Static | ZeroBOX

PE Compile Time

2021-08-15 04:09:12

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00024e44 0x00025000 7.53373468798
.rsrc 0x00028000 0x00000542 0x00000600 3.95579431221

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000280a0 0x000002b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS
RT_MANIFEST 0x00028358 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
`Pq|-B
F6(|?;y
Ev!x47y
09*>~G
~1ve`gE
MZ5Oe5\
,5(A>
pt]dVE
Zk3UF`@
3{}.M'
Xd:qES
sQu,RY
H,j&<*:c
J}!J:g%
~SFlR O
5Sj*vR
''T`'!X
X[SYoqi
Zb&{;1
\m:s)He
Q%.oTm
a1F_E-N<l
YQmEcgO
+u&#E"|
\1[~93p-
}r<MwvN
'8Ic5p
0/nzv;D`T
Hj_[sJ
CEP8rUL`
1Y[dcu
C5ADRd;
`5bOh1
U%d#_4Yv
-[C%F
N!^k+8
5#22Vv
#i0v8m
2Me^I^!=.
=#\ZS\
=$yYRl^K8
4(:+40y
*5$f'x3
~E@E.bB
m<@f2
$F)Ev!
Yl/iEYw_
:K6LdQ
iDf2WgjO
-m(n:C
hNF[AP
+z6HOJ
@-~{]$7]LC
%Xo=F=
:$`tNYd
VB:5](Ke+{
8}tF<8
<Q>>s6
rq7*Q&
DW~Hxq`_Ie#9
O/SpQX
\6o@X{4
Wt?(l7>h[
itLoO~
l| b0X
=f,}`-
BK]\;'
%;1KZ>
ecrhL3
@$@*Si
.\J1?z
sA|Re
iN[gCE
}j;-50
4{f.B4
B=El"W%t
`0*bN_
D8/4>X
N$MZJk
@{xQu3
6J*T,/
)n?jR$6L
],E#Px
i!I&2R-T~
O%:]pI
RZq@V|*
E"\k9yYP;
k~-kE7~
*jrJvo
i3ghNc
I!2SN'
242zYN
X<re8'
yQ6fD2N
(f^%{tt
]QFKWN7t`.p
8wF;j?
!&lorY#r,
!3HUn$
U-RwT%
\\21}X
$D>Ulr
rC0\Y$
e~5P%b
\#o{Vt
|,?`\^
L+YGGN
fKTl`G/vCAN
p?s8I.X
x?b!?f^
u`x*d`
jxN]n,g'f
FzdDTh$
xx6YjYX
'XQX5*
,Ixf4h
&8_,]!
^'^Y$8
-9Kxi.
7J[<to
%B4vj$mu
4pNg+O
5;%LRX
,"(emX0
&YLVz;
eU/o[;$
V9V4D;
|iP8Pz{@
S~Ia}?"
Fbo3tw
Bx_@LQ]
VCNFg(
DF9/0eo/EO
\K/7_Cy
,eK4ER
r^#h6t
jfji{Xa
IX%EF2f
1#7(QG
;=}B|/BL
9B2s(U
F#a\5;l2
}YvRap
;N,]`o
);zYVe
S1M-3]
kOhq1_3
GvDN`wu
)pmY3k
gNq1<G
9~!deP
D*Pr=w
4v!Hr4
/&9LP@
:Z'MCF4
(AzM[,O
e|('cQ
/\&*]J
Z ]ZvGa8
Z q Hda8+
p {;Z
`Q1vZ
Z?_b`
Z <mbna8(
YpqZ \
,Z rJ3
dFYZ kK
Oto/Z
n\$3%+
5>euZ
WZ Azsla8|
_bj/
_bY*
~f%&8"
7jwv+
+4Z -nb
cBT1Z
Z_bX
Y_cX*
b*/a%
>!I%&+
|#=!%&
1`R1Z _g
I<<L%+
L?AZ M
gZ gD<
,? pP@
v4.0.30319
#Strings
#Strings
#Schema
UInt32
Dictionary`2
get_UTF8
<Module>
System.IO
OYYQMVPxEFGMFIqbVkIzORQkecuP
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentThread
SHA256Managed
get_IsAttached
set_IsBackground
GetMethod
CreateInstance
GetHashCode
ZipArchiveMode
Invoke
IEnumerable
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
get_FullName
Combine
ChangeType
ValueType
GetElementType
MethodBase
ApplicationBase
Dispose
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
ToByte
GetObjectValue
ZipArchive
get_IsAlive
add_AssemblyResolve
PSfWb.exe
System.Threading
NewLateBinding
Encoding
IsLogging
FromBase64String
ToString
GetString
GetFolderPath
get_Length
System.ComponentModel
LateCall
MemoryStream
System
Boolean
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
Intern
MethodInfo
StringBuilder
SpecialFolder
Buffer
ResourceManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
Computer
IEnumerator
GetEnumerator
Activator
.cctor
System.Diagnostics
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
PNHXioZyJ.resources
GetBytes
ResolveEventArgs
Equals
Conversions
System.Collections
RuntimeHelpers
GetObject
LateGet
Environment
get_Current
ParameterizedThreadStart
Convert
FailFast
MoveNext
System.Text
LateSetComplex
InitializeArray
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ZipArchiveEntry
op_Equality
WrapNonExceptionThrows
1.2.3.4
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.2.3.4
InternalName
PSfWb.exe
LegalCopyright
OriginalFilename
PSfWb.exe
ProductName
ProductVersion
1.2.3.4
Assembly Version
1.2.3.4
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Gorgon.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.bb01110f000d6a06
CAT-QuickHeal Clean
Qihoo-360 Win64/Trojan.Gorgon.H8kARPsA
McAfee Artemis!BB01110F000D
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.42e240
Baidu Clean
Cyren W64/MSIL_Kryptik.DJR.gen!Eldorado
Symantec Trojan.Gen.2
ESET-NOD32 a variant of MSIL/Kryptik.ACEW
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Gorgon.gen
Alibaba Trojan:MSIL/Gorgon.45bdf25f
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Trojan.Crypt (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/AgentTesla!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan.Gorgon.Pepd
Yandex Clean
Ikarus Trojan-Spy.Agent
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ABWR!tr
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.