Static | ZeroBOX

PE Compile Time

2090-03-20 21:50:12

PDB Path

E:\A\_work\421\s\bin\obj\Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0\Release\Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001bc7d 0x0001be00 7.86722785404
.rsrc 0x0001e000 0x00000524 0x00000600 3.80919129588
.reloc 0x00020000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_GROUP_ICON 0x0001e0a0 0x00000006 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001e0a8 0x0000047c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
09F36856.exe
<Module>
156FF173
EF7B8AE3
1003C40D
1EFFFC52
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.Razor
19EB42AF
54400942
BAA97637
B1D75690
1739CAC1
1BC8BC47
09F36856
88BEC7FB
7842BA7C
09F36856.Properties
A0078488
311F89E6
F3FFD9D5
0F1B620B
3E4CFA8B
4506905D
25BEF06A
5D13ABFF
B674DC34
33AA0D0E
3026B9AA
39E47580
0D3FE2AD
523884DC
mscorlib
DateTime
System
5AF2630D
7AAB23FF
Microsoft.VisualStudio.CoreUtility
IContentTypeRegistryService
Microsoft.VisualStudio.Utilities
468233DA
Microsoft.VisualStudio.Shell.Framework
SVsServiceProvider
Microsoft.VisualStudio.Shell
21A594AB
Microsoft.VisualStudio.LanguageServices.Remote.16.0
RemoteLanguageServiceWorkspace
Microsoft.VisualStudio.LanguageServices.Remote
7637BBF3
6A54CF85
C560616C
RemoteLanguageServiceWorkspaceHost
11BA2195
127E3A12
E79A4826
DC7F5EAC
IContainer
System.ComponentModel
445314B7
ResourceManager
System.Resources
F2CA3530
CultureInfo
System.Globalization
233DC4BA
822FF7B5
C84769E3
6D2AC547
.cctor
9FEEE780
IContentType
9A82D943
Microsoft.VisualStudio.TextManager.Interop.8.0
IVsContainedLanguage
Microsoft.VisualStudio.TextManager.Interop
IVsTextBufferCoordinator
FA5F08C4
Microsoft.VisualStudio.LanguageServices
AbstractProject
Microsoft.VisualStudio.LanguageServices.Implementation.ProjectSystem
VisualStudioProjectTracker
Func`2
Microsoft.CodeAnalysis.Workspaces
ProjectId
Microsoft.CodeAnalysis
IVsReportExternalErrors
Microsoft.VisualStudio.Shell.Interop
IVsHierarchy
IServiceProvider
VisualStudioWorkspaceImpl
HostDiagnosticUpdateSource
Microsoft.VisualStudio.LanguageServices.Implementation.TaskList
ICommandLineParserService
Microsoft.CodeAnalysis.Host
B41FDA49
18AC639D
B92319B0
Microsoft.VisualStudio.OLE.Interop
C4D4F0C2
16773AC5
3C4684ED
FAEF99A4
2551AE79
E241A1C6
1E68BC6D
2ED8A78F
AB1E9102
4181FE5D
EBB637A6
IVsHierarchyEvents
1A94A471
EE526E29
79BE733F
1AE837CA
5E24BF1B
B6E6E6B4
VSDOCUMENTPRIORITY
E7C31165
IVsWindowFrame
E42833DC
1B45CA02
DDCB8DFD
VSADDITEMOPERATION
VSADDRESULT
9042E806
7923F765
4705B64F
6667D6A3
E3C327D1
91F081E3
2FC75C2D
01B59AE5
11B86DF4
EventArgs
Dispose
B0BEED27
get_ResourceManager
get_Culture
set_Culture
get_dadada
get_Default
8F8E86FD
0B849165
9C187470
7E026E75
4DA42861
388BB5B3
8E07C011
E5ECFB2D
617D2D82
contentTypeRegistry
serviceProvider
razorProject
remoteLanguageServiceWorkspace
E351D1E5
CDCA9408
598F6581
84EFEEE2
remoteLanguageServiceWorkspaceHost
projectTracker
reportExternalErrorCreatorOpt
projectSystemName
projectFilePath
hierarchy
language
projectGuid
visualStudioWorkspaceOpt
hostDiagnosticUpdateSourceOpt
commandLineParserServiceOpt
filePath
1B594851
1B9D6113
C955F6C5
DBBD17CF
44BAA8CC
FF5C165E
A5954E81
9E66D879
84FAF4BE
6B9B23F2
548A162B
CD91A8C5
79600E0D
51570CAB
872D0BB5
6F6F2232
F6396ED3
AA53F73F
1BCEC0BF
BF1305CE
ED6CCB51
BE53C53B
3C4E1EDD
ACDD0138
D6467C93
F954B477
593CC1BF
48B46F2E
FE5287FE
2B4013BA
7FC7CEF7
E6BAEC86
F2EE5849
5C032AF2
5AB1748B
1469224A
80C79200
D2E43F95
7DA19BB4
9E00B055
A82B12DE
EC1ED0B8
7BC3D75C
70B44DA0
5A6747F7
B6301338
2E7E301B
632FCBC0
E364F122
CC9CC320
ADF0CD3B
91FA888F
7175E170
89C00020
EC440893
DEE8CA1E
5DF185C2
59155747
7664D958
2EEF3A27
32297F68
C25C72F4
FBA78897
1A005E6D
F25250D7
8C75F622
5148A6AD
disposing
A42A19C2
6A8C4503
B162F4E1
5A37B836
32641139
62E7B21B
F4EAEFC8
Object
GeneratedCodeAttribute
System.CodeDom.Compiler
System.ComponentModel.Composition
ExportAttribute
Microsoft.VisualStudio.LiveShare.WebEditors
IContainedLanguageProvider
Microsoft.VisualStudio.LiveShare.WebEditors.ContainedLanguage
IVsProject
System.Windows.Forms
EditorBrowsableAttribute
EditorBrowsableState
DebuggerNonUserCodeAttribute
System.Diagnostics
CompilerGeneratedAttribute
System.Runtime.CompilerServices
ApplicationSettingsBase
System.Configuration
DateTimeKind
ArgumentNullException
ImportingConstructorAttribute
GetContentType
Microsoft.VisualStudio.ComponentModelHost
SComponentModel
GetTypeFromHandle
RuntimeTypeHandle
GetService
IComponentModel
Microsoft.VisualStudio.LanguageServices.Remote.CSharp
CSharpLspLanguageService
FromServiceProvider
ContainedLanguage`2
Microsoft.VisualStudio.LanguageServices.Implementation.Venus
CSharpLspPackage
SourceCodeKind
IFormattingRule
Microsoft.CodeAnalysis.Formatting.Rules
Workspace
get_ProjectTracker
get_ImmutableProjects
System.Collections.Immutable
ImmutableArray`1
ImmutableArrayExtensions
System.Linq
FirstOrDefault
NewGuid
AddProject
NotImplementedException
Convert
ToInt32
ToDecimal
Decimal
ToUInt16
UIntPtr
String
Replace
Marshal
System.Runtime.InteropServices
FromBase64String
Environment
ObfuscationAttribute
System.Reflection
VirtualProtect
kernel32
Microsoft.VisualBasic
Versioned
Microsoft.VisualBasic.CompilerServices
CallByName
CallType
ParamArrayAttribute
ToString
ArgumentOutOfRangeException
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
set_KeySize
set_Key
set_BlockSize
set_IV
CreateEncryptor
ICryptoTransform
MemoryStream
System.IO
CryptoStream
Stream
CryptoStreamMode
FlushFinalBlock
ToArray
IDisposable
CreateDecryptor
System.Core
Enumerable
IEnumerable`1
System.Collections.Generic
Control
SuspendLayout
System.Drawing
ContainerControl
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_ClientSize
set_Name
set_Text
EventHandler
add_Load
ResumeLayout
Application
EnableVisualStyles
SetCompatibleTextRenderingDefault
STAThreadAttribute
get_Assembly
Assembly
GetObject
SettingsBase
Synchronized
get_ProjectSystemName
op_Equality
LoadLibrary
IntPtr
GetProcAddress
09F36856.1BC8BC47.resources
09F36856.Properties.7842BA7C.resources
EB397E1F
<B061B34E>7923F765
<882BEAA8>E3C327D1
Attribute
IKOE`"
Nerdbank.GitVersioning.Tasks
2.3.186.14880
Microsoft.VisualStudio.LiveShare.WebEditors.ContainedLanguage.IContainedLanguageProvider, Microsoft.VisualStudio.LiveShare.WebEditors, Version=2.2.0.0, PublicKeyToken=adb9793829ddae60, Culture=neutral
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
Feature
included
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
x\zQL%>
;\esH,
o_)'PLq
?h*O0o
0+PS)m
2|FANp
J(U(U.
GeEVHP
{-fw'4
VKstKA
7ZdE?B
agJj]4
VD+c6EK:3
?:?KS
Q+*4(.
z38BRr
wd -lk
XM8R!2
%`h?'}H;9++
!#E}M#
sguDC^^
iq9*VqK3
#CNr5/1r
us)IZ&N
B&mhy`
7?6Mp@0
A9y'X
SY|DJ\F&
$$|BEN
YQwVNME\
h`hkj`
62{\Y=b
Xak#["
yOA#Nf
h[=fMzW#5?
p|`Xp[
7y?CB^0.
t$M yf1
=UIQW/O/
8.[R3{*I
yha[t]$%K
KwN^0.
}mc[YL
Iicbrl5
tI4hDZ\
MCuAQ}
6s@4SK
p|*aY^
?D3{r]
IqAhXW
kl0gmH
KfJO;Uo
BJ<@%b
}T\,Wh"
M2(\S7N
"}AgC..
D-s)Of
'$Xj~ c6
fB>Y|>"*
}fgvV
;e8JY*
nYvQT}q"
S`B2yWW
_|9BWke
h(gcC@<
9UhkCa
ulDEN"!MK;
W/kCt*
^%0:QF
rWN6r\[
NWPIX=+
x?]>.
fMW:'
3WEMRE
3ETKsq
|iqowAV"
8/#4,Xx*
<L8W>(
O^mXp\
a^$e7"
cz:fNjJ
i35<o#6gw
9J\7;~o
Z+"r9AL
8Y!@8(
N5CsT-
>yr<?~
\IA,@%
j~Bf2jk
XT0]VX
}x69>q$
K3[NQ
(JB-[e
*ax&Q
){mFk=9
D0)uW=a
VC)4Lum'
M@5KhEd
Kl.#ym
YyAs5BA
*+#PXM
24mBvb|#-
&l}.&?O
tR)U*\,
|vi*Z^
#dEtl)
c-Br~l
ozC`!C
~6JIvG
,|&aW0
=1'055
!q0jVt'
Q7u+Y\
]jOUt
H63a)RC
FbF3:2zB(
Q)^~.JH
8"{$ZC
Spm1Ft
d^`d#X
xL^2]n'
C*d[eiC#
$2e,$O|
| MM98go
`*zMX?x
:B`Vhq
&X1H$3eZK
{l{`pa
,;hIj.
iA2~aC
B_%F0w
sf"PL7
#6Ngc/2
jbi:^nk
bAmDwI
*zX\c6bd
E=Tx6^
)D%vg-
o>?&4_
,()Fmzp|-
05n+bA
Ed%K $
pN.@0ck
i_#6}5
Yg28f4F
Wn]s[
43lAw
J]nFm:I@
'~5R=!w
uN'WrbH
:biP[F
fpM'JE
)&VYEQ;#
^MAgIa
LFLi-b4
,7Js_Y
kg<oFO\
:q5`Sf;X
Xyl$`[
6ZaTQaf=
9gd<Nl[
,Ly(c^
nKl_8~;
_CorExeMain
mscoree.dll
E:\A\_work\421\s\bin\obj\Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0\Release\Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0.pdb
SHA256
<.C2'.
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
Mountain View1
7651C4341
Google LLC1
Google LLC0
210919100636Z
230919100636Z0o1
Mountain View1
7651C4341
Google LLC1
Google LLC0
Gc}LI|j
Mountain View1
7651C4341
Google LLC1
Google LLC
9+~Do)]
20210919100636Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210919100636Z0+
/1(0&0$0"
contentTypeRegistry
serviceProvider
razorProject
remoteLanguageServiceWorkspace
C#_LSP
remoteLanguageServiceWorkspaceHost
filePath
90D1AC8Fam90D1AC8Fsi.d90D1AC8Fll90D1AC8F
90D1AC8F
90D1AC8FAm90D1AC8Fsi90D1AC8FSc90D1AC8FanB90D1AC8Fuf90D1AC8Ffer90D1AC8F
geeWQCKt77nFvNDFhWZYFYY4Q0l8DdzLsf2Ktd0U0TU=
oQvB4H7Z5zeP1QHYyN6Pcg==
39F70F88Ge5FDB4F345FDB4F34C9939732t39F70F88T90D1AC8Fyp39F70F88eC9939732
39F70F8839F70F88Ass5FDB4F34eC9939732mb90D1AC8Fl87D1BFF6y
90D1AC8FLoad87D1BFF6
C9939732En39F70F88tryP5FDB4F34ointC9939732
5FDB4F34In91AD085Bv1FBF1A11o87D1BFF6ke91AD085B
8E6A520B
39F70F88
5FDB4F34
C9939732
87D1BFF6
91AD085B
1FBF1A11
B651A355
AB26A68D
7F8BB48B
cipher
1BC8BC47
09F36856.Properties.7842BA7C
dadada
1.0.0.0
1.0.1998.37809
1.0.1998+b193eca729
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0
Release
b193eca729a954c1f63315d5c8a6e03d2ead8510
002400000480000094000000060200000024000052534131000400000100010007d1fa57c4aed9f0a32e84aa0faefd0de9e8fd6aec8f87fb03766c834c99921eb23be79ad9d5dcc1dd9ad236132102900b723cf980957fc4e177108fc607774f29e8320e92ea05ece4e821c0a5efe8f1645c4c0c93c1ab99285d622caa652c1dfad63d745d6f2de5f17e5eaf0fc4963d261c8a12436518206dc093344d5ad293
b03f5f7f11d50a3a
Microsoft.VisualStudio.LanguageServices.Remote.CSharp
dadada
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
Microsoft
FileDescription
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0
FileVersion
1.0.1998.37809
InternalName
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0.dll
LegalCopyright
OriginalFilename
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0.dll
ProductName
Microsoft.VisualStudio.LanguageServices.Remote.CSharp.16.0
ProductVersion
1.0.1998+b193eca729
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Reline.i!c
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.37615157
FireEye Trojan.GenericKD.37615157
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.37615157
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 005829021 )
BitDefender Trojan.GenericKD.37615157
K7GW Trojan ( 005829021 )
Cybereason malicious.1f5775
BitDefenderTheta Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACVD
Baidu Clean
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Reline.gen
Alibaba TrojanPSW:MSIL/Reline.00e302c3
NANO-Antivirus Clean
ViRobot Clean
Ad-Aware Trojan.GenericKD.37615157
TACHYON Clean
Emsisoft Trojan.GenericKD.37615157 (B)
Comodo TrojWare.Win32.UMal.fwuow@0
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic PWS.y
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.MSIL.Crypt
GData Trojan.GenericKD.37615157
Jiangmin Clean
MaxSecure Clean
Avira TR/AD.RedLineSteal.kquac
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/RelineStealer.D!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic PWS.y
MAX malware (ai score=83)
VBA32 Clean
Malwarebytes Spyware.PasswordStealer.MSIL.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet PossibleThreat.MU
Webroot W32.Trojan.Gen
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike Clean
No IRMA results available.