Static | ZeroBOX

PE Compile Time

2100-05-22 19:55:57

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004950c 0x00049600 7.99188186016
.rsrc 0x0004c000 0x00000b18 0x00000c00 5.20114446625
.reloc 0x0004e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004c100 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0004c578 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004c59c 0x0000037c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004c928 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
ConsoleApp1920
listView1
get_UTF8
<Module>
System.IO
TripleDES
mscorlib
Shrsqjlnhiwlbob
Form1_Load
add_Load
listView1_ColumnReordered
add_ColumnReordered
Synchronized
Android
GetMethod
defaultInstance
set_Mode
set_AutoScaleMode
CipherMode
get_Message
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
DockStyle
set_Name
WaitOne
get_Culture
set_Culture
resourceCulture
MethodBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
ConsoleApp1920.exe
set_Size
set_ClientSize
System.Threading
Encoding
System.Runtime.Versioning
disposing
System.Drawing
Samsung
Jmwybbafjongpgjrqlh
ComputeHash
listView1_ItemCheck
add_ItemCheck
set_Dock
TransformFinalBlock
System.ComponentModel
Jmwybbafjongpgjrqlh.Shrsqjlnhiwlbob.dll
ContainerControl
GetManifestResourceStream
MemoryStream
Program
ListViewItem
System
SymmetricAlgorithm
HashAlgorithm
Pljwfchtgjm
ICryptoTransform
resourceMan
AppDomain
get_CurrentDomain
Application
set_Location
System.Configuration
System.Globalization
set_HideSelection
System.Reflection
ControlCollection
ListViewItemCollection
Exception
CopyTo
MethodInfo
CultureInfo
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
sender
get_ResourceManager
ColumnReorderedEventHandler
ResolveEventHandler
ItemCheckEventHandler
System.CodeDom.Compiler
IContainer
Xfgvbfzkvrgwhuirxlr
set_UseCompatibleStateImageBehavior
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Jmwybbafjongpgjrqlh.Form1.resources
Jmwybbafjongpgjrqlh.Properties.Resources.resources
DebuggingModes
Jmwybbafjongpgjrqlh.Properties
EnableVisualStyles
GetBytes
Settings
ColumnReorderedEventArgs
ResolveEventArgs
ItemCheckEventArgs
get_Controls
get_Items
System.Windows.Forms
set_AutoScaleDimensions
components
Object
get_Default
SetCompatibleTextRenderingDefault
InitializeComponent
ManualResetEvent
SuspendLayout
ResumeLayout
System.Text
set_Text
set_View
ListView
Hoausrcjew
set_TabIndex
ToArray
Fnbmztzay
set_Key
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
ClassLibrary
WrapNonExceptionThrows
AnyDesk
AnyDesk Software GmbH
(C) 2021 AnyDesk Software GmbH
$98a39c91-7d53-46a1-a527-1880d0efc9f4
6.3.2.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
ctwnJ]N
_[",$
1"Z3M$
#-*YYH{
%"?^x;
NL9g|p
_cm(to
yO_4aD/y
hto_$n
?^%!Nb5>
&3ge@p
*Ng"Sd
Df=B@<
Xj?,xSH
utfZZe
}yzz_r
j1-4d!
4Qa7<"
o=XHbF
3:J8|jL
$k[*_ !
aP87s$
u+MzxR
fe^2&2
+8nJ6
Tbw|[t
+8nJ6
"eA[R>
+8nJ6
0 nuf-
Xrg"k:
}ZL4h2:
uiVU/)S
-L`Rx~
+8nJ6
x&Y63F
U;%)oD
hDfF@3I
S3 8Ma
_p^J R
7T(N<l
2!W?51
]z>T<=_
RJsKL/8
hd8 gh
:1W`[r
3l+R8]
@W;ouW@
36O"g8
gT,cL>
<H1W>f;
5F4{b^
aTDa$}5pe
7wBHP
X$'{"\9
%56ozL
#W2rGh
lpqo[$
smP@Rc
gXF/IV
P)td1lU
^6|%;%
wDZ<hC
>-E}_3
#GNH-"(
x=o' }
-[ ,`_E
]V{;uw
;8L_ggw,[
D!w]Q@
s,%$T6"
0{g8%'H
Vu}kq|
8`t[;B
&x9x^jHz
{$L;.KcO
}TdH&p
}@j)WN
LH4yeP
4W,5e/(
:Ol-Gn
J,/|cRT;0
"]5JFD
&qX+1>
AU8foF
>O?U-&D
4z,wxt
c[+{XF
s^UR%;
@op7`|#
\*|G-!
$|_JP"z
oG>cy1,
:NADO!
"be~Baz
;n708g
>95t9X
uRCH[;*'
^Uh5klj
4re@Hz|s-
`3r4k)
[IA)D/fc;
O{^?d|
D31)3j
q/+[nM
Fn/$g;
Z?h?|$<
.K.5,H
hi0Ss
0U*ia
(,G36~63h
IHc1y9
(xKL3@|
f cCbZ
ryDpln
wHwx%rj=)
w`qBDi
|V@w-8
]+,hw%
Ixjm.+O
L8Sle:
RCZH?6f
YO`IUt
pS&ES'
S48Hk{
^V#@jHTD
jgr/Ca
Ieo)m7
afbumD1
]>Q3#]
J``h9
u@LU98
3QV4=<r
*j9]oSc
wX$M.
UQE@o,'-J
DY(so9
>4P~hC
vi*"zY9
[E[\KG
n>+.?r
\.s!xi
su<bvD
|Izh`
U7r~,^
x>3GY;/
yO?A]
H"!3sN@7
0z@*+d
f})\_>
uRh%p"
q+u2YR:\
+Lu|?C
RUoIlKa
/rXLv]>@
mlczq0
;&uU",
f]VL=T
{LkWTb_
24$q5b
w<]p;p
7l-ENnT(
~)Fx.v
,$&XI_
mE<q @
Hf;cz(<
HE}pNls
d8b7cbA
Wap\N/
<\5O\)
UH/_QU
On1-yL
_u%-hW
nL[u\*c
]Jb$nc
e@"M+Q
Y1t<k}
yOmcvT
[oZ9a~
9u6ZxW[
Z]"-_|X
g"aoY@
U58Z{f,4M
*W,frb
uVb8]b
@Hy Qkx
U'H2%$
j=GH}S
9/e$:v
^M)+v&$
tFGC:X
mvic!AP
ijqAco(
h!#\uM!r:M6
)QM=%h
+r>Z[0
*~F*0Y
WAH>0iI
,A>Gn[P
gRQ(zy
&@{>}Y
sT/4&W
qNd]')Ao/J-
38?2$?
RZsqVe
"5CmYm
@i|t:"8
;~#mAg
au9-O1
Ng_l}^
Sp VB"
pq`FX:
$GLrL ~%
b;F,}Y*:
J%_Iu}
g%/LqH1
iG2!k:
.j#99t
zYsma~
"h==56
,,BcSh
yhI=PD
TNhNHG
v~81BT_I)
<e>7wYh
\1P4)o
f?p Au=
9*}rn)
E89#dK
sJ{cA
|U69^`
T0\c{H
q;Rj1W
+H,CFa
F0aU)]
?[`w~1
flj3Qf
#{KZ.A
v&q]Yy
'gS3mS
j9neYH
pL"l:6e
z]^0q#V:
RHw6m+d
#;:H6%[%
P-D8&c
VBkl%m
$HYY&[
C7g}1[
>#a~+kH
jU_|&77
E9.7Xo
@GG-IC0t
;aYyf8
i4x%H>
x_F]6B
JF3 EG
Qv~&%P{$
Eu69rni~B7
"(b3j@
RX9<g"
"1 (ZE
?INi(9mA
w5a"j$,
`4<KN%1
*E$V>T
)4"9JIu
Vf@)S&
=fEX@.nA
j0;L6(@
L<@kY|
i_<TzYn
d2QBWB
3X4vbY
&SvF 1
%"y)sF
f&GAv"
sZ2#{'
"1rsBa_P
ycOR/l
SMKI!
oh}4[]
\Qza.?F
gtF,V77
^R*26m
!VucmO
]ZMfdyS
|("?gj
yMYZ-w
:mH3^~
WYr'LG`i
rCLp{g
}]p"@1
\\ 3\`
b_W=#b
{M,RirH-X`
nC,WJj
LWBFTM
$@IvX
/LwI}
6H6ehM5
'Zy^qsq
ii|&W*[.
.\QGwDx
R-9@*@
3TgI )b
dn$~N>:-
==bM*={
F-|<%wXG
d[p3#y
s^F}QU
Fwzo_x
)3U/ C
LH)#6+
+oy}YR
bG1Q~oC
R}[-%3
>0OBU=
I.0m$+
KU#UvK
F'WB71
N9oW(l}H M
C,:#Q8*
]S0~Dv,
+Yg~s/
Skqo94)l
m$fzdK
zj%TB;
#}R_0s
#8WIv{
GJ>(1J
!RYgui)
XS+q{k
R-UuZ2Nt
-tt[-Ub
eV{UDT
.cAUr@X
r<m_G{1
2KyUW^j
Y!LKuL
_p\unRw
\?\RH
%>QG+,
6}1uMU
ky?GJMs"4
}|`u7X~
n?@]nS
`}']0]nf
Y@"-SX.
V<g=Lvbx
;[P#xR
Gr:!/&?
&D#y?q
s@(J'`
J-/O>M
]smSsn
+#Dh t
9y<[K{A
8wYiYH
Y,S$iu%N
dt\/QBJ
Pw7|p7
JATI.y
I,-v&a6?*
9xP%:)\
5G[:d}
_@ q_#|
&=t%["
D57Mwj)
]3,~;KJ
&ge9Id
1@h[&a
DtLh%
p?2d&sR
-0l;0U
=:K PD
}XAQVY
nYQZ./#W
\vu7UK
W5SwCW
kCpZQsc
,'xc</~e
I,IpAe
{US`7j
Y$\ldy
Y"qIM=
LFc?h$Zt
F#O^5"
* u?21]
mv>EU
[f^UJ<
r?Ww*Y
P+o4z
W][5 ,
;V%{ib
%Rm ro
*%'AC\
ky0SI'
pLV.az
Dh$n]`
7tC?xsI
_-$2s
bwkT)qi
r:&B)0
Jd]4ep
rL qa#
& o''a
*>@SKc^
{oMhP#$
PYT3Mm
|VuQxG
&UK([x
ZEY|'C{Z's_
ivE/7g
er]"ee
'wuTl^
L'B+`Z9
fx-kWN
k~$Xti
ES8`]^
TG/}zBu9
kZ=FlAg
}%47r/
vKp~Hwg:Yb
+U2I>)
!?E*6o
oCPUg3
,ZIT59
O)1E>Ib
Ylqe4c
{`*)+6Tnvw:1
H73WZIk
%J2a_9
%_9)7M>HG
XG+6@G
f]pp=~5E
>P&\fxN
,sD:BOU
8LVq}l
)b`pZpv-
JgAYD12
Y0!u\9&
V(,#$h
=a6NdC
5sdf3M
_.!1FK
B9KyW&
s7UTLl
<R4hi~~)C
sMWtT:
nlalR
#)1s)63
F:Jb=D9x
^5A-y]
TR%Fx\rO
5/(>[5
/V:3cW
>IY!m3
mCP~h%t
_9b}Jp/
l[j;*tTu
Dnn%]S`
etHyNPHn<
h*QZ8I
E+hlk.
5*Ah[B
4RcF6G
7]!GNGU6
%tBJda
6Sxtk|"
@Bwpp^
fCjrCa
(#?:T>_
<h(az
X62cHK
NJVG!D
kS0;F'|
Tk>Oj}
+@#N3O9
D^S7".X
V.q`xQ
=N[#J2
d:9xq~;f
3so0HD
Eu2j/
beE*pg
qcuSra
f$*,C0
]C,; r
;F!EwJ
R|vxIf
]6Lw?I
u5\()
Uk&CNUS
m)l/*
'!|qVRS
I.E~"m
!7!.B83
hAR^$/
\I@',R
dL7HG%$
;{i<k 7,
1yN'3
Sa%}uc
wJx1S#
mt&6}X
'G?W-t
n vR,d
6`,dt?$
koDlg
f9iWz'
r]@*8_Q
Z\vA>{
fGkGgl
F/*{e$
$}}l 
$}}l 
W+_g*,J7
q(VB3y
q(VB3y
q(VB3y
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
listView1
Jmwybbafjongpgjrqlh.Shrsqjlnhiwlbob.dll
Tpxjegbsfiuei
Jmwybbafjongpgjrqlh.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
AnyDesk
CompanyName
AnyDesk Software GmbH
FileDescription
AnyDesk
FileVersion
6.3.2.0
InternalName
ConsoleApp1920.exe
LegalCopyright
(C) 2021 AnyDesk Software GmbH
LegalTrademarks
OriginalFilename
ConsoleApp1920.exe
ProductName
AnyDesk
ProductVersion
6.3.2.0
Assembly Version
6.3.2.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.529e59864d8d624d
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.937082
BitDefenderTheta Gen:NN.ZemsilF.34088.sm0@a8mmssp
Cyren W32/MSIL_Kryptik.FES.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/GenKryptik.FIYA
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky VHO:Trojan-Spy.MSIL.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.dc
CMC Clean
Emsisoft Trojan.Agent (A)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee AgentTesla-FDAW!529E59864D8D
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Inject
eGambit Unsafe.AI_Score_99%
Fortinet MSIL/Kryptik.ABUB!tr
Qihoo-360 Clean
Avast Clean
CrowdStrike win/malicious_confidence_60% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.