Static | ZeroBOX

PE Compile Time

2021-09-12 06:02:59

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000eee4 0x0000f000 7.33566363653
.rsrc 0x00012000 0x00010e88 0x00011000 2.07913476131
.reloc 0x00024000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00012184 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x000229ac 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000229c0 0x000002dc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00022c9c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
7W*A^
w^|"s#
^0G2.$K
RI+*MU
1^:W<%
)FLh5f
Pr{1+|
+ZA3:,
aNrHCTBS
?4+C'P)
':NU3,
D3TQqv
X*TJ<B.G
./h4WC
$6g*?_
3X7?hT
~&._IS
tq=rKT
ykOz#`
b,G)8O
#{<JFa)
U5q8J?
Pi=}mz
pVW0w^`
prd#w^
CEt2:$
BIRb'$
_)YFC
"Sh;>Vzz
,W;_0=
I4#>1V
V]9Ljc
8ku|]L2f
TXxL*:m
!-,X;2
CD!6stQ
*~[\t:
3HkF^^0
GMuUzDr7x
Y_cX*j
Y_cX*j
VMDj^m
Z?_b`
ntdlT
X l.dlT
NtCoT
X ntinT
ntdlT
X l.dlT
NtCoT
X ntinT
Z?_b`
_bj2
_bY*
Z_bX
_bj2
_bY*
Z_bX
v4.0.30319
#Strings
Mod.exe
<Module>
DataField
awSDNIwUnNTXGxVIqooVSbKnoMYGcF8Z:7Vc'fBq``e]#1#Joi`h!
mscorlib
Assembly
System.Reflection
vSsveOGDddiyEZdjkspfbWyHpQJXm|_e~`%S1Q%&!Y*Uc1e9H+^H$
Decrypt
GCHandle
System.Runtime.InteropServices
Resolve
ResolveEventArgs
System
Decompress
.cctor
SbkupyeCExvvtcbSruBEPutyhbXk@T9w*(vO]qAA5dug|+"U",Bd!
VirtualProtect
kernel32.dll
DbkmZfOaUqAkaaFppvfNccGrIMYz`Y=d}XR|$Eg<7;/]<!oxc('+)
jhAFzklpZNJFXSsyAswjUQQBczSD&SBhwMJrDz:^AUZ,*;#F~36e!
MrLGtxelZhLjVYVQDnEWFrxMWeJyAb7Fk{a5)QM8XZ8<(^B,A0^c`/
ULDqZGIPitpGztbsmeFmwzXpBTxS<X|mFB=/G/g*WMKX1[aN(VD[$
DataType
ValueType
BitDecoder
Decode
BitTreeDecoder
Models
NumBitLevels
ReverseDecode
Decoder
Object
Stream
System.IO
ReleaseStream
Normalize
DecodeDirectBits
LzmaDecoder
m_IsMatchDecoders
m_IsRep0LongDecoders
m_IsRepDecoders
m_IsRepG0Decoders
m_IsRepG1Decoders
m_IsRepG2Decoders
m_LenDecoder
m_LiteralDecoder
m_OutWindow
m_PosDecoders
m_PosSlotDecoder
m_RangeDecoder
m_RepLenDecoder
_solid
m_DictionarySize
m_DictionarySizeCheck
m_PosAlignDecoder
m_PosStateMask
SetDictionarySize
SetLiteralProperties
SetPosBitsProperties
SetDecoderProperties
GetLenToPosState
LenDecoder
m_LowCoder
m_MidCoder
m_Choice
m_Choice2
m_HighCoder
m_NumPosStates
Create
LiteralDecoder
m_Coders
m_NumPosBits
m_NumPrevBits
m_PosMask
GetState
DecodeNormal
DecodeWithMatchByte
Decoder2
m_Decoders
OutWindow
_buffer
_stream
_streamPos
_windowSize
CopyBlock
PutByte
GetByte
UpdateChar
UpdateMatch
UpdateRep
UpdateShortRep
IsCharState
RXEASMsUlLDEjfMiRmERTagrLTKvALc@j|@aGHt(drC4ZGH/"w&hx%
DZnyWCIOgUWzcNOLdTkhshdoqwRpZHMxLDNChK(1hd}(c&[y$okl(
FJNbQZGGedWtBGopRyAdicawydiBAdS'+~NLQW&Jl[=T+g{C}wus^!
oZKjuJLoVfTGvatJWWxUKdWiMdOl]gL"Lh;jgTO3:8'%lF'l"^9>$
foWAOBgjxqRbOQIEknpdUcXnWwLlIbRzB]A0Q0\<N's&e6~#Y<RD!
DRnjihyUfJShgvkVQsItWecDnuCd49H=Y,6bx6[*9HLs[|_-X$%E
mKHbnTtRbQbkvQrTHkMEQWCeIxVr=O8*4ulEJ$7<lJNd!3lRC1L1"
KpydwcbJdxcDwChuwTieGWypcCqfA`vk=9A$Qo'kxM=E1Mgx{_Zcx!
sDqbmDckNjirztOgnNPcWjbSgAiCbAM,wTI(N},uBvs$`Eak9X#!K+
JJDWIeKnqKOeUyWsxhlcrgvxpczW:xZ2s6rMl}|@{=o(59/MW"H]#
KaJwZmCDcewVjWbcqrnjYzjtxPEFnof{{)o|&9[>chUc$Bk_1c4X
nohADicTsAvxkAEGdAaraceTFsfcAI6GB,/4wZ3I1@pUM((k?0(g=)
dgyoQQVLSaFywfAkrvXDbsFZzOkDA{{(<0#|`$1Y]j(y6<qc)nX( "
yCySdtpPfoxcZRFCDvLjLlLOCXnem g~/yFQo7#H\ xSkh3K4Ri8
UCOdnkaIgFOREVjtjTokyCGTIlnEPnWms5XV'#4!'"i%kgLFtp]:!
XgGCNGXtUElKjMFFOVTfHcDCeQaTP5~rPn>H^i7/|DRp7gJtb~*7%
qoiENKKZoLdCMHVvyaySLyfmFvrd,(WF:\py8A><vF,3<0E35z&9!
kABEoZdFxLpbaCqoMrEkChDNRcjbA[f|{+Kt9vG3R*AX:?0]VjA3o"
MmOHuRXqdSnaoByCmkvHGnmUPcpm`XT~L%6Of]A~Z4_UvP0W<Z8I%
ZdLPNVjyNOAwqOatchILbHjbeZNW+yN<h$=~bV$knyk!qB }/d"+&
bFZcueBTguopuctMdvAvGtrecwIwd{kd]E;Fk*94}Ofe<Ns,MS3dk#
YemviqBLGxPiengyBgYyQyVWSWKN>3 [$P;+On,/S/JT#,Jx<lb~&
WxPtuGiibPIKetjHVDlyfncWEroHAR*Nc!?2 tda/9|T}+eKUz_aG'
exHxjmrmnuGaPlvNgJPnOCzrETgc=DW&[1I,a~"_3Q*>\r5f{@Z#!
XpVJjVSZMhLgiFgwbpqQDdIEmntPnLPWP 8VW]$i2??g''~D#5Ty#
bwpXxFmAROzCpFJVVEssJHjBgllDIN5Hz?@d`;9JP=-TeLan@ =^
mqgegaLlMcsUbXfFAbOLibDtjQrc}Ui5aF=\A_ZX{r 7~ai37QF/
KVKKZhfCNzfZDiFDwtvUHUWsZcloAfSD^w(U<3Td;Z+[=:n#@;'K()
YSzWaIMnzPJnEsDkfpzaiNdTEyRCR$:Lz\C[2`X=l?euUU7<Nv+s
jFFcqrKuXIucPgGsmaPIfGQJWtkobCO!EaXgD^cLiVe[#0`tV~7W/%
RIvuieTOEaOLPZytoIzuvaQPXJxh-83YAN<'*zJ0+u&D MIV)jZk"
FjJeASnwDJVwCzGfZfjHcLVmPpWy:jtFVqft\>2AH"%g%%g>**P6"
HXqdOyZAkEXhXWvLVwxmoGKzktLh~lE U@7LxD86*VtS]/r~qWf\
ltcFSnXzCuemJdxOFBHApvVgqdODU-U6oVOI [T_A9#xrU4QEYF1!
DHqjTlkRISUmczRDjIJdyzOURKvm)DoR[YQ|0$SRuTMJi2S0+D8o"
kzsLygsGWDNYDwDsOCNRBdTvaqduACtw&"5SZTl\?";TX3Vo!{Is_$
FIFkGLotZEnfjzzrxrDZabqsJpHI+y>e0 1hDi""QayCJ (y,B<O!
LzHdzIRJgQGDIJBXQHXjkdYYXaXE|Q%3`26>'b<LYnjjMwpfb2@O
lhqmPrZeZYHnULWxGLHWYEReypOqsoom*)^!lo0667vv+#v@q?gF$
JbdjKjPtEsggPQNGaWnjpsvcBYCV#=U6i`I<K"'UT^/=5>{ImPBj$
ekhHZjebiddIriFMVwQyENCRBgsgb*)cx7 YAalG_0r4D<=t2>!am,
tZPBcyXAaqmlBpaSfUsRmIQTLkKmaRjho+"4 5-=J0/rxe9%-f2q!
lGheKAVqLGvLYxHUfzEAWdrGTnyX[go0Z:r>!\p0"P"prS`i>w7e$
tHzDiOdUBBIviuVseinvOzunQTTeAUnCotJ>6Dy(I%3E"WGMc{nPD&
XUBWKjshNzwttbFaJlkTOyUvtlsRf%<p*KUR=i'$/cF8]42n yU3:
BldZOqzjRarGLAMJiLJAaKpJhnsI#_*NY;\Uw?pnW|ond")3Pgiy
WHpiAHWRAxblrIpUYqqIwPipbSJaAf&ILB#pn3=uj#<T95zqW]>]2'
gjYkdLUnMtmTNNgRqVpAXNfJFNPFayZW@%$X;1zHi8]:!"B?hb)j!
blkfoWQZLhWlyEwowHQvAayOwLGwEl 7vB?#qMAo~O38WeH=LX~s!
zhPhnyBJHKyUZxKlKkldUKQWaPZJA7&@5i"%PrF0g;I@9)e!>'@9-'
msOBfHinonSzDnNBucRDGivkLECnYWz$4EqmEST9F+k:TEH3}\)T#
vxKUoXUStuPLFQokRBQXtemQfTaY9H'Rh0\;1~`-[wNnLe1&n%8?%
gBYRGfPGOxdSqEQVFFBXeoQVByIXaiBHQ|?`k`3Z3)BN`eCbX}/F$
rzqMbIWKMrcXBeoYSscbSJLNDBiSAQt}{d0d~S:)>e4BS;G8PZ:J*#
JdOGEOuYBrRnGrdjKbvHHKhLPZUkHkX|t/#!M`l6"e)=%HNKd|/@#
gLCFetcbmDzjVfpgHDYeaDLwryKW$mF"oc@s^=Z:iW0H}&VfGc2@#
JrvlrwbFBLsKYcAOzFojGoNmIMMA@s}hK1LX&;l/v:}-QHC-T4|@
YjbrjXbCxwbJOcVDQbiiYWDkSJYkAP>w"J2MEI^b&ZXZq[=HvEdQ`'
hKqFwEdUxyIWWBkfgCRWgCTHYBxcAE0EW![4?s^:mZU"4+#)V`z@7$
FuaHfRiLqVVCmwaRkdvtWoTjXYDEjA=6bG|eLf=cLG(],NoOSb|a
wTegGXFHKtgtDYsPZweGdSbPnaBEb_:alL[-`aA'4sTH$Eddcfb R-
HecJbJRvSZMVazWkXahKcoVDmlNS>@(G-8c|vvw2}Mny4pkh%"~r!
WsWsLiWpUiWJXpzjrawNexaviqSR2ehv}(-z?jL=S[M[>:S9M=,-&
AqhFMxjqBarazefgDsVcRMzcZYbrA@63#?_*'?eW/c})-JYr_i>ag&
CebLKxuyWTPCCTiqSpGMbPvQNCKy|\Utm*N0)z|P|MR>pLIgZl+~$
CZcMVLwbgcZuwIQpTovLyPGKwibF)o36L5;uw<M<X!xk#s4N6&5>!
MnTKwjeCDCzsZRyPiiMdBqdbyBYPDJVW{(SHl[xohRKdkel,o@^E"
IyPwNlNBjxaAuGWPKrDpolfcGZEq\#~}i^'e]V/6+2BP59((W<=v&
WAcrrnrDmndkeTuHbwwoNhLdTslc2F_KE7-9?&/Vq(u$e`i4iHmY
CWxFJShttLqWilPdRXLJPFpbNHbK>G7zN]FoNU 7WU4l@163}49M#
TcxmhwoWPSHTvHJwteeEvdNrmLqcF[mO=YV0X62!)92KUY}XAw-L
YOmwutxVrPtBomiPvARsZOczbNqP67q;_/mk6I $ >OV]S#"g0As#
fGMtLCVIcmsfLGBtmqAhcaIogoYhY`bO)N8Nmc<d:DIWSqA%Yo|z
aHVmFLfOySnCkwjdvHKOtWxsFbBF_6^_@E%e+e9,Wo*Vb_An 8:~
xnFiSpCdSodcCaqINpEHTjXdQkZYo,6P()%Vw b[yxdZG4,jgQOr%
ZenbinZgnpyqVejSdkrbeWirnCytFHC5MJv1AuN7vHEwg5&w&b*3%
EzVzLdKFUbiuUnTjvKMXxdWJUwggXnFsO^!;}KH;e{_+J[El\F7^
bhlDdSQFQzUfbJecDhrAkOqyIeScb{gC j~kHq5k(>OVi:JL,M&(++
CVRcwNvmrNezKdqbGnQLrBelZtDGAb}TWt9Qmp}d'yiBrA8Rq93I'&
fybEmNMTnqGglVGVnembICAQJfBIbqz9m'X|gkAi)R2Eggc#Vj}+@$
GJMLQZomPPegHTmhzXyjvIqjkcSB-v@&X1sD?35<=1GbG*VOA&AU
bzoyOaSpVdrVDOsqmtwZoxzeiurk HOhGD8>3~6>xSk'k|C9(owc(
GesdSUiKFLKMIFnxEIGIWUfJdBJdbHj_JDH~jxXV//aJ2rKX1`:br#
AofmqSTprzDbltqrDkhFVCJUxEydl'&?F~KG&%"uR/~o8r|f'[WX
lewOnlYmNemxOPpSwPrkBDwOUuncIO~]/TaQAE{l,uc'gF@O<TeK
fvAJtHGlXccdXWPgLatTgaIJkdNX&S%,8r[XGG)BB*'AvJw)Ns?P$
ufvzZinGGmupJjZcqZxIRtZFvDxkUu}"/mT>gIpiXM,>p|]b2MAd!
RdcmgRkrjOFCbebNnPubxEAmKErs<s75fc-[48k$9:_%uHmxCB9y#
HaVycYAMrnKhSxpoZCbWjJvblaOhAN+^EVA<oiE#Dsw6?ElHKUsj-$
TmuiWUWMNspXBKEWsQtTvJRcHECb~_3fv|h@A6bT+!`015F6d0D+
FmAaqgwbJFUyPKpyVhRSUHuZfGjP%4dKW] JZgt_TIl`#4B{LLFe#
jIFSTXnfkqClfAzIoQWkIngIcJiv90d^8UlW(1}L>rCn9A!_0@oP"
IOWhTChVgEDGibGZJGsTBTwfQZFyA2/N-B$biF|U=1~-,9Zpga>BH&
<Initialize>b__89_17
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
ComVisibleAttribute
AssemblyCompanyAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
STAThreadAttribute
UInt32
GCHandleType
Module
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
MethodBase
GetParameters
ParameterInfo
Invoke
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
MemoryStream
ReadByte
GetTypeFromHandle
RuntimeTypeHandle
get_Module
Marshal
GetHINSTANCE
IntPtr
op_Explicit
get_FullyQualifiedName
get_Chars
op_Equality
vadcscc
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.1.0
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
(VIDEO_MARKETING_MOVIE_CAMERA_ICON_192459
VS_VERSION_INFO
StringFileInfo
000004B0
Comments
vadcscc
CompanyName
vadcscc
FileDescription
vadcscc
FileVersion
1.0.1.0
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
vadcscc
ProductVersion
1.0.1.0
Assembly Version
1.0.1.0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.350591b477d78656
CAT-QuickHeal Clean
McAfee RDN/Generic.rp
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZemsilF.34142.im0@a4tHNii
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Packed.Confuser.AC suspicious
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.cm
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
APEX Malicious
Rising Trojan.Kryptik/MSIL!1.D978 (CLASSIC)
Yandex Clean
Ikarus Trojan-Spy.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/Application
AVG Win32:TrojanX-gen [Trj]
Cybereason malicious.7ae51a
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.