Static | ZeroBOX

PE Compile Time

2021-08-09 00:04:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00105150 0x00105200 3.46581224976
.rsrc 0x00108000 0x00001b9a 0x00001c00 5.18504684393
.reloc 0x0010a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0010806c 0x00000e14 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00108ebc 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00108f0c 0x000004bc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00109404 0x00000796 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+M+N8S
-+B+C
+Tz+[
+>+?+@{
_b`}p
Y_bY
%-"+d8e
.++]+a+e+i{
+h+p8q
__d}
,'+)+*+++,
+,+-+.{m
+)+*{o
+:+;{o
+R+S{E
bY {z}
_b`}
hXhS+E
+)+*{f
_+U+V{_
_b`}
+"+#{
+A+F{?
+B+G+H{?
Y_bX
Y_cX
Y_bY
Y_bX
+@+"+?+@{K
1Q+d{m
+c+d{o
+[+\{p
+'_d}
Y_bX
Y_bXT
%,;*8e
X'g C_
)/=d
CEU>
b# JAb
w%xh
a+$+&~
Q~zQbnB
b^^~IB
7w|;~/
oopai1
FW_aNo
2;B]2S
p;plUQ
J>M1y4
##nJW/q
&wZ9[8[WO$d/
!3.!<\Bk
hG7vj<
r^]y:9
v-Cn1+Z
k@n@n@
Lq-KR/lZ
X}mct,i
Y#nBur
j2}#)P
z"rJ8[
%_:srr
_:sE9bn
/K3`=8
;IG7N u
P/%qj1
4!/]@@
i>d^zr-
qEOE*%
1G^}y-)
4OfGodu
od`fl}
%4^rl[
~V`cvI
anSG-{
5*P1I@
I)`u(_
%];lv
EN{Wuj
\&Y?D[
?Jc\pI
r|y>&>4
Wv:ADI
zk~=?l
68.;!j
h,eSSbZ
F?`i,x
C!SZbM
)VT~T
\Ipi#_
p6'i!L
xS)/+v>=
7Jov|lxI
/fI}^{
YxBR^v\
*T&Vg)V
$/V|T$v!
FFp*.b
i?Qd/S#
r%JCT2
NW>nbmg
&['T,
T5a;;>r
QC-hlm
FSbN(*V
`Y6>C\{aN
kP]IxtZ1,V
!: lSO
wO=btj.o
=PSc/+
-ZTOM4
KCK&$e
k#j6*^
y:y`sK
W>1lcw4y*V
'N6;c<O
v4.0.30319
#Strings
RuleConditionReference.exe
RuleConditionReference
<Module>
mscorlib
Object
System
Component
System.ComponentModel
System.Windows.Forms
UserControl
ValueType
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
GetString
SmartAssembly.Delegates
MulticastDelegate
Attribute
MemoryStream
System.IO
PoweredByAttribute
SmartAssembly.Attributes
List`1
System.Collections.Generic
Random
IContainer
BackgroundWorker
ComboBox
CheckBox
Button
MenuStrip
PictureBox
PropertyGrid
SerialPort
System.IO.Ports
SaveFileDialog
VScrollBar
TextBox
PerformanceCounter
System.Diagnostics
PageSetupDialog
HelpProvider
MonthCalendar
System.Data
DataSet
DataGridView
ToolStripContainer
ListView
WebBrowser
TrackBar
System.Drawing
PrintDocument
System.Drawing.Printing
PrintDialog
TabControl
TabPage
DateTimePicker
ErrorProvider
RichTextBox
ColorDialog
System.DirectoryServices
DirectoryEntry
DirectorySearcher
DomainUpDown
Splitter
TreeView
FontDialog
NumericUpDown
SplitContainer
NotifyIcon
BindingNavigator
ToolStripButton
ToolStripLabel
ToolStripSeparator
ToolStripTextBox
CheckedListBox
FlowLayoutPanel
HScrollBar
LinkLabel
ListBox
ProgressBar
Process
ModuleHandle
Dictionary`2
value__
IDisposable
Dispose
ISupportInitialize
BeginInit
Control
SuspendLayout
EndInit
PerformLayout
set_AutoSize
set_TabStop
ButtonBase
set_UseVisualStyleBackColor
ListControl
set_FormattingEnabled
ProcessStartInfo
set_LoadUserProfile
ResumeLayout
ToolStripItem
set_RightToLeftAutoMirrorImage
set_AllowUserToOrderColumns
set_RightToolStripPanelVisible
set_UseEXDialog
set_HideSelection
set_UseCompatibleStateImageBehavior
set_Visible
ContainerControl
Monitor
System.Threading
Encoding
System.Text
get_UTF8
get_Default
Convert
FromBase64String
String
Intern
set_Location
set_Name
set_Text
set_DataSetName
set_Domain
set_UserName
set_AccessibleName
set_ToolTipText
set_Size
set_ClientSize
set_CalendarDimensions
set_MinimumSize
set_TabIndex
set_SelectedIndex
set_SplitterDistance
get_StartInfo
set_Password
SecureString
System.Security
set_StandardErrorEncoding
set_StandardOutputEncoding
set_SynchronizingObject
ISynchronizeInvoke
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
get_Controls
ControlCollection
Truncate
ToString
Decimal
TrimStart
GetTypeFromHandle
RuntimeTypeHandle
set_AddNewItem
set_CountItem
set_DeleteItem
set_MoveFirstItem
set_MoveLastItem
set_MoveNextItem
set_MovePreviousItem
set_PositionItem
ToolStrip
get_Items
ToolStripItemCollection
AddRange
set_DisplayStyle
ToolStripItemDisplayStyle
ResourceManager
System.Resources
GetObject
set_Image
set_Font
add_Click
EventHandler
add_Paint
PaintEventHandler
TimeSpan
set_ClientTimeout
set_ServerPageTimeLimit
set_ServerTimeLimit
get_ContentPanel
ToolStripContentPanel
set_ColumnHeadersHeightSizeMode
DataGridViewColumnHeadersHeightSizeMode
set_Padding
Padding
set_ContainerControl
set_MainMenuStrip
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
RuntimeFieldHandle
op_Explicit
OldRoundCore
Thread
GetDomain
AppDomain
GetBytes
Assembly
System.Reflection
IEEERemainder
ToInt32
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
op_Equality
GetExecutingAssembly
GetManifestResourceStream
Stream
get_Length
EventArgs
ICryptoTransform
System.Security.Cryptography
ResolveEventArgs
PaintEventArgs
CreateMemberRefsDelegates
typeID
.cctor
CreateGetStringDelegate
ownerType
object
method
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
WriteStreaKmClosedEjventArEgs
DPDoUWhile
TramckingRecoxjrd
DicNtionaryValueProviderc1
MessageQueueTFGransactYionStatus
AllowedAudiSenceUriElement
WarSniOqng
WoOrkflowChaMnges
IParUserAccessor
PropQertyValueY
OXmPHlCaseOrder
ServiceElMemeYnt
UrwlParammeterReader
EditborZone
AssociatiognEndMeHmber
TypeAccessExceptioZtn
SslStreamSecurityEmlement
TripVlCeDESCfng
TOoketnBinding
PassportPringZcipals
DesignerDataStaoXredPNrmocedure
GridViewSzelectEveBnutArgs
CVontexWRtuForm
CodeDomSWerializerBase
AUrrQaJyCItemValue1
ChcanEge
CanonicalTrackedInputZFiles
RecyrcleLimiVtMonitorSingleCton
RowmSytyle
FrorestTrustRelationshipCollisionColulecGtion
jgSubstitution
KyeysCollLection
RefpeaterDesigfnyer
zWebBodyFormatMessagePpropefrty
BaseRefexKrence
WebHttpSecuruitPyElement
GlyphSelectXionTGype
ProfilneMigQrateEventAyrgs
FileChOangeMonitorA
SessionPOageStatReSectSionF
DataGiridViewCeTllErrorTextLNeededEventArgs
WorkoflowDebuggerSteppwingAttribute
ButtonBaseAccessibleObjOect
INamdeLshpacePrefixLhookup
jDRbFBgRmMoBKWGplhOqJUtynmFcCK
qtBxkiJcUUPW
AvailableBits
AvailableBytes
IsNeedingInput
TotalOut
IsFinished
BitCount
IsFlushed
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
SuppressIldasmAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
AttributeTargets
ObsoleteAttribute
STAThreadAttribute
IComponent
SymmetricAlgorithm
CreateDecryptor
CreateEncryptor
RijndaelManaged
TryGetValue
InvalidOperationException
Container
TransformFinalBlock
ArgumentOutOfRangeException
FormatException
ComponentResourceManager
Buffer
BlockCopy
get_Position
set_Position
ToArray
Exception
get_Message
Concat
WriteByte
ReadByte
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
Console
WriteLine
StringSplitOptions
ResolveTypeHandle
MemberInfo
get_Name
get_Chars
ResolveMethodHandle
RuntimeMethodHandle
MethodBase
GetMethodFromHandle
MethodInfo
get_IsStatic
FieldInfo
get_FieldType
Delegate
CreateDelegate
GetParameters
ParameterInfo
get_ParameterType
get_ReturnType
DynamicMethod
System.Reflection.Emit
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetFields
BindingFlags
GetModules
Module
get_ModuleHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
WrapNonExceptionThrows
ListBox DequeEnumeratorBase1 App
2ITransportHeaders DataServiceRequestArgs Software.
IToolboxUser Corporation.
-ITransportHeaders DataServiceRequestArgs App.
<Copyright (c) IToolboxUser Corporation. All rights reserved.
$09ae4b76-537e-4047-861e-9222aea7efb8
511.270.505.422
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4(
#Powered by SmartAssembly 8.0.0.4562
Use `RawZip`.
Use `RawZipAndAes`.
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" >
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with.
Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows Vista, uncomment the following supportedOS node-->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- If your application is designed to work with Windows 8, uncomment the following supportedOS node-->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- If your application is designed to work with Windows 8.1, uncomment the following supportedOS node-->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- If your application is designed to work with Windows 10, uncomment the following supportedOS node-->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<asmv3:application>
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
NumberPrototype0
210807130000Z
230808070000Z0
NumberPrototype0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
NumberPrototype
km^Vz_
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210808220411Z0?
0i "YL
-<%ziB
NumberPrototype0
210807130000Z
230808070000Z0
NumberPrototype0
NumberPrototype
20210808220415Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210808220415Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
1<:1>:3<=3<
-*/.225
"!)(*(+(,(-(.(/(0/1(2(3(5464748494
linkLabel1
linkLabel2
linkLabel3
linkLabel4
linkLabel5
linkLabel6
linkLabel7
linkLabel8
linkLabel9
linkLabel10
linkLabel11
linkLabel12
NewDataSet
button1
dateTimePicker1
listBox1
pictureBox1
progressBar1
propertyGrid1
progressBar2
UserControl2
version
Selected compression algorithm is not supported.
Unknown Header
comboBox1
checkBox1
checkBox2
button2
button3
menuStrip1
menuStrip2
panel1
pictureBox2
pictureBox3
pictureBox4
bindingNavigator1
bindingNavigatorMoveFirstItem.Image
bindingNavigatorMoveFirstItem
bindingNavigatorMovePreviousItem.Image
bindingNavigatorMovePreviousItem
bindingNavigatorSeparator
Segoe UI
bindingNavigatorPositionItem
bindingNavigatorCountItem
bindingNavigatorMoveNextItem.Image
bindingNavigatorMoveNextItem
bindingNavigatorMoveLastItem.Image
bindingNavigatorMoveLastItem
bindingNavigatorAddNewItem.Image
bindingNavigatorAddNewItem
bindingNavigatorDeleteItem.Image
bindingNavigatorDeleteItem
checkedListBox1
flowLayoutPanel1
-00:00:01
hScrollBar1
label1
label2
label3
label4
label5
comboBox2
UserControl1
panel2
vScrollBar1
button4
textBox1
algorithm
ERR 2003:
monthCalendar1
checkBox3
checkBox4
dataGridView1
toolStripContainer1
trackBar1
webBrowser1
tabControl1
tabPage1
tabPage2
listView1
label6
label7
richTextBox1
domainUpDown1
button5
button6
button7
button8
button9
splitter1
treeView1
numericUpDown1
splitContainer1
notifyIcon1
208 19 41 164 113 216 229 142 14 52 164 21 106 45 64 156 72 46 51 37 215 166 134 190 218 206 180 44 254 167 22 104 133 198 25 173 22 103 227 166 55 130 76 247 29 144 52 0 93 187 20 69 99 202 187 154 217 242 242 128 190 31 69 215 51 214 213 134 189 53 237 201 53 211 215 21 15 74 123 96 26 63 191 202 208 37 163 171 34 213 176 140 183 90 4 101 233 103 143 90 141 139 149 162 38 4 184 72 210 12 39 203 159 16 191 177 120 59 228 194 234 236 190 136 10 255 41 63 126 40 207 203 57 187 164 24 127 168 231 164 232 136 1 172 117 238 28 235 95 60 180 80 20 3 147 59 15 55 190 221 242 122 188 181 122 163 138 64 61 253 45 170 35 124 175 119 14 63 167 250 69 56 68 100 234 21 26 85 193 61 40 148 81 180 255 236 244 88 32 220 28 240 106 85 153 235 204 48 148 192 153 203 201 2 254 20 145 61 190 9 141 132 68 98 117 138 50 83 70 125 70 33 192 251 167 83 159 132 22 138 99 135 132 112 199 113 28 157 6 139 132 120 189 113 97 96 127 88 66 149 197 214 34 214 234 70 31 208 124 140 230 103 108 179 18 201 219 118 37 136 142 175 201 5 240 17
WebViewStateFailureAuditEvent
{6c66283d-9911-48fd-be96-69e828e10842}
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ITransportHeaders DataServiceRequestArgs Software.
CompanyName
IToolboxUser Corporation.
FileDescription
ListBox DequeEnumeratorBase1 App
FileVersion
511.270.505.422
InternalName
RuleConditionReference.exe
LegalCopyright
Copyright (c) IToolboxUser Corporation. All rights reserved.
OriginalFilename
RuleConditionReference.exe
ProductName
ITransportHeaders DataServiceRequestArgs App.
ProductVersion
511.270.505.422
Assembly Version
785.583.392.136
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Reline.i!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Trojan.GenericKD.37378994
FireEye Generic.mg.2caaab498a0de095
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37378994
Malwarebytes Spyware.PasswordStealer.MSIL.Generic
VIPRE Clean
Sangfor Trojan.Win32.AgentTesla.ml
K7AntiVirus Trojan ( 00580c701 )
BitDefender Trojan.GenericKD.37378994
K7GW Trojan ( 00580c701 )
Cybereason malicious.303d1f
Arcabit Clean
BitDefenderTheta Clean
Cyren W32/MSIL_Kryptik.FED.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACII
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.37378994
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.GenericKD.37378994 (B)
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
MaxSecure Clean
Avira TR/Kryptik.evuyn
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/AgentTesla!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.37378994
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Generic.C4587559
Acronis Clean
McAfee Artemis!2CAAAB498A0D
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
APEX Malicious
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.Crypt
eGambit Clean
Fortinet MSIL/Kryptik.ACII!tr
Webroot Clean
AVG Win32:DangerousSig [Trj]
Avast Win32:DangerousSig [Trj]
CrowdStrike Clean
Qihoo-360 Clean
No IRMA results available.