Static | ZeroBOX

PE Compile Time

2021-11-07 20:02:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00008504 0x00008600 5.59730504143
.reloc 0x0000c000 0x0000000c 0x00000200 0.0611628522412
.rsrc 0x0000e000 0x00004a28 0x00004c00 7.73320430042

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000e130 0x000041d1 LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00012304 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00012318 0x000003a4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000126bc 0x0000036a LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.reloc
B.rsrc
%&d(
%&iT(
%&zX(
%&n.!
%& .$
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
/nS[E!ww
v4.0.30319
#Strings
staring
staring.exe
mscorlib
System
System.Core
user32.dll
Cjfhmlelbxpe.Properties.Resources.resources
staring$
staring%
Attribute
BadImageFormatException
BitConverter
Boolean
Buffer
GeneratedCodeAttribute
System.CodeDom.Compiler
Dictionary`2
System.Collections.Generic
IEnumerable`1
IEnumerator`1
IList`1
List`1
IEnumerator
System.Collections
ApplicationSettingsBase
System.Configuration
SettingsBase
Convert
Delegate
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
ProcessStartInfo
ProcessWindowStyle
Double
EventArgs
EventHandler
Exception
CultureInfo
System.Globalization
NumberStyles
IDisposable
IntPtr
BinaryReader
System.IO
CompressionMode
System.IO.Compression
DeflateStream
MemoryStream
Stream
Enumerable
System.Linq
ModuleHandle
MulticastDelegate
SecurityProtocolType
System.Net
ServicePointManager
WebClient
NotSupportedException
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
ConstructorInfo
DynamicILInfo
System.Reflection.Emit
DynamicMethod
ILGenerator
OpCode
OpCodes
OperandType
SignatureHelper
ExceptionHandlingClauseOptions
FieldInfo
LocalVariableInfo
MemberInfo
MemberTypes
MethodBase
MethodBody
MethodInfo
Module
ParameterInfo
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeFieldHandle
RuntimeMethodHandle
RuntimeTypeHandle
DESCryptoServiceProvider
System.Security.Cryptography
ICryptoTransform
SymmetricAlgorithm
Single
STAThreadAttribute
String
Encoding
System.Text
Monitor
System.Threading
UInt16
UIntPtr
<Module>
Settings
Cjfhmlelbxpe.Properties
AssemblyInfoAttribute
Cjfhmlelbxpe
DirectoryDictionary
ComponentDesigner
ConditionProvider
DirectoryToken
ClientSettings
PaneToken
PackageHelper
ComponentSite
ControlCollection
EmulatorToken
ActionSerializer
ActivatorSite
ActivatorStream
AddinProvider
AspectList
AspectProvider
AssemblyResolver
AssistantScope
AssistantStack
BitmapSet
BookmarkEventArgs
BuilderDesigner
ClientEventArgs
ClientResolver
ConditionQueue
ConfigSet
ConnectionLayout
ConnectionType
ControlManager
ControlSettings
DatabaseToken
DeploymentDictionary
DeploymentEventArgs
DeviceEventArgs
DeviceStack
DialogService
DirectoryManager
DirectoryQueue
DiskSite
DiskTable
DockingPaneResolver
DomainStack
DriveAttribute
EditorSettings
EmulatorScope
FileInfo
FileLoader
FileManager
FormFactory
FormInvoker
FormScope
LineList
MenuItemResolver
MenuItemTable
MenuItemType
MethodInvoker
MethodService
MethodSite
MethodToken
NetworkSerializer
NodeStream
OptionsManager
OptionsResolver
OptionsSerializer
OptionsSettings
OutlineDictionary
OutlineTable
PackageTree
PageDictionary
PageSettings
PartitionFactory
PathResolver
PathStack
PcitureTree
ProcessInfo
ProjectProvider
ProjectType
QueueQueue
QueueSerializer
QueueService
QueueStream
QueueTable
ReferenceInvoker
RegistryInvoker
ResourceService
SelectionToken
ServerStream
SolutionDesigner
SolutionEditor
StoreManager
StoreProvider
StreamHelper
StubDesigner
StubTree
SymbolScope
SymbolTable
TemplateHelper
TextFileSettings
ToolbarProvider
ToolbarResolver
ToolboxStack
ToolboxToken
TreeNodeResolver
VectorFactory
ViewFactory
ViewHelper
WindowDesigner
.cctor
ProcessMenuItem
cancelInstance
containerEnabled
outputLength
lastManager
keywordsSet
colorSet
variableHeader
nextUrl
previousTimer
categoryCount
pathEnabled
rootFilter
activeFont
outputCollection
childVersion
optionsMap
variableAvailable
logInstance
lockSet
currentWindow
propStoreSet
get_ProcessMenuItem
TestTreeNode
Invoke
ShowWindow
get_FullName
get_Chars
get_Assembly
set_SecurityProtocol
ReadByte
InvokeMember
get_Position
GetCurrentProcess
set_WindowStyle
IndexOf
TransformBlock
ToArray
Substring
get_MainWindowHandle
AddRange
get_InputBlockSize
GetTypeFromHandle
WaitForExit
set_Capacity
get_OutputBlockSize
set_Key
set_CreateNoWindow
Synchronized
set_FileName
CreateDecryptor
Combine
TransformFinalBlock
GetBytes
set_Position
GetExportedTypes
GetExecutingAssembly
set_ErrorDialog
DownloadData
set_IV
set_Arguments
Reverse
get_Length
FromBase64String
get_UTF8
GetString
GetManifestResourceStream
ToInt32
ToInt64
ToSingle
ToDouble
BlockCopy
get_Unicode
Intern
GetModules
get_ModuleHandle
ResolveTypeHandle
ResolveMethodHandle
GetMethodFromHandle
GetFields
get_IsStatic
get_FieldType
CreateDelegate
GetParameters
get_DeclaringType
get_IsValueType
MakeByRefType
get_ParameterType
get_ReturnType
GetILGenerator
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
get_IsFamilyOrAssembly
Callvirt
SetValue
Newobj
ReadInt32
set_Item
Dispose
GetMethodBody
get_Name
TryGetValue
GetDynamicILInfo
SetCode
GetLocalVarSigHelper
get_LocalVariables
GetEnumerator
get_Current
get_LocalType
get_IsPinned
AddArgument
MoveNext
GetSignature
SetLocalSignature
GetTokenFor
SetExceptions
GetValue
get_Value
get_Module
GetGenericArguments
get_OperandType
ResolveString
get_Size
ResolveSignature
ResolveMethod
get_MethodHandle
get_TypeHandle
ResolveField
get_FieldHandle
ResolveType
ResolveMember
get_MemberType
Concat
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
Sentinel
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4%
Sentinel desktop and web client.
0.3.4.0
$5a250297-b29d-4416-ab39-ebcfdb8c9d7a
Copyright
2021 Sentinel
_CorExeMain
mscoree.dll
"MDfdfdU
@R-H2}
Ca<3U
e2v|ET
dVv#`D
".h>MV
/`]>U5
&2>BDj
[wBgN$8
'o =g}
f1V!v4`uo
Z4n0M-
$B[ZqVo
AyOU}=@
9Jn1iy
]ssQyc
[qWnDS-
k[Dh7J
z'Sw?Fv
<?xml version="1.0" encoding="utf-8"?><assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" /></application></compatibility><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware><longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware></windowsSettings></application></assembly>
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
180917000000Z
201010235959Z0f1
Cambridgeshire1
Cambridge1
RealVNC Ltd1
RealVNC Ltd0
V%`IOoR
VxHzDjas
http://sv.symcb.com/sv.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
?pg|/d
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
u+t PV
http://www.realvnc.com/ 0
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
200529121611Z0#
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
180917000000Z
201010235959Z0f1
Cambridgeshire1
Cambridge1
RealVNC Ltd1
RealVNC Ltd0
V%`IOoR
VxHzDjas
http://sv.symcb.com/sv.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
?pg|/d
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
http://www.realvnc.com/ 0/
%&q{Db3{
20200529121611Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
200529121611Z0/
/1(0&0$0"
@QN-L1P
"3D9B94A98B-76A8-4810-B1A0-4BE7C4F9C98DA2#
c3RhcmluZyU=
c3RhcmluZyQ=
PublicKeyToken=
publickeytoken=
c3RhcmluZyo=
_Encrypted$
dynamic method does not support fault clause
unexpected OperandType
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Sentinel desktop and web client.
CompanyName
Sentinel
FileDescription
Sentinel desktop and web client.
FileVersion
0.3.4.0
InternalName
staring.exe
LegalCopyright
Copyright
2021 Sentinel
LegalTrademarks
OriginalFilename
staring.exe
ProductName
Sentinel
ProductVersion
0.3.4.0
Assembly Version
0.3.4.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.47352306
FireEye Generic.mg.fc0fc8c35a580893
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.47352306
K7GW Clean
Cybereason malicious.ba5088
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.47352306
Emsisoft Trojan.GenericKD.47352306 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Trojan.GenericKD.47352306
Jiangmin Clean
Webroot W32.Trojan.GenKD
Avira Clean
MAX malware (ai score=95)
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/RedLineStealer
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.MSIL.CryptoObfuscator
eGambit PE.Heur.InvalidSig
Fortinet PossibleThreat.PALLAS.H
BitDefenderTheta Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.