Static | ZeroBOX

PE Compile Time

2021-07-13 00:01:16

PDB Path

C:\Users\DEEP\Desktop\HayatVarmis\HayatVarmis\obj\Debug\HayatVarmis.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000011c4 0x00001200 5.26593873501
.rsrc 0x00004000 0x000005bc 0x00000600 4.0913138158
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
DownloadData
mscorlib
Thread
Synchronized
defaultInstance
RuntimeTypeHandle
GetTypeFromHandle
GetType
get_Culture
set_Culture
resourceCulture
ApplicationSettingsBase
Reverse
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
HayatVarmis.exe
System.Threading
System.Runtime.Versioning
ToString
guncellendi
System.ComponentModel
Program
System
resourceMan
Boolean
System.Configuration
System.Globalization
System.Reflection
Exception
CultureInfo
InvokeMember
Binder
get_ResourceManager
System.CodeDom.Compiler
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
HayatVarmis.Properties.Resources.resources
DebuggingModes
HayatVarmis.Properties
BindingFlags
Settings
HayatVarmis
Concat
Object
System.Net
get_Default
WebClient
ToCharArray
get_Assembly
WrapNonExceptionThrows
HayatVarmis
Copyright
2021
$bed9c145-81c5-4765-bf79-ca32ca9413c8
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
C:\Users\DEEP\Desktop\HayatVarmis\HayatVarmis\obj\Debug\HayatVarmis.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
https://adsclaim.com/damn.dll
https://adsclaim.com/bitli.exe
\Windows\Microsoft.NET\Framework\v4.0.30319\jsc.exe
damn.RunPE
catlak
HayatVarmis.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
HayatVarmis
FileVersion
1.0.0.0
InternalName
HayatVarmis.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
HayatVarmis.exe
ProductName
HayatVarmis
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.19b5b2947386eabf
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
MaxSecure Trojan.Malware.300983.susgen
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34058.am0@a4dzqHb
Avast Clean
CrowdStrike win/malicious_confidence_80% (W)
Qihoo-360 Clean
No IRMA results available.