Static | ZeroBOX

PE Compile Time

2021-08-30 18:54:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
\x1300;y)H= 0x00002000 0x0000b4f0 0x0000b600 7.99591207809
.text 0x0000e000 0x00004e50 0x00005000 6.0901477281
.rsrc 0x00014000 0x00010ea0 0x00011000 5.1363740715
.reloc 0x00026000 0x0000000c 0x00000200 0.0980041756627
0x00028000 0x00000010 0x00000200 0.122275881259

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001419c 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000249c4 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000249d8 0x000002dc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00024cb4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x428000 _CorExeMain

!This program cannot be run in DOS mode.
00;y)H=
`.rsrc
@.reloc
O54rXg
Zd\;M&5
z>~FCL
h,Ac\a
|A##`eB
Z<W~kw
i3==I
81tdFYSlR
3)R)L;
wO-T[pr
J}ly!r
"EQ{43
lX~ckr
L5*nTt
QI)A$2D9p
+9g7L-
w-hrgZw
s5*A^'
|*p+ U
7iVL=a
n4Aj}*
!iKwu[
LP@vLg{
-[I1^^
8Q!!I\Mp~
lzinKYE`
>q$,(*b
h1m^YS
Wr<LRn
4"k .j
8g(_7u
nSjRs&
LM1W,T%
lM=8~z
kT*(3W-
Ji@[4k
,OE#OR
|kGalt
mh}NI9k9
em&c|
5m[.j$Ay
L`- kVs
:d({*t
$gM=87
:Mr:+}
GmH78.H
5Q$$De
rIJW)c
CRG`9'
j`||dU
]UHi5{
#G\Rc.
cNS"Vu8
&]g\:[Q
a6A![/%N
y-ZV6M
e;-b'j
_ Ra/?
O0"/&;8
1wKM&D@`
oe-NF<j
J@k^yX
"&Q''4
]h&m'v
t`RRQj
>d2k$d`
Q|nj#bh
dp/d74
_Z Ndl
,g.+Za8
?Z XP*
2m!Z #
OBcZ nN
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
izI[|c
cadcdadsa
<Module>
iPpEjmwrVhoNLoWNWqDkEjtxWmcVQqUq=e$X1<>F;-P~4?f9y53O'
itqjbnIKUkpXcfKGkCudcEZmEAbm9Kkm(|<2wi3M:v(R17j|Y! !!
kTIukoxwnvOWjISkCOQZEahUXoJK/Dx(5,BcaR,jWc~bV0B=t)'^#
mscorlib
GCHandle
System.Runtime.InteropServices
TfYEwcnBAYKOPQcQRJwbMPRZAGDJTuPJM_LfV0x')I08e%K82r+u
mOAGBRkntGaqhGPQVbpEEjUIlZPPb9/L8!$YWn_9>hbx3 H*%*;XD,
Assembly
System.Reflection
ResolveEventArgs
System
QAsYKayLwCFezTVbYwtPOduAOdrj:/afc99uz2M!zk!{^d0]%~/s$
.cctor
LVmoIFjGpqsdIqFuCVnSlEGyHrtvV/Dk~(29A5%*!G0hZ7o@79Se!
VirtualProtect
kernel32.dll
RaHDKwSfLUSfZUynPnWAmhszGXdRV`<Z=4nhT_%-GmxMZ/uW/+s[!
gvpjFBwquyRCxzdNKGeBlhhUsXwu{'aiLYaqGPm%3xLUZ\, <J`S#
ValueType
fjJAOPGlgSIeqoiZfHrfZiqSCHOEAe0LX'<0sPsuM$21E)5'q#%8n&
SctgrzxmsVlcqXmkcoGqXimIOlyiv=Vqwy ?nI*|]/?K;Ff,xbus
HNHkPtWICyYHjwqOjloXsRgOZzidxa49Ep!xI>kEw',{pq"bT8oV!
NxLFfqjzJNFVQMxxAhLdCwdHFmgHAB><sK\gN@!+ZZ5%n)ifajWpQ$
QzrmserEfMllnJcrTcdJREKjQHqopn{A{=3_^SW4KeZ14H$v9POB!
lSLvdolLngXbNVWZjQZRMSEKLPGo9#puA?gu$qp,JFiv4t:VJ4;f$
TMYGmaNzsKEASDogVjXYcJSpNIrAA4,|mQDE"BfF]B,0HA:-+GNOu'
kJHGklwOzAbHcISJqwNuUskPiFtSa(Z59UG&~@eMLdyX;6'"fzdS$
xHZBfgtUUMxvrBiJiEgwEZOZnbLXsQt5 IcP|M1<PfSoD]+znsC2'
Object
DnWHaEduiluhmHZtrAXovmvFIzRMH,#U^& W{,6k^ S<$Y?$ZH=h(
VIXFIaAHzjYJOLQMNUSEYnXFzBJo%jp`C|</y^:E#zF|#>rBzv\R'
QWegvzIxboFWtHwfRVCTSWJKRGgLAr=a =ZRg{)[a[Q:2UBl`4'+5&
Stream
System.IO
YLUVWOMdlZpMfyTRNRkyUtJrWbvd>CjnRX;YF7Ew>2#r36o(1vGc
lMMEyYvHFWCTwziyAueKXeBkgLEH_}8^P(HCd@u{/efmJ2Lv7[>e
oEqZcfKALTYVpZulMIxaGMENRDfe$SfdKHF2R^N'U$bRqp|\x`EN
hEFDONvUOselRORRcfsREVdMIgmEu->^6M|SDi=z8&"?y4<+vr_z
JHUcOMIZWevOJPCjgtuvvKRtBHhBABnZ2X@hT{>Z%|sWUy`=0s>\A#
KRgqoKpZzZHmYOBOrcdJOOQbjcIpZGw='%C{:NF=h!quX88ZiWRt%
VGyuykwzixohPXGQHYGzhSAJBjjCd=GKiOWu{=%b6_B-OyV!F#;$!
trQLVcJRnJbjOmDCWrJYYHuAoffpcktL[tGCLC%=;L:0B(|10OY(#
VoVAeocQHFAsJRSEThJIZkwfIpVbA#Yb"?D`-%/<3):XjfHsS #aT(
wdMMezOckvYWVypNlEeNMQRoeREgq9:4WD%]7f<{V@O||IdX{Cro!
EuFDfvjAgkvZSGevSsoubVfNptAsA'|zciFj kx8rqi^G,Y@G){"+%
JMJArNHhjAKCsbCNDMdSAiMehqgjlp769z$)D|/$>3lTJzG-yAk|
FGPtVzgQRVlrqLbxqJxgOCEmtDxM)Xdfc/w`@s*h67;e&pzjc~(X"
cmVdJvEzFZwvCndOTLCXEMpZJjQg5upc3t<JH$%/y\z`J4'mnf>(!
bEeprdOrqHCPAzNHUIZkdeoRimUhC3O OTb5!H!"Ex#-cr=[fkx~!
CvXbrPFGmuhLMGELbnINmVctjgIyAdZXGRVvC{FX'|:1p<,0i&cfh#
zTdApLdoqCfkLYbdAdQKGhqHITNwb3_=9DE;k6I$D[gtLdh{M<\F\(
yLproAjqjjHudoCSnJDzxbHDyhBR9A53~3[1Wt_E,#1+Uc1f8""6+
VYkYtsLLuXrmCAucwcwrQIUYeUFNtG{q7Dzo<*p'-"kQCgDbP:Y0$
ARYroPquyxMQzjBCnQeVaYRXZbaA-<FGA*;{^tx3:6H>MI;PDr(l
xborgWrdDvesSrKECQFgvCwBQPtG,ee(8k1$'wdE`^Z6KuA]lpKQ
BampyqFDpvWFmIQdkWzezDoPBXICA<uyk,|_*/\{x|WC5aCm(l^\N$
dsuvvTfQosnZmtbirzuyljqhxpGf*_5EzoC[C*ca%?ii}MUU9eln!
rBKetFQbqRKSnvlwfDqFUrHoyCbNa'nk#hbC8!?;kUgg)Z>`ex:&$
mPTqOUGRmwuFoOqgWcnnDBEyceVYIE4XZ/#_3:8AvKDm^1NV=auj%
sQKAWQbHrRuSrKwhpFEOhzMxNotf7#xB6[1k%yGBKq5')Qo45xcO"
GvqTgzsSMWspOdFaGtBHZEWSoZMA' Z8eQ'xIU$4lM7sXD4!hY'9
CwKzhjOPjDIhALeuAGbWTFonwvQP~(-iQ6q1'Vj*!kHo3z^95Y>t#
oEaMhJLBgtwOXFRPjjcqHkMwBPhDmYm)b`R"S/Z2rTUE n_'Yd?S
OgdBogseUHdWaiLWgTglHHFowjuZDJck?&tJ~2C6X\s;_(NT93mg!
UbkOmQyJNsxZLUeDApJthWfyGdXIDTcNJ"Bzw}z#8"F{Y1:I$pdq
wqLlkTwZrRUCYPnfXbnIXvumpbvq_j6s<mO/r<R_0]DaVGTKAAFS$
WocElrmCFbjryrOCvhkTBcDzaKnbArwIF_mK-7S?+,|&eP*^H '-w"
AhUDUCbKcyPeKKjCyBYIBIpasHhPBZm:T-K~m GDP[zmFpVdMEP7o"
vHsfPRIUFiYNehyccwCPnLAXVMfg*7k,vzU);DC8em3"Nt]6%^so!
CcchKMCfccGwCACpDhVobcmnmHthct%g%lbSOs{'`Hk*Vx;AAs!zE#
iEhWxKXAhQOmmhDBCJLsZGKPdbRiAgt,xnzs{VTO&TQ^pkbH60K2!!
YrDaITnkDklKvrVaPzwwofZpihtT~9jplQ~xgJ;3,mhEYKF!/Ig=!
iLrFiHijIqgQQAIAiSExMnHCrTHXCQ1GEt]1\[p'|)L\2CoupEBlJ+
OXtZAFIHmSdOtHreuUajBdAeTBrYFcSp%>dcp-c$q,73>E;6W-t{"
VvWaxEThAVBVVbzYaHxfPuHDhGofhMnwr@u\l<PyeJ&8y:>{'MCp
NDMTlCNjRXegRNHDgHeZPAGqeoey~V44Db}+jaXL]P"z#(zPC]i$"
XlJQBULNdClzbwgEBdqdiVbJkAMh4N#:N:LOz]a,YW~GU9Ts^;'<
YrTDhmgIXXdtPtmUQiTGEdJixbTCb2y8wIKPXNeB2{tLXUfYlwQ-R#
gNeqobpAFdrbzeVGlOPwFSNdVyxFuaWeAy'3{O1AI!(`W#%%E4?}!
RPEGZaEMUBIFxgrovJgSJGZHhRzs^\~Zcz9h+xc;@ &~Bk!v+v6*$
yhPjmpEOjqZTVZFsGEBiyQLDLddl[6\&"PLQ5LVpkc`HO/!F-d=b!
oOWzlBpfDZjSOnTgQPoKgqIzFOoj1cH?L34;jC6S1 ^#% "PKP1*"
DUgcSDEoScPOkmwXxOqlmGFWRiUFAp_"@NT18Gh!,QX_ 3YbBXz(P-
UPghTfvZdDSAVSCxyaOHfjjqbTEiA88eGg]fOH>@ Pgo4Vt=SwD/#%
ArKdHQVDWztbCZqpsmFLvuYlpMBU8VR~l!2dC]lZj[CL@qEn/v1^#
ubGBOSEXcBAndgEecpyUPpABzprJIi\N>!Qm8LU3DQoMTZNZj{IH!
zQjkdHPrMEloWdyEHORcmYRJgitxQNku~j^plG-(}z2ZIo3<J{Y2"
NZZoArCyWYpggFqAHguzGpQcqJbGbh3ppM-|@n3},Zv0a]mg\&\CU'
VgGPNaMzaVVvAbMTyEYjDCVpewWg~n'FCL`Ib!VSKL_Z*ADzS{:C"
TTHFumIrupavBicKUortnfjlLkGwAZ:4}3V@?1;t$]|hOCIs1I-;+0
gkNasKGLhTjbiooOdgJeykvnUeLNA;T|c@>+A>,AM x,%d_("Wg4n%
KhsvwNqdVfOrSIqjsvPZRgEukmPhVwCkdELmkn>zk_/_ht[r]U4O
BWquCokNDTApoywOaOevaKwQnIOwdioz 1Y%L1"X_%c"ZMio2H6X%
DTiRRaWfIGLIZmOrDAIkaqZAceCJA`I[nW40x2:$X3GrNIc*LRc*n/
xPEVtDleTNjYDbWPLwocuXvokuECMd8^V}!;\ErUp0)_oa TI*#N!
XePExYopieAPwUrtTQxHVeYekZUJ+eV$xm ck@m7jSn{2\hJCX=j"
xjRcYWhdRPkoQcAyCKqwmkvVbkTGb=pTp-?o#27DDt}Joau]kx] 6%
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
ComVisibleAttribute
AssemblyCompanyAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
STAThreadAttribute
UInt32
GCHandleType
Module
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
MethodBase
GetParameters
ParameterInfo
Invoke
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
Buffer
BlockCopy
get_Length
MemoryStream
ReadByte
GetTypeFromHandle
RuntimeTypeHandle
get_Module
get_FullyQualifiedName
get_Chars
Marshal
GetHINSTANCE
IntPtr
op_Explicit
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.2.1.1
bvsdvdssd
WrapNonExceptionThrows
DDFO447
NNN3SSS
XXXL```
aaa*aaa
!Gi!I
fffQiii
jjjxlll
wwwfyyy
yyy<|||
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
4BEACH_BALL_VOLLEYBALL_SPORT_BALL_HOLIDAY_ICON_191548
VS_VERSION_INFO
StringFileInfo
000004B0
Comments
vcdsds
CompanyName
vcdsds
FileDescription
vcdsds
FileVersion
1.0.0.1
InternalName
LegalCopyright
vcdsds
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
1.0.0.1
Assembly Version
1.0.0.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Trojan.Siggen15.2301
MicroWorld-eScan Trojan.GenericKD.37513040
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37513040
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Trojan.GenericKD.37513040
K7GW Riskware ( 0040eff71 )
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZemsilF.34126.iu0@aiXQ44
Cyren W32/MSIL_Agent.CDW.gen!Eldorado
ESET-NOD32 a variant of MSIL/Packed.Confuser.EJ
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba TrojanPSW:MSIL/Reline.50eb9341
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37513040
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.ch
FireEye Generic.mg.0dd588d0d11074ff
Emsisoft Trojan.GenericKD.37513040 (B)
Ikarus Trojan.MSIL.Krypt
GData Trojan.GenericKD.37513040
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira TR/Redcap.fiwng
MAX malware (ai score=98)
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Gridinsoft Trojan.Heur!.03013281
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4621943
Acronis Clean
McAfee RDN/Generic PWS.y
TACHYON Clean
VBA32 CIL.HeapOverride.Heur
Malwarebytes Spyware.PasswordStealer.MSIL
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-qqpass.Qqrob.Jwf
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Reline!tr.pws
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.6c5d27
Avast Win32:PWSX-gen [Trj]
No IRMA results available.