Static | ZeroBOX

PE Compile Time

2021-11-09 19:30:38

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002285c 0x00022a00 7.67370453489
.rsrc 0x00026000 0x0000054a 0x00000600 3.98317231714

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000260a0 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00026360 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

!This program cannot be run in DOS mode.
`.rsrc
o<2;)3
Sz2u*a`
7C)[0O
<A1Z*W
[lRY~G
k'xkJ%
Swb?2{
y^"H;2-$
f@(`(%j
7({Q9&
%dfP:*
OS;U]is
O+X>;Z
tg/:&+m
PZE%xb
gwa?p|
V_as295o
(1iL}n52
.N_{l|
B/'5PxC
Y{YO!!<c
:'d{t)
GV09#8
6UE3!Nc
{t5F}v
-*@nwOhv
7; +<*Bx
j7S0B1
MC,tBPh
72LPd"
nIEl&4
#7s_Okm
4YWc[p
s6N}@_
G!D\0#
m)Yb^9
pSDpb<A
&zTmhG
|s39u?y
VgI0+;
mF1iGw
#m|!~f
QZ,Ygh
lp`\DG`B
v&i"kR
P,&/y;
aJn`ps
s!b-
1OVex]
]TkF.~
-[3>N<
$F"2,V
n-0g_n9
~<Mz>M
%];J!O>^
Duk/@/3
qnP66fh
_ 2}^#
iK Z~J
HLS,8A
SW8VN{
7wgTg*
P_lU46
^C{IYdM
2TJ~aV~
D:M`t<
HOp9NE3@
>8Le^U
P<pzH4
cdQ4mro
R&6-`m
e&@z73o
['>&ci
bA"l?
,ikpQaI
IaKQ[:
Ni`;S{D
o=UJ}oe8
. :w1/4rs
EGE57 9?l
NNzYY+
-//2^@
e6+?h`<
/7VU9P
Cz0]AB
'ZhJZ
v0xk;t
y\b$yO
8Gs{@b
1jNggZT
e/(~j0p
1h@ERYt
7;U9"m]\bQH
lQo()0
Uh9V|o8,
-_1w>wm
nR-7IE
f`D,+>
OC-D}^%7N
`it/V2
ZAK75%
#.h& BR
a8[#<{
~`*)b,
U.LdaYHU
&C[xcp
xBrGC.
y3(.V'
*%:S`1qL]
ei~8K?vcp
>=LnwE
V%wa{tw
*z60c<Z
2VUCiv
3~QKvU
9t+`kh
1~C8DR W
>XM>*T
4jyyRO
{+DPL:7
:UZsUr
"=uTh8#
2<BD6U\
;Pq7Vf
{h>3!?X
3}W(bb
ex:[LcT
iCa-YI0j
%]Y4(v
iNTCP<o
zT+_o"W
;\j\i% G,
kEvxYE
\d@@CA4
kUv3D{,3c
4-[AG{
)-(-Zo0
J,_i/`
Lxmi,&
A6vp\,
hpb6*W
'NyfG
GUTN[Y
w\`:eE
`iK9X%
9sZVD]x
z{yQ,"`1
\Su;I
jz7ih#V
e-jK[sn
fZWOg"
M{;,ok
}\t<pJ
VG63p#
]w/"mt{=@
wWP_fr[I
Hi?!SZ
BUI&]h
i0}Cwt;
Pd*>=5
(>0no['r
["rF:W
1SBm^p4
E/CFY^
H+^Y":
t&#i<d
!b|EZc
"hZ[0n
^@=I*"
vXVNf[8
g.u[HU
Ie%PJw
fed\j6h
<hR.;%*F
+Ad8VK
}|*9uR
-+:f[o
BOQwASe
9qu[&-
wS7^qK
*IE<Z
uD{a8z
wpZa8k
Z?_b`
+&$s%+
HiCa88
d=wa81
lZ 4Sg
&kfa8~
N)%a8.
Z 1&5za8
b%&89
u#/Z %
Z I~yma8@
}Z ,r1a8
>ciZ g
-Z d,[
_bj/
J}$D+
_bY*
~u=a8n
rr,2Z O
F.oa8c
1b~; M(@fa%
tcZa8g
LcDa8:
^`C_%+
;u;_%&
_Oea8x
c 3)T2a%
Z_bX
Z _x[*a+
Y_cX*
Xs}a%
/T@%&+
/V_%&+
_:Z Oc
cP%@Z
v4.0.30319
#Strings
#Strings
#Schema
UInt32
Dictionary`2
get_UTF8
<Module>
FXSQNEYqdDbuBrlbvhGdengfdhLTA
QBtYsSH
System.IO
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentThread
get_IsAttached
set_IsBackground
GetMethod
CreateInstance
GetHashCode
ZipArchiveMode
Invoke
IEnumerable
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
get_FullName
ValueType
GetElementType
MethodBase
ApplicationBase
Dispose
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
AssemblyTrademarkAttribute
SuppressIldasmAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
GetObjectValue
ZipArchive
get_IsAlive
add_AssemblyResolve
QBtYsSH.exe
System.Threading
NewLateBinding
Encoding
IsLogging
FromBase64String
ToString
GetString
get_Length
System.ComponentModel
LateCall
MemoryStream
System
Boolean
System.ComponentModel.Design
AppDomain
get_CurrentDomain
System.IO.Compression
System.Reflection
Exception
Intern
MethodInfo
Buffer
ResourceManager
Debugger
ResolveEventHandler
System.CodeDom.Compiler
Computer
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
System.Diagnostics
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
okb8JV5Z4.resources
ResolveEventArgs
Equals
Conversions
System.Collections
RuntimeHelpers
GetObject
LateGet
Environment
get_Current
ParameterizedThreadStart
Convert
FailFast
MoveNext
System.Text
InitializeArray
GetCallingAssembly
GetExecutingAssembly
BlockCopy
ZipArchiveEntry
op_Equality
1.2.3.4
WrapNonExceptionThrows
MyTemplate
14.0.0.0
My.Computer
My.Application
My.User
My.WebServices
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.2.3.4
InternalName
QBtYsSH.exe
LegalCopyright
OriginalFilename
QBtYsSH.exe
ProductName
ProductVersion
1.2.3.4
Assembly Version
1.2.3.4
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.df90b2e12b0377db
CAT-QuickHeal Clean
McAfee Artemis!DF90B2E12B03
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren W64/MSIL_Kryptik.DJR.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/Kryptik.ACJJ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1142184
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Emsisoft Trojan.Crypt (A)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1142184
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Backdoor.MSIL.Androm.gen
Microsoft Trojan:MSIL/Reline.BE!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Spy.Agent
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
AVG FileRepMalware
Cybereason malicious.a004ec
Avast FileRepMalware
No IRMA results available.