Static | ZeroBOX

PE Compile Time

2095-11-10 20:02:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000b6494 0x000b6600 3.83068453045
.rsrc 0x000ba000 0x000002ac 0x00000400 2.19092052763
.reloc 0x000bc000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000ba058 0x00000254 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Grindstone
Grindstone.exe
<Module>
IteratorDicAttribute
Grindstone.Attributes
Object
System
mscorlib
InterceptorInfoSchema
Grindstone.Schemes
<>c__DisplayClass2_0
FacadeErrorTemplate
Grindstone.Templates
ProxyPageRole
Grindstone.Roles
<>o__4
AuthenticationInfoSchema
InfoPageComp
Grindstone.Composer
<>o__5
Identifier
Grindstone.Descriptors
RoleInvocationModel
Grindstone.Models
TaskTestClass
Grindstone.Classes
TemplateErrorTemplate
MulticastDelegate
ReponseInvocationModel
Creator
Wrapper
SingletonInvocationModel
Params
Facade
StrategyTestClass
MethodDicAttribute
Template
Descriptor
ValueType
SchemaEntry
Grindstone.Database
Connection
SerializerPolicyDescriptor
ClientPolicyDescriptor
ErrorIdentifierRecord
Grindstone.Records
ClassPageRole
<PrivateImplementationDetails>
__StaticArrayInitTypeSize=728436
NewSystem
String
EntryPointNotFoundException
ResolveSystem
SetSystem
SelectSystem
Func`1
Boolean
IntPtr
Invoke
InvalidOleVariantTypeException
System.Runtime.InteropServices
bridge
CountSystem
UInt64
UInt32
UInt16
op_Explicit
Marshal
SizeOf
Application
System.Windows.Forms
get_ExecutablePath
op_Inequality
Thread
System.Threading
ToInt64
GetTypeFromHandle
RuntimeTypeHandle
AllocHGlobal
FreeHGlobal
m_Info
invocation
.cctor
UpdateSystem
selectionsize
Replace
CompareSystem
ValidateSystem
reference
Binder
Microsoft.CSharp.RuntimeBinder
Microsoft.CSharp
Convert
CallSiteBinder
System.Runtime.CompilerServices
System.Core
CSharpBinderFlags
CallSite`1
Func`3
CallSite
Create
Target
ToCharArray
PostSystem
get_Length
FromBase64CharArray
Encoding
System.Text
get_UTF8
GetString
CreateSystem
_Prototype
_Policy
DeleteSystem
StringBuilder
get_Chars
ToChar
Append
ToString
InvokeSystem
MoveSystem
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Exception
DefineSystem
Action
SearchSystem
CalcSystem
m_Test
VerifySystem
ConnectSystem
CSharpArgumentInfo
CSharpArgumentInfoFlags
InvokeMember
IEnumerable`1
System.Collections.Generic
Func`4
ssalCyalpsiDcreldnaHtneilCpttHpttHteNmetsyS74805
Func`5
Func`6
GetMember
m_Getter
_Config
process
m_Role
reponse
_Singleton
worker
_Utils
_Issuer
m_Importer
m_Serializer
WriteSystem
LoadLibrary
kernel32.dll
RegisterSystem
instance
FreeLibrary
AssetSystem
GetProcAddress
kernel32
PublishSystem
FindSystem
GetDelegateForFunctionPointer
Delegate
ReflectSystem
customer
hProcess
isWow64
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
lpBaseAddress
lreganaMyciloPytiruceSyciloPytiruceSSWytiruceSledoMecivreSmetsyS84980
lpNumberOfBytesWritten
exitCode
connection
handle
counter
hToken
lpApplicationName
lpCommandLine
lpProcessAttributes
lpThreadAttributes
bInheritHandles
dwCreationFlags
lpEnvironment
lpCurrentDirectory
lpStartupInfo
lpProcesedoMgnisserddAdetroppuSslennahCledoMecivreSmetsyS49574
hNewToken
hThread
pContext
selection
ProcessHandle
BaseAddress
ZeroBits
RegionSize
AllocationType
Protect
nCmdShow
indexer
attribute
product
writer
_Resolver
annotation
_Adapter
m_Exception
m_Publisher
m_Global
m_Candidate
m_Token
interpreter
_Dispatcher
_Visitor
iterator
m_Method
m_Struct
_State
m_Composer
strategy
m_Tokenizer
_Exporter
setter
predicate
_Specification
server
m_Comparator
_Callback
m_Code
m_Expression
message
_Registry
_Reader
m_Definition
ManageSystem
PushSystem
8D8F7232BEC1AD04F38066044B6CD95AD8DDB088
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
TargetFrameworkAttribute
System.Runtime.Versioning
UnverifiableCodeAttribute
System.Security
ParamArrayAttribute
DynamicAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
CompilerGeneratedAttribute
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
KotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS953652gcIRcaJz8FHQMvEB8NBA==
KotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365DQYMxcwBjkSIDIp
GotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS953652kANCwvIyAdLwAsE2ojDRJ8JBIuHRwhFxo3Px4Qd2c=
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365B0cIRcgHTkRPxg2HxA/ASh+Hh0pLXdl
GotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS953652gyLhZFJwURMH8xKB8gSg==
GotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365QIEABdEEn4GIQgjKGo7GxJ/BVo=
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365jQYDhcaQCQrIRAqEAARJysgBgsTaRgoF0VFcQ==
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365jQYGhcwCToRVQxqEA4vBxIiGlYTDTIWLyBAOisJIWc=
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365GkAKBEwJx0rCnMwEAA7DSUbHhMoaQBt
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365GhzazsdIwQSPxgPKxA/GygbGiMoaH9oLy8ZfA==
GotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365GgcaCMwGTUSMAwxG2pMAhULHlMuG3dl
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365GhzazsdIxgSPxgPKxA/GygbGiMoaH9oLy8ZfA==
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS953652gcaCMwGTUSMAwxG2pMAhULHlMuG3dl
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365zccIhEgQCAeICIjEA8zHA==
otacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365
GotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365GgcaCRFSDkrVXMpEA4RBxMhGhEuLXdl
LotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365gIENBYdPDUEChgpKBlISg==
HotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS953652giLhFGFTwqChgsLi9ISg==
ssalCyalpsiDcreldnaHtneilCpttHpttHteNmetsyS74805
Replace
FromBase64CharArray
ToCharArray
Length
GetString
JZJXuwqLHg
VotacitnehtuAnekoTnoitaitogeNipsSytiruceSledoMecivreSmetsyS95365FZxUUFBTUFBQUFFQUFBQS8vOEFBTGdBQUFBQUFBQUFRQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUE4QUFBQUE0ZnVnNEF0QW5OSWJnQlRNMGhWR2hwY3lCd2NtOW5jbUZ0SUdOaGJtNXZkQ0JpWlNCeWRXNGdhVzRnUkU5VElHMXZaR1V1RFEwS0pBQUFBQUFBQUFBYk95RDhYMXBPcjE5YVRxOWZXazZ2ekJUV3IxNWFUcTh3TE5DdlIxcE9yekFzNUsvWldrNnZNQ3pscjJ4YVRxOVdJczJ2WFZwT3IxWWkzYTlZV2s2dlgxcFByek5hVHE4d0xPR3ZWRnBPcnpBczA2OWVXazZ2VW1samFGOWFUcThBQUFBQUFBQUFBQUFBQUFBQUFBQUFVRVVBQUV3QkJBQ2gzQkZmQUFBQUFBQUFBQURnQUFJQkN3RUtBQUJhQWdBQTlnQUFBQUFBQUh0eEFBQUFFQUFBQUhBQ0FBQUFRQUFBRUFBQUFBSUFBQVVBQVFBQUFBQUFCUUFCQUFBQUFBQUFnQU1BQUFRQUFBQUFBQUFDQUVDQkFBQVFBQUFRQUFBQUFCQUFBQkFBQUFBQUFBQVFBQUFBQUFBQUFBQUFBQUJrNkFJQVVBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQlFBd0JjSVFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFRMlFJQVFBQUFBQUFBQUFBQUFBQUFBSEFDQUl3QkFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBdWRHVjRkQUFBQUNOWkFnQUFFQUFBQUZvQ0FBQUVBQUFBQUFBQUFBQUFBQUFBQUFBZ0FBQmdMbkprWVhSaEFBQjRnUUFBQ
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
Grindstone.exe
LegalCopyright
OriginalFilename
Grindstone.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Trojan.PackedNET.972
MicroWorld-eScan Trojan.GenericKDZ.79325
FireEye Generic.mg.7e400451e3153f07
CAT-QuickHeal Clean
McAfee GenericRXQO-NJ!7E400451E315
Malwarebytes Trojan.Crypt.MSIL.Generic
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKDZ.79325
K7GW Clean
Cybereason malicious.681717
Arcabit Trojan.Generic.D135DD
BitDefenderTheta Gen:NN.ZemsilF.34266.Tm0@aGu4Rkj
Cyren W32/MSIL_Kryptik.FYB.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ADAC
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKDZ.79325
Emsisoft Trojan.GenericKDZ.79325 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.bz
CMC Clean
Sophos ML/PE-A
Ikarus Clean
Jiangmin Clean
MaxSecure Trojan.Malware.121218.susgen
Avira HEUR/AGEN.1144480
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:MSIL/AgentTesla.LEG!MTB
SUPERAntiSpyware Clean
GData Trojan.GenericKDZ.79325
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4628732
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKDZ.79325
TACHYON Clean
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_100%
Fortinet MSIL/Kryptik.ACCF!tr
Webroot Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike Clean
No IRMA results available.