Static | ZeroBOX

PE Compile Time

2021-09-27 20:43:07

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00039c54 0x00039e00 7.13019888763
.rsrc 0x0003c000 0x00011b08 0x00011c00 4.19921890619
.reloc 0x0004e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003c130 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0004c958 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004c96c 0x000003e0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004cd4c 0x00000db7 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
^6|=8n
`7K)M$
t{HQ+9*p,zh
?ym*xW!{
~`R+ON
pH+t0<
f#dTwp
lDwH#'
#4;A|.~*m
Qsq}!]
{Z2E0:
]T0`J@e
;;f*Isr(>
)/_.]/xJ
e3dG=F
rFFdV7
#JbO=a}
@h/c+RY
gH>8}(^J
B5gfN}
YQ+S5|
8_e2a!*
_(<|7i
c(1~Wd
+Y2(HX
FdmRX)
>fb?rb
70$80M
+L:6AeCF
="{v\Nc]
\]?X+o
TI:":
765VLW
@}Pj[9A
{L&z2!Kf
QZ@_@w
\OPF7a
i$Fy^z
":WY\ 46
0$@0/W
f)L*#R
haI=Ko
V6er|n
Z=8!~G"
|,YExd
1J*JE;
:u~J0E
^VqCn
u F[b7PJ
jlB."-|
vt=S [
_!=B=zo
/:#C3)
j,FF'H
yo\XWLQ5
,@L8n[
S\I3We
8dzeT#
rr@w|$S
9tfOU
WJjFoy
P^#MtNu
h*&YI?h
+2N\c
'`KX9I
MB1GY8
BuIV<4Kp
cJe3"1
=$(EK=#@
}o5jfHK3GH
%tali_
`6^2*/p
z71"BgJ
ww%w<f
li&'B<
o,%"E.K6
C:$'95d,~R
lSL3QYG:
+z}BW@
P!251$
>l94}5
V*JP >
Hn!/"rMP
0%I@Rk
yPv&55
Hq<+F\!\7
_viUS&(
mHUQtu
%J"F^P
i`'& {q'5
*Ng`b
lS 9U=5%
=S/~ 8
@^4b4
qr.7F0`
og/TCQT
-;mr c
S>$~{\n
,b1u,}
}Cl23B
e9!h)]x
E>A+)m
Mzshv[
*I0pid5
7d4CL9t
i?d,e!
CY$;rl2
Mezgia%
1axk<iV|<Q
9 kx1~
\7[Fm##|>
eVC8jH:J~
AedyXx
tp^;0
i.HC(p
T$BFO`
Ty";\2R_UAUpm
9r4a
2Exc/O
k6O48#y
u/?.us
38,poRL
81@N/(
a5Fw#0
(_\XI@@
9!63zv(
L(t2L]E
Y;)pn4
x^Yn,I
\!fi)H!
e7 8xfD(
`B)Ytw
=' #En
n^RqPf3)2
Y6B.7Y
,q6f)uH)
BDk&*6
3*@.x
j{tj6Xc}
NBr(,mb
]3;6fY
3}OsD^\
ouB/h'
R`n:h[R
AOhLL{Z`
=#-@C,XR(N
Yl}T%dv
gmWj 4
&kl.8|Nk
(DoKjkQ:
48&]D
=3O]rZ
b<B._z
P*!@$@/
94$4im
Vd[wu ~OW
0)c![J
B~1_BV
Oqo/u*
$"qtxe#
!$_kIWt
+S!K''
R!e [-
mBc jM
ip'|T:
%af>EM
nAV)?s<A
K4#qC2Z*
R@ZJ:C
/r,eb7'
x:W&;CWO
[DjwNZ
Gu])_$
T1w}gJ
gLRF{H
W8c@7_
jGP@M"
orp9DU
#<OA[py
uUzY?o
;7J[M)N6'
jU$Njo
(5C+*3
u+0$V!l
a+\q4tM
Zc%&8I
Z?_b`
PZ fJz
Z OLTza
*:!a8O
/*Z Ra
C/La8f
B'Ba8y
Z cw>na8
^o%&8\
o/EZ V"
lG%&8x
-[b%%&8
gFi,Z gA
B ruZ
h5qWZ X
)Z $oUga8
D,pa8K
mH.Za8H
_bj2
_bY*
68Z f)
[Oqa8M
$Z aM)
*Z 4Z6
FZ 4pbea+
1R%&8q
4k1x%+
]xyM8
vh`D%+
k[.8D
Mp%&8v
],0F%+
wpSa8W
Z Le:_a8
Z_bX
Z <2m0a8^
#\Fg%&8X
rU: !I
s[aZ V
Y_cX*
L9WD%+
pZ +>g
\+wmZa8q
Z %`#`a8
7: v>S
8(a8=
~[7N(
_^uRa%
%[Za8e
];]{8:
_^uRa%
abg^Z {
*#%&8q
^~%&8A
!6Za8`
*GEZ &x
?-'O(
`5iZ M
Z M}.ma8-
+%yvZ
_LZa8
*&1Za8v
cTiT 'l
,HX/(
*%Rp(
BZ *#t
6LlbZ
%kZa82
Qi9n+
K>Z Le
]U%&8)
WUWZ(
awZa8U
B`3Za8
H-Wr(
uZpvZ
.s%&8]
`Z V*=
.4j2Z
+a~Za8I
Zh0p%+
9%&8i
v2.0.50727
#Strings
Recover.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
|zu?\?@daadC"w#;n{!P+r+K'
System.Windows.Forms
UserControl
IContainer
System.ComponentModel
TextBox
ContainerControl
Dispose
IDisposable
ComponentResourceManager
Control
ProcessStartInfo
System.Diagnostics
Process
WebClient
System.Net
FileStream
FileMode
Random
RegistryKey
Microsoft.Win32
List`1
System.Collections.Generic
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
PaddingMode
CipherMode
ICryptoTransform
MemoryStream
CryptoStream
CryptoStreamMode
Encoding
System.Text
RemoteCertificateValidationCallback
System.Net.Security
WebRequest
WebResponse
StreamReader
TextReader
<>9__4_0
X509Certificate
System.Security.Cryptography.X509Certificates
X509Chain
SslPolicyErrors
KeyNotFoundException
DateTime
CultureInfo
System.Globalization
<>9__0_0
<>9__0_1
ProcessModule
StringComparison
SecurityProtocolType
DirectoryInfo
RawSecurityDescriptor
System.Security.AccessControl
GetKernelObjectSecurity
advapi32.dll
SetKernelObjectSecurity
GetCurrentProcess
kernel32.dll
Win32Exception
GenericSecurityDescriptor
RawAcl
SecurityIdentifier
System.Security.Principal
WellKnownSidType
CommonAce
AceFlags
AceQualifier
GenericAce
value__
PROCESS_CREATE_PROCESS
PROCESS_CREATE_THREAD
PROCESS_DUP_HANDLE
PROCESS_QUERY_INFORMATION
PROCESS_QUERY_LIMITED_INFORMATION
PROCESS_SET_INFORMATION
PROCESS_SET_QUOTA
PROCESS_SUSPEND_RESUME
PROCESS_TERMINATE
PROCESS_VM_OPERATION
PROCESS_VM_READ
PROCESS_VM_WRITE
DELETE
READ_CONTROL
SYNCHRONIZE
WRITE_DAC
WRITE_OWNER
STANDARD_RIGHTS_REQUIRED
PROCESS_ALL_ACCESS
Exception
AppDomain
ResolveEventHandler
<>9__1_0
AssemblyName
BindingFlags
Binder
FieldInfo
HttpWebRequest
DecompressionMethods
0L`w}1<MGJd~"mY"^,'Bh LH!
ResourceManager
System.Resources
Settings
PhotoShop__shmCdV5H9ZHSpcEQ.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
Recover
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
NeutralResourcesLanguageAttribute
CompilerGeneratedAttribute
Newtonsoft.Json
JsonPropertyAttribute
NewtonsoftJson.Json
FlagsAttribute
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
0L`w}1<MGJd~"mY"^\,'Bh LH!.resources
WnDVpfrCMFGVrgHcSFiYmKQyyBdW
|zu?\\?@daadC"w#;n{!P\+r\+K'.resources
PhotoShop__shmCdV5H9ZHSpcEQ.Resources.Newtonsoft.Json.dll
Environment
String
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Length
ReadByte
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Buffer
BlockCopy
GetElementType
CreateInstance
get_UTF8
GetString
Intern
get_CurrentDomain
add_AssemblyResolve
get_FullName
get_Name
op_Equality
System.Drawing
set_Location
Padding
set_Margin
TextBoxBase
set_Multiline
set_Name
set_Size
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_Text
get_Controls
ControlCollection
SystemColors
get_HotTrack
set_BackColor
set_TabIndex
ResumeLayout
PerformLayout
SuspendLayout
IntPtr
get_Size
NewGuid
Remove
Insert
GetTempPath
Combine
Directory
Exists
ToString
CreateDirectory
WriteAllText
IsNullOrEmpty
set_UseShellExecute
set_Verb
DownloadData
GetEnvironmentVariable
GetDirectories
ToCharArray
Enumerator
GetEnumerator
MoveNext
get_Current
Registry
CurrentUser
ToLower
Contains
OpenSubKey
GetValue
CreateSubKey
SetValue
LocalMachine
JsonConvert
DeserializeObject
set_Padding
set_Mode
set_KeySize
set_BlockSize
Convert
FromBase64String
CreateEncryptor
get_ASCII
GetBytes
FlushFinalBlock
ToArray
ToBase64String
Replace
CreateDecryptor
ServicePointManager
set_ServerCertificateValidationCallback
Create
set_Method
set_ContentType
set_ContentLength
GetRequestStream
GetResponse
GetResponseStream
ReadToEnd
System.Text.RegularExpressions
ClassesRoot
Substring
HttpWebResponse
IFormatProvider
get_Now
set_Proxy
IWebProxy
Console
WriteLine
set_Timeout
set_KeepAlive
set_SecurityProtocol
ASCIIEncoding
get_ExitCode
get_CurrentCulture
Boolean
GetDirectoryName
GetFileNameWithoutExtension
GetProcessesByName
get_MainModule
get_FileName
StartsWith
DownloadFile
get_NewLine
get_BinaryLength
GetBinaryForm
get_DiscretionaryAcl
InsertAce
TimeSpan
FromHours
op_Subtraction
get_TotalDays
ToBoolean
get_TotalMilliseconds
GetEntryAssembly
get_Location
GetCreationTime
GetExecutingAssembly
GetManifestResourceNames
GetManifestResourceStream
SettingsSection
System.Net.Configuration
GetAssembly
GetType
InvokeMember
GetField
get_Chars
set_AutomaticDecompression
get_Assembly
Synchronized
ConfuserEx v1.0.0
WrapNonExceptionThrows
PhotoShop__shmCdV5H9ZHSpcEQ
$200f0fc5-c957-4cc7-998c-554db4fb0b2a
0.0.0.11
linkDownload
execution_param
nbrDay
ListProducts
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- Options du manifeste de contr
le de compte d'utilisateur
Si vous souhaitez modifier le niveau du contr
le de compte d'utilisateur Windows, remplacez le
n
ud requestedExecutionLevel par l'une des propositions suivantes.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
La sp
cification de l'
ment requestedExecutionLevel d
sactive la virtualisation de fichiers et du Registre.
Supprimez cet
ment si votre application a besoin de la virtualisation pour des
raisons de compatibilit
descendante.
-->
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Liste des versions de Windows pour lesquelles cette application a
e, et sur
lesquelles elle doit fonctionner. Supprimez les marques de commentaire des
ments appropri
s, et Windows va
automatiquement s
lectionner l'environnement le plus compatible. -->
<!-- Windows
Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows
8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows
10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indique que l'application prend en charge DPI et qu'elle n'est pas automatiquement mise
chelle par Windows
un niveau de
DPI plus
. Les applications Windows Presentation Foundation (WPF) prennent automatiquement en charge DPI et n'ont pas besoin
d'opter pour ce choix. Les applications Windows Forms qui ciblent .NET Framework
4.6 et qui optent pour ce param
tre, doivent
galement affecter la valeur 'true' au param
tre 'EnableWindowsFormsHighDpiAutoResizing' dans leur fichier app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Activer les th
mes pour les contr
les et bo
tes de dialogue communes de Windows (Windows XP et version ult
rieure) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
PhotoShop__shmCdV5H9ZHSpcEQ
CompanyName
PhotoShop__shmCdV5H9ZHSpcEQ
FileDescription
PhotoShop__shmCdV5H9ZHSpcEQ
FileVersion
0.0.0.11
InternalName
Recover.exe
LegalCopyright
PhotoShop__shmCdV5H9ZHSpcEQ
LegalTrademarks
OriginalFilename
Recover.exe
ProductName
PhotoShop__shmCdV5H9ZHSpcEQ
ProductVersion
0.0.0.11
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.47130157
FireEye Generic.mg.3a8369a0ce3b79b7
CAT-QuickHeal Trojan.IGENERIC
ALYac Trojan.GenericKD.47130157
Cylance Unsafe
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Adware ( 0057ecab1 )
BitDefender Trojan.GenericKD.47130157
K7GW Adware ( 0057ecab1 )
CrowdStrike Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.34218.sm0@aGvDUDk
Cyren W32/Trojan.IKKZ-2482
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Adware.CsdiMonetize.AS
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Agent.gen
Alibaba AdWare:MSIL/CsdiMonetize.6cf317ae
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.47130157
TACHYON Clean
Emsisoft Trojan.GenericKD.47130157 (B)
Comodo Clean
F-Secure Clean
DrWeb Adware.WizzMonetize.1
Zillya Trojan.Agent.Win32.2485484
TrendMicro TROJ_GEN.F0CBC0UJF21
McAfee-GW-Edition RDN/Generic PUP.z
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira HEUR/AGEN.1142317
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Agent.vb
Microsoft Backdoor:Win32/Bladabindi!ml
SUPERAntiSpyware PUP.Tuto4PC/Variant
ZoneAlarm Clean
GData Trojan.GenericKD.47130157
Cynet Malicious (score: 100)
AhnLab-V3 Adware/Win.CsdiMonetize.C4626882
Acronis Clean
McAfee RDN/Generic PUP.z
MAX malware (ai score=82)
VBA32 TScope.Trojan.MSIL
Malwarebytes Adware.Tuto4PC
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.F0CBC0UJF21
Tencent Msil.Trojan.Agent.Llrf
Yandex Trojan.Agent!t08fCWj21vE
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Adware/CsdiMonetize
Webroot W32.Malware.Gen
AVG FileRepMalware [PUP]
Avast FileRepMalware [PUP]
No IRMA results available.