Static | ZeroBOX

PE Compile Time

2018-08-10 00:29:28

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00067974 0x00067a00 5.5920046933
.rsrc 0x0006a000 0x00010ea2 0x00011000 4.00480670945
.reloc 0x0007c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006a130 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x0007a958 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0007a96c 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0007acb8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
!1!%)+...
383,7(-.,
,$$,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,7,,,,,,,,,
uH0G5Z
un\fG%
Dwu\gV
I?U.4
dOO&m#
xH^?W1&K{
6Byv-Qv
EWG)6S
Tnq&I'
^Y7tt+
a"BI/D5
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
R+s]dm`
RZ*_]
K. 700
sbnC9
mOwK. 700
ss:orE
oQEO69
J9DJZG
Bd^\LOI
Gg16fJ
<=<,|H1
UE:sp0
dUuO{R
r)(C6G
BsVpUcQ
/(YZPz
J(T[gz$](
u=$VZ+V
Y8b'0OEs7
fW\,-Q
INb_ZI
B5Ni%.
4@\k^"
4NT1Dm0B
t3q$UR
%\b%Y
:*qgHa(
<-]@>N
3to>R{(
FJFd#x6
TR>ML\
#W)|ds
Ksk(@6
|:Y:go
JU9W75w
C^=:v
?4`pMg0/N
NHthjj
kBL.x=
&l6z7.X}
v*:m)o
*04D',,
\S!]/"n
zRNKiQb
ve2l2k
w(5\xj
,hvE^a
UC=}2K
hw?OQ
MX'b`:
<OVn 9
*7?gwJ
{Qdtdle
ndIHX4@
#UZ0Qa
fK*\Pg
](j1LpQo
Y[t00OK
xqUJ?/
leNN5(
g_~8YZ
U`fL5G
q#jNcX
kt{:o+
):;Zr
0f;geQz%:
:i~kDd
#e$C1r0
ska*mV+
E{GaDp_
|;IQ9V
uq0Lp+
m``rBU
:gQetV
itJh7Fy
&.g0Da
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
$.*$ `~l
dmBM$z
/yhr=L
1/%8*n
h6T!4B
XkpZYo
f5o^G:
kL|N^:
x;"\u_-
e)4?a_
,=.:&
lbVL#h
Zc&]Ryc
{u}dB+3
}MJ@:;
vn'e2
Q_:,7L
JH8G|<d,
{){VVE
?.<DSZa
J]#|l%xE
~i7#Vs
e}>Gx6
~Ha3c<
u2/Z-e
BsfXjZ
j;z}])
ad:%[5L
GIo=27
xw-rgTT
zv`5&x~(*
5>)>(
/tDncW
O92gz/"
lqt1pZ
lp=) ~
+n|JTs]
-}(>`No7X
ScT"4F)
yj8:nj
>mrHvz
[f64uW
;.}/zQ
7 #I9
vkeseG
3i7BvC{k
VQVv/d
Ujo>qdX
;Il8#q
#X;Cz/
!Nw3i^
r+z@:]
n^1gs *}
m{b"\
:&C1r(I
zNQii
>FrMfB
J-btu}c\
rpdt U
Qimv|'
sp?=JV=
J-btu}c\
W:'M3nB
3SGXaL
$+guS;b
]E7E}b
-1O-Ext
JVT\6BI
`aT`d}
e97K*p
K");)'
6?1Gy[1c
qs+2gy9
MU-G"o
75}fs'
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
Gw&(X?
+4y7r~X
l(AE`p
oe{3D^a2]*7
w7^eZBg
|Xqx]X:
U_(W)_
bn|UpLX9!
N)gCd:;
xc8-<vIUFR
x`vM?[
y)*au_
:1q.em
ED+(:sQ
,VfiB
+Wb`]0
z$5iC]
e4]z%
-jKr[Q
,PKGP9
E32;tb
$|O {nmF
Xl$7#5
jATXl%
vg!6BWS
Ib,IT9
Cw1~z;[
m<uN[+
SY(`Fg
CeC^$]
` e;*_P
iR%Q?:
pEc6Gt
K0JT-)
LGE]pZh
WGd;_N
y"b>^v
\K@iN
H3|1E/
oYqbM_
Kh,*aS0\m
!7BiEc/
=LicN;?lot#0
bnLL`x
qP"S"~
T|aP/]O`
N;hj|O'c
~O80RE
{dsMLAE
gDw8w[
%+]4Sf
sFm./v
95)9j}
K9Hc7|
tx3WSc-
r?:B:*f/
wO!kY<
'$_;$g
KOw0iK
ycfrhIU
?.:yH%
URk[5
C.VzPOb
+VQLeb
p<9q'_#_T*1dK
#\6Tw*
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
'XITQ6
dQ<>0u}
<'X_[>@li
w*Y75QF
?e,JX#
'c)BZo
9^ZCn*,
99M}df
mkvqTP
`&bD2)
/]vK#\
:U83FjE-
5r{V;O
>WYZ&%X
I_%##]
(lFKkdme
/|c;X97
[G_A8"
D@XKec
!1'0~n
|Qox[:
Out6d[
NWHva0
M]=\lig
3&& -|h
;92'-c
!?tz09
>_KPFJ
sys$GE
0/lri
FOX;dt
t(S"(;
l_}7s2
1%smZ=
"a(9,\+
?J-J-<
PpWIG39Y
<_R>&$KN
L58"pl5
EX{&$'J
XldR:%
IN)I#4
4qM[3`
}s3$f|
([q:OY
Jz+7),
xzT^N;m>m?@&$
_k fy+
Vw'gZ8
B&$(.(
crD5$'
4v.Foo0
0d1=ug?
J{+N%u
RR,+@'
<:>er
3[n|d^l-=eiE
T 0>xCZ
.$n*g_
/Q{MZ~
y.{j V
DGaqk23
)xMS8}
[?l:]*
Xa7t{)
)xMS8}
OI,`Ue
rgXR2n
s)<ve;
{MP9:.
SW*S'k
8^b+sa.3
)xMS8}
Un8NTZ
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
4}Q00/
dE)(zoEG
h5>^v[@
CIksAQ)P
8>m`c@
s(@C!h=
yI+C5N
>c>b)\
tKZaChe
/(ep=e8TlS
nxB(>@xe
V>i~.*Q
^bZuT$
]*\^LN
yQ0bq6Cg
I"k*!(
]>G,28
c/CqL,0e
/)HeSH
092F)T
5ReARQ
(<J:nY
1ZS:Q6
bO{x!4
ymaLhS3#
2Tu)yWs
P#nGEcpr7
jpbh0c
XGTKs@
v>9@pW
`'x2h^
q'zGZ9P
*J!/=~
*NQ&<
>Lg85B
&i f}w
^38PW<
TT>M1kN
~9W)+fWM
D3<,ktQ#oW
8%j(Y6
rW4@1cz
yh15T(
''e)cp
]|wP=
[+1*qB
v.d>'}
7Cy`&H
.WFplt&
R5w]A
eD7A=B#
Zuhjjz/G96
ZqR+pe
)TY.x4
Nc=gh>
$H%x][2*
SEmEjk
%]EqdJ
#utGK
90*!<g
WHv*>5
_dHu;5
4|{JxVs
gEQJ3}
Vd.6g/4
Fc@)uEQt
|jt},A
`:8r-;m\^
`:8r-;m\^
JSf,\q
`:8r-;m\^
2b5+."
VU)4G~
C`n Q
^<gTT"
C"-!4:[5
%j[#gX
]gSRk9
S~'K-C
x/uN+c
\d&Gl3xR
]l%:II_$-
IxT56o"
^?@ST@
@9 _%-
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
f0q6AAI
5-HR>:
(8%32-;
_B`|d&P
L+-7mT
v4.0.30319
#Strings
List`1
_Label1
_Button1
_PictureBox1
_GroupBox1
ToInt32
_Label2
_Button2
_Label3
_Button3
_Label4
System.IO
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
add_Load
get_Red
add_TextChanged
remove_TextChanged
set_FormattingEnabled
get_IsDisposed
m_FormBeingCreated
Synchronized
get_FirstChild
Replace
CreateInstance
get_GetInstance
defaultInstance
GetHashCode
get_ExitCode
set_AutoScaleMode
set_SizeMode
PictureBoxSizeMode
OpenMode
XmlNode
set_Image
get_Message
Invoke
IDisposable
Hashtable
RuntimeTypeHandle
GetTypeFromHandle
Console
set_BorderStyle
FontStyle
set_Name
DateTime
ReadLine
WriteLine
SecurityProtocolType
OpenShare
resourceCulture
MethodBase
ConsoleApplicationBase
ButtonBase
ApplicationSettingsBase
FileClose
Dispose
Create
DebuggerBrowsableState
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
AccessedThroughPropertyAttribute
m_ThreadStaticValue
GetObjectValue
Remove
set_Size
set_AutoSize
set_ClientSize
ISupportInitialize
System.Runtime.Versioning
GetResourceString
CompareString
ToString
System.Drawing
add_Click
remove_Click
System.ComponentModel
System.Xml
set_SecurityProtocol
ContainerControl
ListControl
FileStream
get_Item
FileSystem
resourceMan
FileOpen
System.ComponentModel.Design
Application
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
ObjectCollection
NotImplementedException
TargetInvocationException
InvalidOperationException
get_InnerException
ArgumentException
Button
MethodInfo
CultureInfo
set_TabStop
ToChar
XmlReader
StreamReader
XmlTextReader
m_AppObjectProvider
m_UserObjectProvider
m_ComputerObjectProvider
m_MyWebServicesObjectProvider
m_MyFormsObjectProvider
StringBuilder
ComponentResourceManager
ServicePointManager
EventHandler
System.CodeDom.Compiler
IContainer
add_Enter
remove_Enter
Computer
set_ForeColor
set_UseVisualStyleBackColor
ClearProjectError
SetProjectError
Activator
.cctor
System.Diagnostics
GetMethods
Microsoft.VisualBasic.Devices
WebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
Ho5.Resources.resources
Yn8.Resources.resources
b202d6bf24cc.Resources.resources
DebuggingModes
GetExportedTypes
Settings
EventArgs
System.Threading.Tasks
ReferenceEquals
get_Controls
get_Items
System.Windows.Forms
set_AutoScaleDimensions
Conversions
System.Collections
RuntimeHelpers
Operators
OpenAccess
Infants
components
Exists
Concat
m_Seat
mySeat
Format
GetObject
System.Net
EndInit
BeginInit
GraphicsUnit
Default
Environment
XmlDocument
Component
set_Font
get_Count
Convert
SuspendLayout
ResumeLayout
PerformLayout
LineInput
System.Text
get_Text
set_Text
AppendAllText
get_InnerText
_childtxt
_infantstxt
_adulttxt
set_TabIndex
set_SelectedIndex
PictureBox
ComboBox
GroupBox
ContainsKey
get_Assembly
WrapNonExceptionThrows
Seat Assignment
Copyright
2015
$2b827ee8-25d5-4442-8ecd-ec3d0d07d28f
1.0.0.0
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
My.Settings
PictureBox1
Label1
GroupBox1
Button1
Button2
Button3
Label4
Label3
Label2
infantstxt
childtxt
adulttxt
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PictureBox1.Image
818a016f
b655dd6e0
b655dd6e1
b655dd6e2
b655dd6e3
b655dd6e4
b655dd6e5
WinForms_RecursiveFormCreate
WinForms_SeeInnerException
Property can only be set to Nothing
Seat_Assignment.Resources
C:\Users\tfaye\Documents\Visual Studio 2013\Projects\Airline Bookings.txt
C:\Users\tfaye\Documents\Visual Studio 2013\Projects\Seat.txt
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}
C:\Users\tfaye\Documents\Visual Studio 2013\Projects\Passangers.txt
Infants
PictureBox1.Image
PictureBox1
Microsoft Sans Serif
Label1
Flight Bookings Management
GroupBox1
Flight Bookings
Label4
Infants (under 2)
Label3
Child (under 12)
Label2
Adult
Button1
Button2
Button3
adulttxt
childtxt
infantstxt
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
Seat Assignment
FileVersion
1.0.0.0
InternalName
Seat Assignment.exe
LegalCopyright
Copyright
2015
LegalTrademarks
OriginalFilename
Seat Assignment.exe
ProductName
Seat Assignment
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.d7674428d2b9970b
CAT-QuickHeal Clean
McAfee Clean
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Packed.Generic.619
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Trojan-Spy.FormBook
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilCO.34058.Em0@aatJaWp
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Malware.AI.3984503289
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 Clean
No IRMA results available.