Static | ZeroBOX

PE Compile Time

2067-05-13 19:24:48

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0010f0d4 0x0010f200 3.64308955194
.rsrc 0x00112000 0x0000029c 0x00000400 2.14202482519
.reloc 0x00114000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00112058 0x00000244 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Grunge
Grunge.exe
<Module>
Watcher
Grunge.Filter
Object
System
mscorlib
MethodRecordDescriptor
Grunge.Descriptors
<>c__DisplayClass2_0
ProccesorRecordStrategy
Grunge.Strategies
MockVisitorListener
Grunge.Listeners
<>o__4
RegVisitorListener
Grunge.Connections
<>o__5
Record
Grunge.Tasks
Method
Grunge.Schemes
ParameterRecordDescriptor
AdvisorVisitorListener
MulticastDelegate
VisitorFacadeInstance
QueueRecordDescriptor
Database
GlobalInfoMapping
ComposerMapper
ConnectionInfoMapping
AccountFacadeInstance
ServiceFacadeConnector
Global
InstanceFacadeConnector
RegistryAttributeSchema
Importer
ValueType
IssuerRecordDescriptor
DatabaseInfoMapping
Grunge.Maps
ValFacadeConnector
ReponseMapper
Grunge.Mappers
ValueInfoMapping
AdapterVisitorListener
Observer
FieldMethodFilter
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=1092472
CloneWatcher
String
EntryPointNotFoundException
SearchWatcher
SetWatcher
SortWatcher
Func`1
Boolean
IntPtr
Invoke
InvalidOleVariantTypeException
System.Runtime.InteropServices
authentication
RestartWatcher
UInt64
UInt32
UInt16
op_Explicit
Marshal
SizeOf
Application
System.Windows.Forms
get_ExecutablePath
op_Inequality
Thread
System.Threading
ToInt64
GetTypeFromHandle
RuntimeTypeHandle
AllocHGlobal
FreeHGlobal
visitor
m_Account
.cctor
MapWatcher
nextresult
attribute
Replace
ValidateWatcher
EnableWatcher
Binder
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Convert
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`3
CallSite
Create
Target
ToCharArray
MoveWatcher
get_Length
FromBase64CharArray
Encoding
System.Text
get_UTF8
GetString
ListWatcher
_Facade
ForgotWatcher
StringBuilder
get_Chars
ToChar
Append
ToString
SetupWatcher
LogoutWatcher
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Exception
ReadWatcher
Action
instance
VerifyWatcher
FindWatcher
singleton
RateWatcher
CustomizeWatcher
CSharpArgumentInfo
CSharpArgumentInfoFlags
InvokeMember
IEnumerable`1
System.Collections.Generic
Func`4
ssalCyalpsiDcrevloseRreePprnPslennahCledoMecivreSmetsyS33516
Func`5
Func`6
GetMember
_Indexer
_Utils
m_Message
_Printer
m_Writer
_Definition
_Property
wrapper
m_Manager
WriteWatcher
LoadLibrary
kernel32.dll
OrderWatcher
FreeLibrary
NewWatcher
GetProcAddress
kernel32
_Parameter
QueryWatcher
PublishWatcher
GetDelegateForFunctionPointer
Delegate
ReflectWatcher
m_Issuer
hProcess
isWow64
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
lpBaseAddress
lepyTtnevEecarTscitsongaiDmetsyS44779
lpNumberOfBytesWritten
exitCode
handle
hToken
lpApplicationName
lpCommandLine
lpProcessAttributes
lpThreadAttributes
bInheritHandles
dwCreationFlags
lpEnvironment
lpCurrentDirectory
lpStartupInfo
lpProcesnoitpecxEysuBooTrevreSledoMecivreSmetsyS22458
hNewToken
hThread
pContext
counter
ProcessHandle
BaseAddress
ZeroBits
RegionSize
AllocationType
Protect
config
caller
nCmdShow
m_Interpreter
_Producer
m_Token
process
configuration
bridge
m_Exporter
m_Getter
_Listener
m_Mapper
m_Reader
m_Model
iterator
worker
m_Registry
product
m_Policy
m_Object
_Setter
_Exception
m_Template
_Invocation
m_Task
_Customer
_Filter
m_Initializer
m_Decorator
specification
_Merchant
m_Params
client
m_Error
m_Schema
m_Creator
m_Descriptor
interceptor
CallWatcher
LoginWatcher
1787617151CA8840FBF950CEAC520F88E9DF945E
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
ParamArrayAttribute
DynamicAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
CompilerGeneratedAttribute
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
IyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177lY+FzEVHTEoFQoRMikrCw==
IyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177Qo6BTE/PDc/KDsX
EyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177lciAgogGS4wJwkSMVwFAihyCRonIz4XMRUNMTMYflk=
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177SM+FzEvJzc8NxEIPSYZDhJwMxUgE1VT
EyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177lYQGDBKHQs8OHYPCikGRQ==
EyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177DwmNjFLKHArKQEdClwdFChxKFI=
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177wo6ODEVeioGKRkUMjY3KBEuKwMaVzoeMUp/fw==
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177wo6LDE/MzQ8XQVUMjgJCCgsN14aMxAgCS96NAYBKFk=
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177VciHjc/HRMGAnoOMjYdAh8VMxshVyJb
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177VZRXR0SGQo/NxExCSYZFBIVNyshVl1eCSAjcg==
EyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177VY+XgU/Izs/OAUPOVxqDS8FM1snJVVT
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177VZRXR0SGRY/NxExCSYZFBIVNyshVl1eCSAjcg==
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177lY+XgU/Izs/OAUPOVxqDS8FM1snJVVT
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177gk+FDcvei4zKCsdMjkVEw==
yTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177
EyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177VY+XgJKcjcGXXoXMjg3CCkvNxknE1VT
JyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177zwmAjASBjspAhEXCi9uRQ==
FyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177lYAGDdJLzIHAhESDBluRQ==
ssalCyalpsiDcrevloseRreePprnPslennahCledoMecivreSmetsyS33516
Replace
FromBase64CharArray
ToCharArray
Length
GetString
CdhnSxKBeo
VyTtinIyarrAcitatSsliateDnoitatnemelpmIetavirP21177FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFnQUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFCUVJRQUFUQUVEQUlCclE0OEFBQUFBQUFBQUFPQUFBZ0VMQVRBQUFJZ0JBQUFrQXdBQUFBQUE3bzRCQUFBZ0FBQUF3QUVBQUFCQUFBQWdBQUFBQkFBQUJBQUFBQUFBQUFBRUFBQUFBQUFBQUFBQUJRQUFCQUFBclprQ0FBSUFRSVVBQUJBQUFCQUFBQUFBRUFBQUVBQUFBQUFBQUJBQUFBQUFBQUFBQUFBQUFKeU9BUUJQQUFBQUFNQUJBTGdlQXdBQUFBQUFBQUFBQUFDWUFRRFFDQUFBQU9BRUFBd0FBQUNBamdFQUhBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFDQUFBQUFBQUFBQUFBQUFBQ0NBQUFFZ0FBQUFBQUFBQUFBQUFBQzUwWlhoMEFBQUFySVlCQUFBZ0FBQUFpQUVBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUdBdWNuTnlZd0FBQUxnZUF3QUF3QUVBQUNBREFBQ01BUUFBQUFBQUFBQUFBQUFBQUFCQUFBQkFMbkpsYkc5akFBQU1BQUFBQU9BRUFBQUVBQUFBckFRQUFBQUFBQUFBQUFBQUFBQUFRQUFBUWdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQU
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Grunge.exe
LegalCopyright
OriginalFilename
Grunge.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.79325
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.GenericKDZ.79325
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Trojan.GenericKDZ.79325
K7GW Riskware ( 00584baa1 )
K7AntiVirus Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.FYB.gen!Eldorado
ESET-NOD32 a variant of MSIL/Kryptik.ADAC
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKDZ.79325
Emsisoft Trojan.GenericKDZ.79325 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PackedNET.972
Zillya Clean
TrendMicro Clean
Sophos Mal/Generic-S
Ikarus Trojan-Spy.MSIL.Agent
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1144480
MAX malware (ai score=87)
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D135DD
SUPERAntiSpyware Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4628732
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.RedLineStealer
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ACCF!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.