Static | ZeroBOX

PE Compile Time

2021-11-10 18:57:19

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000013f8 0x00001400 5.53628279097
.rsrc 0x00004000 0x00046e78 0x00047000 4.83292308113
.reloc 0x0004c000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004a1f0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a1f0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a1f0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a1f0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0004a1f0 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0004a658 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0004a6a4 0x00000466 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004ab0c 0x0000036a LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
ConsoleApp17
ConsoleApp17.exe
mscorlib
System
System.Core
user32.dll
Cmivqnidpxoqmmqmf.Properties.Resources.resources
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
IEnumerable`1
System.Collections.Generic
List`1
ApplicationSettingsBase
System.Configuration
SettingsBase
Console
DebuggerNonUserCodeAttribute
System.Diagnostics
Process
Exception
Func`2
CultureInfo
System.Globalization
IntPtr
Enumerable
System.Linq
SecurityProtocolType
System.Net
ServicePointManager
WebClient
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
Binder
BindingFlags
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
String
Thread
System.Threading
<Module>
Settings
Cmivqnidpxoqmmqmf.Properties
Cmivqnidpxoqmmqmf
.cctor
ShowWindow
Synchronized
Single
InvokeMember
Reverse
ToArray
GetExportedTypes
AddRange
get_FullName
op_Equality
GetCurrentProcess
get_MainWindowHandle
set_Title
WriteLine
set_SecurityProtocol
DownloadData
GetTypeFromHandle
get_Assembly
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
$c5cec0ca-60b1-42b8-b34e-850979faf7f2
VCopyright 1984-2017 Adobe Systems Incorporated and its licensors. All rights reserved.
Adobe Acrobat DC
Adobe Systems Incorporated
Adobe Acrobat DC
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
WrapNonExceptionThrows
18.9.20050.57426
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?><assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" /></application></compatibility><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware><longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware></windowsSettings></application></assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDING
yng89ttNS3mg1k1ZvU0.kwtUgftXAKWHkDhFoPV
http://84.252.121.97/ken/ConsoleApp17.png
kojtpJSCx9
Cmivqnidpxoqmmqmf.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Adobe Acrobat DC
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Acrobat DC
FileVersion
18.9.20050.57426
InternalName
ConsoleApp17.exe
LegalCopyright
Copyright 1984-2017 Adobe Systems Incorporated and its licensors. All rights reserved.
LegalTrademarks
OriginalFilename
ConsoleApp17.exe
ProductName
Adobe Acrobat DC
ProductVersion
18.9.20050.57426
Assembly Version
18.9.20050.57426
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Bulz.776408
FireEye Generic.mg.521339ae9fa89c3a
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Bulz.776408
K7GW Clean
Cybereason malicious.11ff91
Arcabit Trojan.Bulz.DBD8D8
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky VHO:Trojan-Downloader.MSIL.Seraph.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Bulz.776408
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Gen:Variant.Bulz.776408 (B)
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
GData Gen:Variant.Bulz.776408
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Bulz.776408
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Inject
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.