Static | ZeroBOX

PE Compile Time

2101-07-02 08:00:07

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006b6c4 0x0006b800 3.72966307114
.rsrc 0x0006e000 0x000002a4 0x00000400 2.16737752172
.reloc 0x00070000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006e058 0x0000024c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Drabness
Drabness.exe
<Module>
ConsumerTokenizerTask
Drabness.Tasks
Object
System
mscorlib
ContextConfigurationEntry
Drabness.Database
<>c__DisplayClass2_0
Params
Drabness.States
Predicate
Drabness.Common
<>o__4
ValueBroadcasterStatus
Interpreter
<>o__5
Bridge
ComposerTemplateRole
Drabness.Roles
Client
Singleton
MulticastDelegate
InstanceWriterFilter
WrapperPoolConnector
AdapterStrategy
AccountWriterFilter
Consumer
ParamBroadcasterStatus
Customer
Printer
CreatorTemplateRole
AlgoStrategy
EventPoolConnector
Drabness.Connections
ValueType
CustomerTokenizerTask
ReaderStrategy
Drabness.Strategies
MapTemplateRole
Expression
RuleConfigurationEntry
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=423316
CheckParams
String
EntryPointNotFoundException
DisableParams
MapParams
ListParams
Func`1
Boolean
IntPtr
Invoke
InvalidOleVariantTypeException
System.Runtime.InteropServices
DestroyParams
UInt64
UInt32
UInt16
op_Explicit
Marshal
SizeOf
Application
System.Windows.Forms
get_ExecutablePath
op_Inequality
Thread
System.Threading
ToInt64
GetTypeFromHandle
RuntimeTypeHandle
AllocHGlobal
FreeHGlobal
m_Writer
broadcaster
.cctor
CancelParams
col_low
template
Replace
PushParams
PopParams
Binder
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Convert
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`3
CallSite
Create
Target
ToCharArray
FindParams
FromBase64String
Encoding
System.Text
get_UTF8
GetString
ViewParams
m_Listener
InterruptParams
StringBuilder
ToChar
Append
ToString
ConcatParams
PublishParams
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Exception
AddParams
Action
VisitParams
ConnectParams
tokenizer
RemoveParams
GetParams
CSharpArgumentInfo
CSharpArgumentInfoFlags
InvokeMember
IEnumerable`1
System.Collections.Generic
Func`4
tnemelEytiruceStropsnarTpttHnoitarugifnoCledoMecivreSmetsyS32978
Func`5
m_Strategy
m_Reponse
_Message
_Identifier
prototype
_Manager
WriteParams
LoadLibrary
kernel32.dll
CallParams
FreeLibrary
ChangeParams
config
counter
GetProcAddress
kernel32
configuration
ForgotParams
PrintParams
GetDelegateForFunctionPointer
Delegate
ReflectParams
_Mapper
hProcess
isWow64
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
lpBaseAddress
ldcnysAemaNytreporPetirWoDretirWtxeTnosJnosJtfosnotweN23925
lpNumberOfBytesWritten
instance
second
exitCode
handle
hToken
lpApplicationName
lpCommandLine
lpProcessAttributes
lpThreadAttributes
bInheritHandles
dwCreationFlags
lpEnvironment
lpCurrentDirectory
lpStartupInfo
lpProcesssalCyalpsiDcyranoitciDdetroScireneGsnoitcelloCmetsyS49423
hNewToken
hThread
pContext
reference
selection
visitor
ProcessHandle
BaseAddress
ZeroBits
RegionSize
AllocationType
Protect
caller
nCmdShow
_Repository
issuer
definition
_Method
_Container
m_Page
_Merchant
m_Factory
_Indexer
server
_Attribute
_Iterator
_Field
m_Composer
creator
m_System
_Thread
_State
_Context
m_Rule
database
m_Global
candidate
record
m_Attr
_Error
annotation
_Importer
setter
m_Item
_Product
interceptor
_Authentication
m_Descriptor
m_Getter
ComputeParams
StopParams
E4C1640DB4943EE86DF4A84EBBD4F24DED1E220C
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
ParamArrayAttribute
DynamicAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
CompilerGeneratedAttribute
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
EoitcerideRslennahCledoMecivreSmetsyS88638EACFCgHORYaMjgHDioyGQ==
EoitcerideRslennahCledoMecivreSmetsyS88638xwGBigtGBANDwkB
IoitcerideRslennahCledoMecivreSmetsyS88638EEeARMyPQkCADsEDV8cEAxVOz0VNQIUKAcpFgE/TE8=
JoitcerideRslennahCledoMecivreSmetsyS88638zUCFCg9AxAOECMeASUAHDZXATISBWlQ
IoitcerideRslennahCledoMecivreSmetsyS88638EAsGylYOSwOH0QZNiofVw==
IoitcerideRslennahCledoMecivreSmetsyS88638ioaNShZDFcZDjMLNl8EBgxWGnU=
JoitcerideRslennahCledoMecivreSmetsyS88638RwGOygHXg00DisCDjUuOjUJGSQoQQYdKFhbWA==
JoitcerideRslennahCledoMecivreSmetsyS88638RwGLygtFxMOejdCDjsQGgwLBXkoJSwjED1eEzQmGk8=
JoitcerideRslennahCledoMecivreSmetsyS886380EeHS4tOTQ0JUgYDjUEEDsyATwTQR5Y
JoitcerideRslennahCledoMecivreSmetsyS886380BtXgQAPS0NECMnNSUABjYyBQwTQGFdEDIHVQ==
IoitcerideRslennahCledoMecivreSmetsyS886380ACXRwtBxwNHzcZBV9zHwsiAXwVM2lQ
JoitcerideRslennahCledoMecivreSmetsyS886380BtXgQAPTENECMnNSUABjYyBQwTQGFdEDIHVQ==
JoitcerideRslennahCledoMecivreSmetsyS88638EACXRwtBxwNHzcZBV9zHwsiAXwVM2lQ
JoitcerideRslennahCledoMecivreSmetsyS88638B8CFy49XgkBDxkLDjoMAQ==
oitcerideRslennahCledoMecivreSmetsyS88638
IoitcerideRslennahCledoMecivreSmetsyS886380ACXRtYVhA0ekgBDjsuGg0IBT4VBWlQ
FoitcerideRslennahCledoMecivreSmetsyS88638SoaASkAIhwbJSMBNix3Vw==
JoitcerideRslennahCledoMecivreSmetsyS88638EA8Gy5bCxU1JSMEMBp3Vw==
tnemelEytiruceStropsnarTpttHnoitarugifnoCledoMecivreSmetsyS32978
Replace
FromBase64String
GetString
qrTmJjoeWH
VoitcerideRslennahCledoMecivreSmetsyS88638FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUhpL0FNc0FBQUFBQUFBQUFPQUFBZ0VMQVRBQUFMZ0JBQUFNQUFBQUFBQUE4c1VCQUFBZ0FBQUE0QUVBQUFCQUFBQWdBQUFBQkFBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFBZ0FnQUFCQUFBK2NRQ0FBTUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFLREZBUUJQQUFBQUFPQUJBTndFQUFBQUFBQUFBQUFBQUFESUFRRGdDQUFBQUFBQ0FBd0FBQUNFeFFFQUhBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFBTGdCQUFBZ0FBQUF1QUVBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQU53RUFBQUE0QUVBQUFnQUFBQzhBUUFBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQUFBQ0FBQUVBQUFBeEFFQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUF
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Drabness.exe
LegalCopyright
OriginalFilename
Drabness.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Bulz.699108
FireEye Generic.mg.b510e124d32628b7
CAT-QuickHeal Clean
McAfee GenericRXPZ-YL!B510E124D326
Malwarebytes Trojan.Crypt.MSIL.Generic
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.699108
K7GW Clean
Cybereason malicious.f2cd4f
BitDefenderTheta Gen:NN.ZemsilF.34142.Bm0@aitsDdm
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACCF
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.699108
Emsisoft Gen:Variant.Bulz.699108 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.972
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gz
CMC Clean
Sophos ML/PE-A
Ikarus Trojan-Spy.MSIL.Agent
Jiangmin Clean
MaxSecure Clean
Avira HEUR/AGEN.1144480
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Bulz.699108
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4628732
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Bulz.699108
TACHYON Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CC0DIK21
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ACCF!tr
Webroot Clean
Panda Clean
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.