Static | ZeroBOX

PE Compile Time

2103-08-06 22:16:03

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000061e4 0x00006200 5.94037083343
.rsrc 0x0000a000 0x00004764 0x00004800 2.26926095364
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000e158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000e16c 0x0000040c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e578 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
GY Z+p
AAL F0\
c 8n}:a
AAL F0\
*qvg
GY Z+p
"&gae E
]w;a S!
{8 ef ,4*`a
b $58/a
el/fe
*qvg
(Xe ib
a 4ug;a
{8 ef
"&gae E
v4.0.30319
#Strings
Product_Specifications_Details_20210650_RFQ
Product_Specifications_Details_20210650_RFQ.exe
<Module>
Strategy
Product_Specifications_Details_20210650_RFQ.Descriptors
System.Windows.Forms
Object
System
mscorlib
ConfigurationFieldCandidate
Bweaavtunj.Candidates
IndexerInstanceMapper
Product_Specifications_Details_20210650_RFQ.Mappers
ModelExpressionAnnotation
Bweaavtunj.Annotations
Request
Resources
Bweaavtunj.Properties
Settings
ApplicationSettingsBase
System.Configuration
<PrivateImplementationDetails>
<Module>{2a21942c-5840-4911-89dd-2b562d5c0c52}
m_Expression
_Proxy
creator
record
IContainer
System.ComponentModel
SortObserver
RegisterStrategy
EventArgs
caller
AssetStrategy
ProcessStartInfo
System.Diagnostics
set_CreateNoWindow
Boolean
set_FileName
String
set_Arguments
set_WindowStyle
ProcessWindowStyle
Process
ThreadStart
System.Threading
IntPtr
Thread
CollectStrategy
InvokeMember
BindingFlags
System.Reflection
Binder
Assembly
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
SortStrategy
TimeSpan
get_Length
get_TotalMilliseconds
Double
InstantiateStrategy
WebClient
DownloadData
Dispose
doasset
CountStrategy
Control
set_Text
EventHandler
System.Drawing
Single
RemoveObserver
DefineObserver
AwakeObserver
ConcatObserver
UpdateObserver
InsertObserver
OrderObserver
ComputeObserver
ChangeObserver
WaitForExit
WriteObserver
RestartObserver
GetType
FindObserver
FromSeconds
NewObserver
get_Text
SetObserver
ManageObserver
CloneObserver
StartObserver
IDisposable
ExcludeObserver
SuspendLayout
DestroyObserver
ContainerControl
set_AutoScaleDimensions
VisitObserver
AutoScaleMode
set_AutoScaleMode
CountObserver
set_ClientSize
ListObserver
set_Name
DisableObserver
add_Load
SetupObserver
ResumeLayout
process
_Registry
TestObserver
.cctor
PushStrategy
IncludeList
AssetList
LogoutList
SortList
CalcObserver
RevertObserver
_Mapper
_Params
PostObserver
outputlast
PopStrategy
Container
InstantiateObserver
PublishObserver
ReadObserver
GetObserver
InitObserver
_Field
PatchObserver
RestartStrategy
ResolveStrategy
Rfc2898DeriveBytes
System.Security.Cryptography
MemoryStream
System.IO
CryptoStream
RijndaelManaged
Encoding
System.Text
GetBytes
SymmetricAlgorithm
get_BlockSize
DeriveBytes
set_IV
set_KeySize
set_BlockSize
Stream
ICryptoTransform
CryptoStreamMode
requiresitem
ViewStrategy
CreateObserver
MoveObserver
VerifyObserver
get_UTF8
CollectObserver
RuntimeFieldHandle
RuntimeHelpers
System.Runtime.CompilerServices
InitializeArray
ValidateObserver
get_KeySize
CheckObserver
CallObserver
set_Key
LoginObserver
CipherMode
set_Mode
PushObserver
CreateDecryptor
RunObserver
SearchObserver
InterruptObserver
EnableObserver
ToArray
_Error
MethodInfo
iterator
InvokeObserver
SelectStrategy
DestroyStrategy
ForgotObserver
ReflectObserver
ViewObserver
RegisterObserver
ResolveObserver
StopObserver
FlushObserver
DeleteObserver
QueryObserver
PrintObserver
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
instance
ResourceManager
System.Resources
attribute
CultureInfo
System.Globalization
ConnectObserver
get_ResourceManager
get_Assembly
get_Culture
set_Culture
CancelObserver
RuntimeTypeHandle
GetTypeFromHandle
ResetObserver
MapObserver
Culture
defaultInstance
CalculateObserver
get_Default
SettingsBase
Synchronized
RateObserver
SelectObserver
Default
66840DDA154E8A113C31DD0AD32F7F3A366A80E8136979D8F5A101D3D29D6F72
m_60d87a5b99834ef09e7857a3f2a2602c
m_f4c2fe4f7c1849f0a3be48060fe3ba48
m_621163dec29c4845a08ab024c48585ac
m_eab34aff9f7f4c40b2b91252419950c0
m_295ee028fa0a416683385bb696ac177f
m_5363eadfcf1d4c7e9f642ba33c1bc382
m_0b016146972746a5a59f46c44f5c2a3c
m_f61fe5f76e9c447ea3efdb09b8b6de66
m_c478adf003f74e2388fa7e7cbf35b54a
m_6e26227cd2094a99927b7502c05f503f
m_623b7b9de21746f5be1fbcb487d61506
m_c676eed5eba44415ba2d85ddfd02d8ed
m_4255f95189394279a62cfc289d8e45ce
m_b5ba415907f34f3eb5adee690bde7935
m_47a69e84b42d488cab47586a9db6d8e0
m_658380ab276d446487ba77d666af75eb
m_8b0882f1937d4fe3812bf6f8b6067544
m_f8119b2a20d9437785bc3183e74338c8
m_87ef1b55a8e641d98872a117587503bb
m_3c908075e23a46bda09f44da0a3d7f03
m_bac2aeae0acd43d1afe1ed02f9b1eb61
m_0b7c71fc66be42ffa5f97ac014845c11
m_161ad1b2c1eb456b8f44e701b554e70c
m_b7d60ec8978d4a4082315d1538791179
m_786f64a41ed04e2c8685290e10fbca13
m_a4bf086fd60a42b8863b6d33925b8aeb
m_62316c2cd0884aac928f430e2c0138d2
m_66ffd3b40ad347599765df846750db71
m_a72c88841f144895b3f84c268a06be8f
m_cd287d3252a94c168ee9ee940f46acdc
m_f3464b4783f94ec49bcaf421fc1628cc
m_9ad415ada7d1448f8d667d4eca0013c2
m_15a3713eb8714a90a30b519fd2d23344
m_b360d694b3d14b6b8250c54e43484d6a
m_21fec7b15be945fe8be87e811fb1bc46
m_739869807acf4a68856f67bea577e226
m_c1f42d898a1940c893c4d8b67f3f6f33
m_f39b4578c0b64af981e85a4a985e0612
m_9d09f48705ff43b48ae7aa942466ef88
m_e756466189604b609445c91c02f6e662
m_260c77ae4c6a414eab1489965d042bd0
m_547dd914cb35492a9d1d337b446b21f8
m_7e2017bd26b64415b8b35808211b5450
m_80d161c94c44417ebf88e409447ea2f5
m_53326a37277b494294135cb9ebb65bd1
m_061f983586464dae94b4e55c1a3f40f5
m_bdacfb3f0cf74242ae2872760d8b0c8a
m_8b1fb8efe52e4536ac4506e33d096baa
m_746a05c4174a417bacf2c451f920012f
m_e73beef6e6234c5dab28d63a80e23a91
m_0d2cde0bd7af4f0ab3e8ba6e51d81268
m_3e0de116fd6b414dbf5f4d648e0b848e
m_a96668af5fe24701b4bbb02c6d493a0a
m_038eae84e13d4f79b269c3c3f616fa73
m_13602a1c3aff4a1c95e4ae4e0f306f72
m_cd2e0bf8d0df4dc89184f7db19642ba8
m_7d1c80e41a134e0b866ec67c0de817d0
m_784f61ccb1b645eaacbde64ef7bc91be
m_5a67cc5c0a144e3aac11589efb679ba8
m_318771672261414fad87edf5a838814a
m_2e4e53b530574b2b81bc6c52da8ea568
m_0b47eb8eea4343a2859fdeee6d9b6771
m_9572d3dc4f164cb4a6ca23d31c5151e5
m_8394e33ad85f48da9014c109c8b75f26
m_4966fc1072be4564acd26137f3ce1726
m_c62aa84fe2b14a839d558429e278796e
m_08a49d4ddf79437baa141f9b8f7a6b49
m_23ac8e023aa042909a07177e178c1947
m_76f122859e3946ab9d898fadbe4f68d8
m_9013fc4ff11f4553be5bb4327aedadc7
m_599a7a0a0e94419c8b73fe22af23c30d
m_c5be146dd4b24879a46f3d792ca55165
m_11e5c1408735411e860dcd5b57a4f362
m_7403788055a042b096ca40d295fa3500
m_3179aa08c1c040dbad65a02c4437511a
m_f90bd4f1de944d3789b71fb18a52c405
m_01e269a3ac64473da17309b1e8128f9f
m_547620c3c5e647af8fcfc93694b904ed
m_ec6d97ff093540cc9405f7da68219bad
m_96fa05f1ba6146c0872c3bf5eae6e1d1
m_25f8fabddb4d4b5898f85ebe4a5e05ef
m_39844de91a084f60bf049237852fc838
m_251c7a5aa025482cb18afde9ba2cdaa4
m_7dc2e695713c42ea8e271f1ee1ece8e2
m_59c706ca75e8403fbd1aaffb8a5df019
m_48c2e3f34b5847a1b22aeb23f4b46531
m_6b48a02c26e5451297651851b8828bd4
m_bdd5b449bd74400aa99035aa13209847
m_9af582e67a864d8b98c138757c8098cb
m_45ec8520921c43958060dc911b86077e
m_380340b99678408493f77510e5797061
m_30de1526536e40bf83bfad0fb245e112
m_75a92eafe2c742ef87dc44c87762b9d2
m_354ce1d55cc543a58197783224ccfc27
m_bdf77ad2de0e464c8bf6596e893a92af
m_e4e45547e3eb46b09753efe033a6da5f
m_b3d56953411743ea955f98310539fd0f
m_9a46fe81d79546428ac608133b9df6b4
m_265191d5ac474d538b34445cf9563c67
m_26b9b6f5d0a34d2b9898442d8ce266cc
m_376c5df072014028afbfcf261e606ac7
m_285758823e9a4a6ba6e53ccc1e0ee89d
m_6f168d98699749fabd700f3eb0731f56
m_314c3e648ae541b7bf8f53cf3749dec7
m_35ad03652ba94b77a2e07ded6f1acb31
m_47bb0202c10647c9be3c7eccaad1391f
m_94fb9651ff644aadbff9705e5273aaed
m_3f345770141042908056831392473a17
m_1546295d6a8e470883594e960935ac67
m_f1a54bcdd9914dc5b73541eda5b9482f
m_efd14ba4db864f49b0160465d6fd4cd7
m_7728ec15ce8a45f499ae5c73af5c2d7a
m_5d4686330e8e4030930d43372a02ea9d
m_f020fa8396814f3a9e34713a119c944c
m_6e2011df14aa4e06a10b761a5cc81af5
m_c53983cc8f1c4360b65e61e4ee71a763
m_219b546165ee472a87fbb643b02a074b
m_ee64541f860a4db98ded81d87d855ee6
m_3307aa81bbcd47ccb9a08f418cbd9b8e
m_5282d703f09c449c88b2ace1fcca9436
m_905158c1c4b04fae9ae072b07f70d853
m_e2787e7357e14c24a7db38414fbe6ed5
m_09ae8988e1214f4598cac1a6e27a02ba
m_f71c218fb8914a88a9530ba8285d3719
RemoveList
re5e8135d983646b29bb10ab09b093d69
ConcatList
DefineList
AwakeList
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
EditorBrowsableState
Product_Specifications_Details_20210650_RFQ.Descriptors.Strategy.resources
Bweaavtunj.Annotations.ModelExpressionAnnotation.resources
Bweaavtunj.Properties.Resources.resources
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$0c7f53dc-a0d7-4f67-9f25-89b593abaef8
2.8.9.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
powershell
Test-Connection www.facebook.com
Test-Connection www.google.com
Test-Connection www.twitter.com
System.Reflection.Assembly
SmartAssembly.Visitors.CodeReponseVisitor
ComputeReader
https://store2.gofile.io/download/7a80b600-2309-4cd7-af3d-a2c5c0bd5e34/Shsiatkkhdjdpjmanb.dll
Test-Connection www.bing.com
Thkakmexjgwkfqzvuibuc
Bweaavtunj.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.8.9.0
InternalName
Product_Specifications_Details_20210650_RFQ.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
Product_Specifications_Details_20210650_RFQ.exe
ProductName
Telegram Desktop
ProductVersion
2.8.9.0
Assembly Version
2.8.9.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_80% (W)
BitDefender Clean
K7GW Trojan ( 00577e181 )
K7AntiVirus Trojan ( 00577e181 )
Baidu Clean
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik_AGen.E
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.de964e4eddeb6ff3
Sophos Mal/Generic-S
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!DE964E4EDDEB
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MCrypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_90%
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34142.cm0@aqFkKWg
AVG FileRepMalware
Cybereason Clean
Avast FileRepMalware
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.