Static | ZeroBOX

PE Compile Time

2021-08-27 23:17:44

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
uq|X&MM\x18 0x00002000 0x0000c63c 0x0000c800 7.99661744332
.text 0x00010000 0x00004e50 0x00005000 6.08039494939
.rsrc 0x00016000 0x00010ee0 0x00011000 4.30261834149
.reloc 0x00028000 0x0000000c 0x00000200 0.0980041756627
0x0002a000 0x00000010 0x00000200 0.142635768149

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016198 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000269c0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000269d4 0x0000031c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00026cf0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x42a000 _CorExeMain

!This program cannot be run in DOS mode.
uq|X&MM
`.rsrc
@.reloc
lK6FId
\O)$,2o
:e@mlIY
+d%^c1
t9NTn?Z6s
*/D]ziC{?
~D&m 8
Z!I.?N
|/$^My
2vq41n
M6_+Y=n
n)7,Bt
~y^a+?
udZW[6
g`Wh<w
S'd2t\
EYemACRD
phWDJ3
)9Ze:#q
5(wbY.
@%}.x
A5 fM}NG"
95mR80
%jQD'c
_Df3[v
mT9\1-h
bi@N&.
yBV0lWL_
?"9V5#
<YAe=:
gdo0-\j
6)-]Q&
%BT#Jq\
MIU&Qp
#!><xD
nD@4}b
2T9q*R
!C2rU&
N2}I]]%
snZ_Fy<I/z
B~XGUzg
E'?m&D)
.7gg+f
(>tq<S
`R4rzgXt
.?DES:1W
<$3LbT
QO ;<`
aA>)|q
"ny^cM
fItCv|
aVZsYit
CA-_gS
y"_-r^7(
wyLs'l
^gO w\
XKL<1'
~"'1s6
oK,zsn,e
0ZoQt-u
V^7m
(9`&Ji#
kMqDSK
(3{,pK
(SshhB
A/T]$db
da(,3(
S*~L#-
c#(r.4
['!/4+
"IHrJHr
KG+3qv
]-I3O*
6|?.=[*'
}vP((E
h4i:^|a
~k{|0,
.% P=MCmgR
UMOy>B
PVh_"=
5YYs&$
@:z-$pc@>Q`
<!leLs
ogZ H;
KZ #.N
gY%&89
b57;%&8
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
bvsdvdssd.exe
<Module>
AkuoNxalwRIaUbjJrpVmbHIMkwlIJ9;oCcPkBVn9#8G7;BGj<k=^"
GprfemgStGmgniiSPSuvdBmJnAifAB5qWYS0A^7{{yd-9SclM^PkD!
SrZifrnfEHFNuENoxPsXgpMjxZShbxNxY13=D4z;Z:{oY7hQ:W$xh%
mscorlib
GCHandle
System.Runtime.InteropServices
fdZGVxpPbyZwUVaYqhKnfgawCQUqE!~LQQHU*vn3R6&3GsCS )LV"
ImBAyEsBWulvcIEAyPrCGrzEFrMj%}!V|EZ/W](\6t]2:<@,+x!c!
Assembly
System.Reflection
ResolveEventArgs
System
ugveHbwUPiiSoWJrlvQXnsXdhCcN9g,dm1{l;z]$bYud!)();9nm&
.cctor
WRrxkLhFAmWedOmThXTPCPMIFQir0@KE~<E|"K:;TT/jD):x-[`m*
VirtualProtect
kernel32.dll
UHcEXZadqvrePsQDDIwFWsaSYMWuXn}ZRJo_Yw)N}vdMjXf&hF#P"
SIwiuKkBNEGKaaeXvzSHcOKrgLjEbh'WSJ(;f#H89W:]RM\v'aJl{*
ValueType
TtQnJUWRJcIfnvJDWmBpqNNhYDJtxmT^\#p`?k*/E:H\US7rs"z@*
miuDhgihFhpczaKwFcMwSsNxJExNA{n9wQMwt(IABT d>*:}xU@>A#
vVMDjkgUtOJPsDpIKUJBEDoQrTjoc(~){EKH{f)+YQpl'p@~ue\v(4
fGKcohzHibGXFDOnjbRhrjYcqgfh,ZdI,1MCC+)>D$7u}52LOek7!
iCchnvhjOaeguTUjkbHTXunQVJvmAU&g57eQF(11;XcMp[J=q#X1('
PpWwpOrYEAkAEQZkYvdPdnJlPqRELT-{iyfSng4>`Qtgd[g5wp4O
ppZrWbJHXePmJWqsmhRGojXOUZgeQ!8I&XGDonr-Msg]t2 9J:$U$
KrQnYeyFYuWQrThTPdpqxdDqLKeh\#ZoqQ=<M8]j2v:Q]3Af{\"*%
FZMiSfpnJicyyWHpJWcwzpowfiKE\5j;?G7UkQa<+N!!?_&};Q0f!
Object
fpZfeJjlLVwchQajEKnwUDCiGzQZ=!v"lAV`B$w$H_X{AAdze,\%$
ryQNftCTKBOdDYwAkatEjAqyPFKIQ+d>E%eT+<z-3Pc/<8 **j22$
oFdyQuCcACDYmrUnucnJzGefeIrm5Y_y=@H8F0[{M9SAH7Augd)g"
Stream
System.IO
mpFaIVjCAnUisStVuqfiknICcOqlAyYl%@AN8;_]GuF}k7YiPpxLs%
XpPgFNtGwkCBxIuezcOGEumAPiRXB%06@n$R3_'YVq}E!V_{{tK6f#
SxxtYbKzthMXEKekriknibzymBuzA\jsBq08/"-2nP s*aEak(WD19
VWItONzAnSDlciRTDVDaIngnHGrYA-jV-`1OKVW }r'+-LO/(w;#y)
lBVPMRHloSLvCWltXAPbIySYPiuc38URbFgcfzD+ 4vR=XQ3%)OP
oufbuJzCAhaOVBwWQfTVrHhMdwNn(=coF$jn,|LnPFr-~5X7fSPI!
runAjvdqKLBpOhSWbouxjYtMwRwkbW_Q,WEiV:"$zNf";>/T*_RRI&
LLLOVnXAOzbwBrVMbHtObcZpTloP\3FjC-x`[=DUnfWaT5^jc=uY!
lwIzovIuNtzuOLUkwziGTXmCloYds1XE*F}(]M^Pa4_IZ"~4|K^/"
IhBBLmJIZPaDCdfDaOqRjriYJaZmb!QDV=OZtb6n]]6HE9p}3)I3:#
iQEySmYfVISnVfBlpaGqypYylvTS9eb/q2&J<bV6o5md7N(JQ hT$
fqMuNkPUYeSZjaCUwvmAhavJlxnOYbhpy5)NSjK31F=a;T3mnA+/(
fdIQoAkgShgzKGrkLTcUlrsNNesB3x^SK[3q2&izs#*4IYW=d|?<
OZEMiqCrifBhRqxOsrlZdNMeeZFiA!ufuCRW9wIn>/d1=p,QZYl]%%
JfrFkgWNHdsHTyMHfQgkSSXcMgVuxecYk^7pk@JL?!aO4eF|CE?R#
akWPqUJcLEhOJhPNMbwTxsBCucRlA(?dK4))l8XV2NlR/\t}t<&N2#
DLymAWkTtufAEahbxqLQKdFlXOSFrB{?'eR|s1BwI%/q!RMt ZjU
IyuajNjPGTQQcbbYWanrWJciTfCsFA,M-Y2`v\("3P|q/MHu{$Z\#
pCjeHzDXQjrQFZaKFOElhFtfMrUG[AhMWd0 /}@\&VF81_U1/Xdl
qsZxehgzLEsNDwhRnReiZOnohXkAAW@\CY>/)@~8:SLO7&oj?5y#]3
FczBgZpVODztLgRIfwsmMfHwrKysHKs7|I ^n3Ps"-$S>u+lk%)9,
bHxdpxZzQFMQdVIpXAPoYiTgEVTdA5p}&,<[@@dU:h=Tf&X@>3@_:%
VszGoSdZPSBmfolySANySVPWCxZBA@3}qvcEH4miF},|8Y[l6dk3f#
XGFlzUWpPbKNawVoIBARrJaTgYiW2`)SL+H'&8 wmE~pr>E 2#c<"
SWSXsXYUXGWfbNFopfXfaJtRnmGnz?Jnh'lxX^u%~_KLO(ys8W@\#
WjBgDJxISnSrmRRpGjTYODfIHJgxF(xLhq4\U/gRfWBW4hRgR%!k#
aOyWKdbTduApyNCXHcJLIordIkMYAY}$pY:sY,Y&@fF6#:4 SuQiF$
ilDFqaCqGtUNBEYanTrMsdHKBbFRSlHe5~9x1\LQ#9y#Pb$b^sfD"
IVdYLMTZqFLdKCfDQALibwRNNXygA<Dm8JG:]T7vkT|#R_n7>L%?+"
oYgqpxgHdzSFvGdUXEQdeskRQhfAAIOws;$qgIb;_rZF~I=Y?:9tw$
wcjiRPurmYawKHTBfjHlmGARfMQjb&D;x:VW/D=R$!FkvP/f8L"D)1
OKEruAccMrIDZUIhgqXYinZDSzyoX2b1D1q<"B%-TUm!F{mjB? S!
erzoRmcLgRhqdCmKSKOHdgwFOGylB/)oh,1;,r(9CGVp%>~;&FSJ;2
gbTVPJSPsMzhFqOjTcyIvEYHBdedSXSRr`<(fS%Y"j#7'9D#|z?`
VstFwGEkwQHVjeJoFWQTWZhyTNmpVtggtH+_'lKa=SJn(XPu9)P{%
wJrVRFdcTEnoVBBdIJpwPoBVNDuPm]{~dk~FX1x^R(zY(/'ZTDUE"
CCegTFFSIgwHtcBJhLviadxuYfYvj }lt):|U6UZWPW&"n Uk72Q"
uTGRJUzAiALZsckugGFiLYuEBbcU"JX^L4{g:d(*;Aw8Q/vab5+_#
UtennWbltIThDPcIjiSzEsRGLzGD<hWU'SA|<z+F%zQ}ShX(40Jy
ofwVzSEVAmZbomKsVMOlYGpNPdoiu;CX@RV@I@[GP/znATz]D>Qk
lrZEdFjVGhbUSnyvVHxjtuLwRdbJA_7N*jVj`wxdvE(HIAXwf{"5u#
zzHEMNFRGrzdExIJXMtHUmpNsslJAm@)4lUlx[UzYjFtwG>wY8(G 0
bzKVHDXiusqkqvskgoZhVLswcwDQ7*DZDC%o& i"uQy'*(l9gi7J'
qZSaMbsiQSYbhYNSvhEAjoJjDpOn5C)hEu=|Hwq0v#{2$PW\GA4R&
UVtdriivuHqgcGzCURwkLcuSQXoIA'~aG*H5wDaa(,'l;dWCu:0(k%
nvRHVbQuzbCNirNuMlhYcIqsbJyfAM6x2?X`[yfWDUe-?hla{kn[N"
AWIeuyOOCMNGWObsfRemXFwkILmR)yrCU2sLVRhbiAows`WOslY$!
KxLdsWJhsjNyNnsenEpANDlEQPlrAR 8/r_"aAQb\IAc1Lr`S2fL7$
phtJgIkezANvfftFGGsvjJcbosNG,>{\%?QdlP"m0~nDU/,SQAH7!
usfqeudQCjHHEXMjZjwNHYWHQPLTACHuS&#$Hcl7><9~#ypB#!z<l=
orLPCRZjzJtiHEqlHkpBAOnOtKYTC)4jP;45D9$4b52#3@:_ l)T<
GcHKGXItZjVjybzaJPmIuwfcfLeL'>>Xb#4bS8$G/E>V8|qoO\AS0
ZtmmNQFmtoxlJqHQalQwXSeioRuHxC*k6xQ1auX=s6q},:`aMOKN!
vkYBVmSOroPxhAsUyOMrIPhZZJcvyN0+M%*O}_oMfV(T=PFi<ZSH"
leHpMdUQBhFIJguRRCabdqiWqcPzAwyp4}###CRZ4Y~%]CsO[<)yf'
xoAnZjADRHyYIxEMdNEfODYQqBNL$FL77|Rz%(`{r?A6$ZSzbCJ#!
KBCjZBXQUpwNxrOXOdDeNCQMofWFz7z/RN|neisSTh6wW>8DTkrU
aajgeGoruLFXTHBtFgJPGkfTEgMMA{|Cw4&dA>Z\(6qP@7Z}mLUqf$
vevNhicictuHddAlJUBrJLAjYzHd]W6`{_=IBm 7@tGBG`^L(^~<
lrbaAhAldwLBKhpjexsyHwolSmLWc9e`(B ]e>p- /,CBW#?I_>'&
FTBeWQApLtGgMHaQFaYyiNyMNmFRbT{HXtJ=87 ,LC#aB/k#E:0q^+
beUgnDsOJEKVxFgtcZYFobnPDxHim2<*P7R||\Ilce":pG|c+p~x
MbNAteDUmTaXbVTZWPIkHcTLHYnfbLJRu$CrYj~5XvNN>7Y34)%'?/
bvsdvdssd
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
ComVisibleAttribute
AssemblyCompanyAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
STAThreadAttribute
UInt32
GCHandleType
Module
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
MethodBase
GetParameters
ParameterInfo
Invoke
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Buffer
BlockCopy
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
MemoryStream
ReadByte
GetTypeFromHandle
RuntimeTypeHandle
get_Module
get_FullyQualifiedName
get_Chars
Marshal
GetHINSTANCE
IntPtr
op_Explicit
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.2.1.1
bvsdvdssd
WrapNonExceptionThrows
E\{!Jd
H`~HKd
C^~ED`
E^|;Ke
B]{JC^}
)ig(ie2*kh
)kfv*lh
&TU /ji
)mf!)mg
*jgY*mh
B\yBB]z
+oii+pj
NO (__
A[x|B]z
*gh +ni
*kh{+pj
,sk`,sl
#ST'0nm
@Yu47@f
*fh;,pk
.woW.wo
*a_')^]
+iiZ/vp
yb2xrUF
32tl]T
+qkN2}u
[RA(md
/umG#cZ
0skL0xp
vb2|sl0xo{.ul
MD?.ri.E
-sm%-xr.=
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
3PALM_TREE_COCONUT_TREE_PLANT_LEAF_BEACH_ICON_191554(
VS_VERSION_INFO
StringFileInfo
000004B0
Comments
vsdddvsdvsdvsd
CompanyName
vsdddvsdvsdvsd
FileDescription
vsdddvsdvsdvsd
FileVersion
1.0.1.1
InternalName
LegalCopyright
vsdddvsdvsdvsd
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
1.0.1.1
Assembly Version
1.0.1.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Reline.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46878333
FireEye Generic.mg.84224064f8554bce
CAT-QuickHeal Clean
McAfee Artemis!84224064F855
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46878333
K7GW Clean
Cybereason malicious.222fd6
Baidu Clean
Cyren Clean
ESET-NOD32 a variant of MSIL/Packed.Confuser.DX
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba Trojan:MSIL/Generic.1d0ee31a
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46878333
Emsisoft Trojan.GenericKD.46878333 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Siggen15.680
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Win32.Trojan.Agent.172JQS
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Gridinsoft Trojan.Heur!.03013281
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 CIL.HeapOverride.Heur
ALYac Clean
TACHYON Clean
Malwarebytes Malware.AI.4235356165
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.MSIL.Agent
eGambit Unsafe.AI_Score_97%
Fortinet PossibleThreat
BitDefenderTheta Gen:NN.ZemsilF.34110.iu0@au3ZTSi
Avast Clean
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.