXvk#
U**^3 )U
;qw}H6
N(n}Q)
i$I{:Yt
nAY^kjt
ZUAEZh
PmoaqN
K#zf5H
jJ'B.hP j
Nd4C&N
hcA710D
RXSx^k
o&j {z
-xK@^=
faMwkx
FZcmh&v>
9q P5u
Ne,#g~
uOOP$J
E<HgS;
!YPLOH!
tQ;d^2
:ziZT-
~;|!7j
{MvJ;1
cY}*Vd
YeX?{@:PD
&=XZ{<Q
K+CX;
EDB]xk
wx/oa_
0ySimi
oQUad#
9Fj 0&
.;)^QEF.
wk*)']_
2[4ILqS
dBo@|)
FHmAr$7
B5mTq&
D(s{ 0
mfc{7vi}
buD Z6
sH\o]l
.:iM[+
g#b8H#
X?/bd
Zn,u=N
YY(@>0
t#rc!d
1WNR2H
23UY5k
?S7ev%
$cj'gg
`NV=@:\m
{^5R!'Z3
Mn-1xd`n
2_6M2V
]\5Y.B
bz(*Td
$[dC0[
<K_57R
2pMm{T
kO.`po0%
hCg76k
I7ZZ@#2
TBEN w
TLbUFs
OG&I:~
?BN+jV)G
I_3nh^X
E-|fRV
fUda&s.
*gE!R#
dN)"Hc
itxaKx
`$^T3hM
'GFW.-
+)l-~~lh~c
Q@(7Zq3
'w\z3:
d1~f+
v NRK}
U/Jo2#
V+SO;"p
B\Fuf
hdK;cM
QF9z~K
e9Fv_x
ZDL.0O
OTfsS"
H.l"z1
M8,^rc
t#,=SbgYG
G<{@[H
X&?B,T7Q
fvjv10
?p->7$
VJ4_}8
|yQ Q9'
29MgP^$
vv4T,
i06jAa
oDE^rd2
j5?&z4
ehqpMLB
'iblDI[K
r_4epi8
+(;,z/8
]sF4-o
gz$Uje
0Nwd5JJ
<M?_Ui
/4KUPu
c!B;vBK2
/(&rDg+
o51GR2
+@pUO\
toJVv$
mc0cnQ
q1XXh.RYN
f_x01%
.4U|IN
AW>u2q(
o5)h'J
E|J_v!
Z:[ \m/
CgN\/33%
dfm]Yt
9~IJF}
fhl/n>
TrT.(y
tFc%5.
LfHI>7
]Bl-ChQ
J`GU$s
2(;&)
q98f*}
vYgFETZ
eb)if
)ek7;q
T>GlzU
}f%2Yhd
@u/V#D
9NJw)N
1F*\gNK
BO{'f9n
|>T>+[
\k}#"1
aEG]ULA
d|.Cm(_
>;K6|}
>"Y?hy
6$Vy'Y
rkyX^6]
26ND&C
4m<<J
^t~]+j
y%V!xF
u\Q/fk
r^(IzP
.GhWQG
,:~bj"X
*}!BG=
;fRB`6PK
(7.EV:q
Qee[A%X
ilt0+o,?Zz:
Tc3/J5
Q/Q}]k
8O9Lrv+
a|3YkN[
1b2{UkG
bR}W&B
SDkECn{hJ
gP/!c*
"T/F 8~
e^Lv^)
+^tpoP
x.>S{S-n
.N86m<
wH(H{S
.@Cti?|
L3hX"W2
n:SR.F
%1xV!d*
GPp/mLX
+8ia)}@j
CEA7[Q0
83sA*SPK
FRS%,q
feizBa
fY$2*{
P^YKRl;
$T'EP1
1!+7][
U|0i(2
9x*`G0
4,Nu3w8
wi&Ef@
3?Vdk?
ZpZJIK
:M'u^)
UYoGUHk
nc%F-c
D"U*fp
=`c*Cr
'.^$El
#5+vb2H
%/>XRC
$T!aR~
phn'h]
cYY7O)]
Tw{sz'8
cNNVV*
^2qx9-q~d
rF<)iz
BA{E/I;
-<.cT'5
g#*b6\
VfWJy1c
^%z{B)
Xd3<ng
i%8=t~
AF.2Z+c
YI}Um#ZD
Yr"PAIMu
m$k!:R
_~1|@d
Pdq)v>^
J7!o'b
z5qmnly
Yl<Es3l
Fm|kGsiJ
{6[Bdc
gY-dP/
#pZ@]
*`BI&a
{b?_}n
^^\f29%
U7_BqL
H}+P=i
S+~-;$L
Ci=f+~
$eGB"U5
Q0!W%6
0=oQQy
=A.}!9
l l/q8
$ogMl%
-oGA]l
>llb%U
;h~Z]}
fA`93!
)!4r|g
;`N@;|
_\E3|_
S|M6=s
]k=MaB
x7U4v3g
;cvD]P
CL-G@:
v^M+*\`}
i`X|Kr
Mz,S'L
+{]h&;
ZEk%:4
6^[-FH
(PV(@qN
0BAV',
E*ml0p
JY!2{F
mSnN.P_o-
^b&=l.
Or^s.
,'%[F?
iU[_ |_
Kk>EwJ
VXg,h/
J:"R*(^a.,'
<^,lVE
odlI;Y
clnDg[!Y
;n-P2]
A`Cyn8
!{-cAe
$@0fCA
*tj/j<
}%FnnS
\sp3s;
^!wO)T
nlcz"@
|r*0n{A
YIj_cv
RGB6%45
*T~B:F
1\C*^^'VJ
8h>Es(
Lr:F)>
rruXjF
r$9bmF
R49e8 Au8+
uhv}@4<|
92P]DO
b,eNC>W
OEz5\U
."$Mj(
Y]oZ#8
q8]I^y
\BIVhv
[w$@5U
D;|CN^N
eL%^6U
0i4.M7
'[D9YS
=G!.oEXn
h^R?S]}
TSX$Z`
x$,:pM
d79Xw)b
383B{=
/P{B:s
Rr%;P5
,O%%K-x
SG$V2G
VsIe}
28DO7Y~AlnG
=KLvSm&i$
$p}'LH
=gxDPX)
X^\ms.
fC0cZVm
\{eMrv
XUaJK4@
q/,77*
}Ei;96
QPi{5
|h^0G%
DS O^&a
07VgYv
H-L[Y~
!4Mp|y
K|xm0%
2N?nG
q`oaSI
e@cV1:
CltV8n
;x\`*?F
G~T"|{
fYZ v/
2|@pZ
UKsT%&8\
Z?_b`
4G<_8"
>>:Z {r
;)Z b9
)}%&8N
4Ne%&8
Z -z!/a8
aZ v_n
N7aa8@
_bj2
_bY*
-TZ "VP
_/0a8p
aQd%&8
.z UMR4
Z I4Dwa8
:NHa8\
J{Za8i
Ip;a8S
K5Z %I
Z L+7na8
dw&k%&
RBSeZ +
Z_bX
>sna8D
Y_cX*
qyPB%+
M]'Q%&+
+S OOF-+
P^Za8o
LxZa8S
pt2F
vl,a8{
4r%&8!
|*z6%+
v9u(Z
${&%&8
@G{Z u
[ef(%+
a)PLZ
I$P(%+
v4.0.30319
#Strings
#Strings
#Schema
List`1
UInt32
Dictionary`2
get_UTF8
<Module>
liMjooLaYdlVujHtyCZzCwMcbAQpA
System.IO
value__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentThread
SHA256Managed
get_IsAttached
set_IsBackground
GetMethod
Notice
CreateInstance
GetHashCode
ZipArchiveMode
get_Message
Invoke
IEnumerable
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
MsgBoxStyle
get_Name
get_FullName
DateTime
Combine
ChangeType
ValueType
GetElementType
MethodBase
ApplicationBase
Dispose
EditorBrowsableState
Delete
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
GetObjectValue
ZipArchive
get_IsAlive
add_AssemblyResolve
xcCyF.exe
Serialize
System.Threading
NewLateBinding
Encoding
IsLogging
Warning
FromBase64String
CompareString
ToString
GetString
get_StartupPath
GetFolderPath
get_Length
Critical
ConditionalCompareObjectNotEqual
System.ComponentModel
LateCall
MemoryStream
System
Boolean
TimeSpan
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
Application
System.Web.Script.Serialization
Interaction
System.Reflection
get_Exception
add_ThreadException
add_UnhandledException
Intern
MethodInfo
DirectoryInfo
StringBuilder
SpecialFolder
Buffer
ResourceManager
Debugger
ResolveEventHandler
ThreadExceptionEventHandler
UnhandledExceptionEventHandler
System.CodeDom.Compiler
ToGenericParameter
Computer
JavaScriptSerializer
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
System.Diagnostics
FromSeconds
get_TotalMilliseconds
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
3sRcacuuo8T4z.resources
ReadAllBytes
WriteAllBytes
GetBytes
ResolveEventArgs
ThreadExceptionEventArgs
UnhandledExceptionEventArgs
Equals
System.Windows.Forms
System.Web.Extensions
Conversions
System.Collections
RuntimeHelpers
Operators
Concat
Format
ConcatenateObject
get_ExceptionObject
GetObject
LateGet
LateIndexGet
System.Net
MsgBoxResult
WebClient
Environment
get_Current
get_EntryPoint
ParameterizedThreadStart
Convert
FailFast
GetWebRequest
set_Timeout
MoveNext
System.Text
get_UtcNow
LateSetComplex
MsgBox
InitializeArray
Emergency
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
CreateDirectory
ZipArchiveEntry
op_Equality
WrapNonExceptionThrows
1.2.3.4
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
I>$\I>$b
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
name="JR.Inno.Setup"
processorArchitecture="x86"
version="1.0.0.0"
type="win32"/>
<description>Inno Setup</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="x86"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
</assembly>
ICON7(
VS_VERSION_INFO
StringFileInfo
000004B0
Comments
This installation was built with Inno Setup.
CompanyName
Epson America, Inc.
FileDescription
EPSON Driver Package Setup
FileVersion
1.0
LegalCopyright
Epson America, Inc.
ProductName
RR-60
ProductVersion
1.0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Stealer.l!c
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!9A122ED5DD32
Malwarebytes Trojan.Crypt.MSIL
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0057f2f81 )
BitDefender Trojan.GenericKD.37226791
K7GW Trojan ( 0057f2f81 )
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
Cyren W64/Trojan.BSFN-7729
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/Kryptik.ABWR
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Kryptik.0e2e4f3c
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.GenericKD.37226791
Rising Clean
Ad-Aware Trojan.GenericKD.37226791
Emsisoft Trojan.GenericKD.37226791 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.VirRansom.gc
FireEye Generic.mg.9a122ed5dd32c372
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Trojan.GenericKD.37226791
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/AD.StellarStealer.bkskm
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2380927
ViRobot Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:MSIL/CryptInject!MSR
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Trojan.GenericKD.37226791
TACHYON Clean
VBA32 TrojanSpy.MSIL.Stealer
Cylance Clean
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DGC21
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Stealer.ABWR!tr
AVG Win64:Trojan-gen
Avast Win64:Trojan-gen
Qihoo-360 Win64/TrojanSpy.Generic.HgEASYQA
No IRMA results available.