Static | ZeroBOX

PE Compile Time

2095-09-17 19:21:26

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00003b24 0x00003c00 6.04337190536
.rsrc 0x00006000 0x0002e300 0x0002e400 6.58877762132
.reloc 0x00036000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0003370c 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00033b74 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00033bf8 0x00000318 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00033f10 0x000003ed LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
<*X JLA,a
X hj[@X
[mxae
X hj[@X j
$K X 0
<*X JLA,a
[mxae
b 8uoLa
$K X ov|
v4.0.30319
#Strings
ConsoleApp3
ConsoleApp3.exe
<Module>
Program
WindowsFormsApp41
Object
System
mscorlib
Resources
WindowsFormsApp41.Properties
Settings
ApplicationSettingsBase
System.Configuration
<Module>{8c09d2ab-0071-4348-8a95-81379cdf5762}
manager
Stopwatch
System.Diagnostics
RemoveSchema
Console
WriteLine
PrintManager
WebClient
System.Net
String
GetTypeFromHandle
RuntimeTypeHandle
GetMethod
MethodInfo
System.Reflection
ServicePointManager
set_SecurityProtocol
SecurityProtocolType
RegisterManager
Assembly
GetMethods
SetManager
TimeSpan
get_Elapsed
get_TotalSeconds
Double
MemberInfo
get_Name
op_Equality
Boolean
ThreadStart
System.Threading
IntPtr
Thread
FindSchema
FlushSchema
MethodBase
Invoke
IncludeSchema
Reverse
TestSchema
ResetSchema
InvokeSchema
GetType
VisitSchema
EnableSchema
op_Inequality
ForgotSchema
BindingFlags
Binder
CultureInfo
System.Globalization
_Registry
InterruptSchema
.cctor
InsertManager
get_ElapsedMilliseconds
ManualResetEvent
ToString
VerifySchema
WaitHandle
WaitOne
CompareSchema
InitSchema
CloneSchema
ResourceManager
System.Resources
m_Request
ReflectSchema
get_ResourceManager
get_Assembly
get_Culture
set_Culture
GetSchema
MapSchema
PublishSchema
Culture
defaultInstance
ResolveSchema
get_Default
SettingsBase
Synchronized
StartSchema
RegisterSchema
Default
m_ae8abf5187e445f2b7db5a68b820b691
m_5d0c6fb6b40f4ed38499b5264a9e1bc0
m_9face62815e94999a2cad106925f4b29
m_002730fd7a9f4c0fa52e58a0941372f7
m_5eb4c09ad55640c191cc87202ac237c2
m_a730dd1f43de45d5b802485600189014
m_421ab51bc1d54a71bb43b4adc65fd75d
m_713ae20023824aaeb84f99f6076e7e89
m_ad54f43f3b5843a1822d71349e3c34eb
m_f7bd47a790e64bf5afb191b63dfe88b4
m_a95e8afbba6c42a4ace06e4f92f4a36b
m_b1b8cc17722648d2bb108fed011c6b8a
m_da40374db0e74c619287ec4748db1ad0
m_9245acdb67284a1ba0c6918962228573
m_3b8516e3b39b402daf29b5dc8ec6666a
m_9b38b03c37a846c495e6859a03f952a2
m_af66ceaa267547c5901727a7c944b6bd
m_076db936b0434cef81f11e4aa77bfe2d
m_ed88721475894281a29fbda64a593766
m_e903feb2ed3c4764a91e193502c2a9e8
m_431d96f085c541b4b516087cc8d16ace
m_15de309edb6d407e896fcaae2dd12a39
m_f878f5ae5c914b7ba79812bb136a9ebc
m_e8bffdc7e1c6433f8a07eaa8da017cc5
m_b22c3f3cd4bc457ba45314ed5869fa44
m_59585258f1ad45c1a1d8908ca75753b5
m_5e1f341194b54c6c9093af4d1859f94a
m_1c98050150f54e07b8d5d7e67687e2ed
m_e5339a06bf1f494ea0101ccda514afd2
m_0623fe77e60444f38718eab32f52323e
m_5363e43013714c29999a6dca3fb434bc
m_7b939b647c1a4bd3a59d887a9ba1f03b
m_7913e502ff2f43f880fe8393ce3a7e94
m_fe25c238d2dd45029da98a8acc96da5a
m_9d3da9d9cd694eeb8d721a6b15f48594
m_333099d236ae4511b5b837f7921c3e69
m_7ec86c32dd4842d0a8f808ea8e040f5e
m_fc1ca82c17c345d79b65b885899ea851
m_84a6c0e0b66a45bba94bbf33ef815989
m_f3d4cf0ab5dc45b3a0f09af5300e2976
m_e7328d0e5b554794beb0dee6b01f8b7d
m_b630ff0c93ad4b86a5b4410bd434c76c
m_430cc9cc6fcf475a8a59338773cdf79c
m_ba301341477d47cd93b1c09888ff5dc8
m_0fd2203686bd4076b3bfdba58e872eb5
m_fdfba3a86963420da6a5337d2aa41335
m_2ab223c5d12940ffb85ddde7dbb3c82d
m_40542b960a154c6d83e3f65eff4ffc4f
m_ce4c6b711ce04f8aa491c6fb0c034da5
m_924f690ce28040d288c6a41813430c1c
m_0d5410d62a104c58852686c060146126
m_9d41f8f4694b4709b6bbb8606e3e6a41
m_935fd8711a1740019bdd121c4210192d
m_44dc45d3e97e473d8df01e2577b0eb90
m_47b9669b770540aa96f03f330e72b35a
m_d4dbfef18a3a451b8e423e196848f00f
m_973807d30c764a49b006c649c816a211
m_4929325572714f79bd2bd2b3689be509
m_1cb726a9c16049f68daa9d91721dcd55
m_e4996c0dde954a99ac355e5c63df519e
m_0f8af7c3e22c40609bcb84f47cc2bd0a
m_4978d2a385dc41de87d3f17c41b022dc
m_a9caadcde212442a8caeddaa0f684c49
m_43b59681a44f477f85d6698c21fc876b
m_645ff342f390439a8aa0b22794f05cac
m_0f1ed1f15dbd451ab99e9e9691179097
m_55738b62498f43a1aa73e6564c3e05eb
m_97b12f3f58dc47ca823128d24db0f6ac
m_0852e8e4346a4cc2b376d9b0bf3899fb
m_91e20f5ee38f4fdd823efcc20480e776
m_2d8b2955728d45c88b58fae9134d0069
m_979f4788ba674db08f527f43c98f6bda
m_c113d70b3e0a4092a526121bb47c14a7
m_e2ea44b6ef784281b5b5dbd574450973
m_9509af56b5184135bdfbeeaf7edf55ac
m_d31417973b2f4277bcf691f016f255a1
m_d0e412b6f0e04e89b5a6fc19f0ee04a9
m_45e6a77d821f402494d9a2e07db289dc
m_c6f38df4884c404f8df49b769a3d849c
m_dbbb8222d4174189b9867f27808820cf
m_7face4367f3a4bf9a18e34c4c448e2e5
m_e9fc847b2f844751a3960392323bb284
m_8b62bd7e48ba4f8689fdd68cf87dc753
m_d099ed8340c34ada83772d471647629f
m_c3122641e6c9468a9471de63a2018c06
m_dc0c782cb30343b490d60181b9004183
m_08523a273e9d40cf95181030c5377597
m_23293005dd634b5c9206fec2ebb308ab
m_6b3a3909f73c4fafa051eaf094455642
m_b390266d572440bcb3edc3cce02c946f
m_a5db3d35c92f47cd9a873c461f6f8a5d
m_05715fc3610045a9ac5681e4346663df
m_ef009db0693b4705aeb08242905931ba
m_4244fa9ce618467aa1945a85d485248a
m_2a6b6914b1c645b29a663fc0da320d35
m_7730aeb7fa4542b58d21b0f638c6c6f2
m_938f98fcdaa24dc784d7723582c38ce0
m_031ed4f289034c8b83100eb0a8c08978
m_b6f2c6b0f80d464085d31e1789c07d8e
m_a8aa602a63ae4206b34d08af4868f170
m_f67b982d1b0b431cb11f7496336306bc
m_244f025647c8477fb214b2d9455f96f3
m_ea53b55a1cb64e38964a7778865c8aff
m_5a80d9bcfc8f473fac0989174bf1cdc0
m_c505b5386f284e41b2739efdb940e287
m_47b51d751cac43bdb81f6b629063223e
m_57d9457d7f82405d918ceca911160cdd
m_f947b4ada75d4bd6ad938ad8e0acf37d
m_bc4c37c05f324570a56137d434b8ce26
m_32872a8ff5104bb8a25c85c3dc7e9f3a
m_dffd8b12b26b47db8c645daf744c6857
m_015673a3ac79423994231b80d05f7c31
CalcSchema
x888dfb02af68456d9fbb9877ec764509
RunSchema
SelectSchema
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
WindowsFormsApp41.Properties.Resources.resources
WrapNonExceptionThrows
Bitnami
Copyright Bitnami
$fbe9fc5c-94ff-4168-b59a-3951be648c40
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
RSJLRSJOMSJ
TRRTLRRROSLLRSORLRLOO
[TUUQ[WNUWTURNWOSSOLLRSMLMLLM
Q[[TttU[t[[U[UT
[NTU[T[WRSTSO
!T[[Tt[U[UW[UWTU
tRtRRRUR[TT
#\]\[[utt[[[tU[U
Uu[U[[U"
Psuuyu{u]y
y{wuy`
d[\\\_]]aaaaadddddddddd\]
7777777777777.A@$77
88888888888886%K?58
::::::::::::::,CF*:
}UUUUUUUUUT;K?Sl
UUUUUUUU-EF+t
WWWWWWWWV<M?9
XXZXXX[XXHEF/
yyY<M>
ryIFEQa
|||x<M<1
eddd^]!'"
]]j^j]j]j^j]j^j]nd
HHHHHHHHHHH
H7 .%
H<"""""0,
H@>>>>>>/&
HD1111111,
HDAAAAAAA2'
HHHHHHHHHH,#$
HCAAAAA333+(
HHHHHHH3HH3-
H5H5G5D3H3
338383833
WUT@-~
555PQ^
TWCFz:
P]SUUP\\
G=7^1o
H(**j4
z(:ujG
93%B"-
;'N|i?
.|*;;3
j5JfvH
rrr //
;"1j*c
'4CyX)
n^/`wR
54@Uu5
2e\LLL
?8C]g?!
Lc!PaIv
()+,DBZ#R
O>y2:*
O^o>N2
H6&ei#t?BV
k5`9y-
:8U\\?
:a5kL7
S'CEU5
7_[jw8
7^C_:b
\%@'HH
5PRQ/'(
sb99hx
q~VQNW
V;(UZ`X
npBuy-
8#!cV\
B^aUf|v
]>%51
1cG=j0
uB+djBL~z
AQ]=rv%X
W;,L0Mj
T,p&8&
b.kuY=
~~o;3$
iL>nyo
5 HDb&
J$8["=%
l@c~=j
,:YK]$}
CEMU=F
y(B]Xb
6|u~,X2
a%!7I%
Q5$@eI
Sp!p4gx8
h76n)@
|3SiQp
>x"0 9$Ee
q}j{<1
vR[pJl;2
Fg1AD#E
'd)MBH
V DJj:%
PSRHkP
Dgb&6Z
\`jcU)
.,_3 =a
aRDjPLH
<#s~E}m
P|TAb:S
V]xRVYD
b[fi_(
2Qu9"L
qYMxhQ
nUN7`\
Ch*oBj
Qw:1|R
fLz*]P
/^"!9o
lV[~UuUa^
2P/x7d`
wF+}m[
nvmcZe
d^-Pzt
oI';Te~
m/=wo]n
&6z#Rk
>5^bk\
?X2'1U
={u,4
M-4~-_7
>aO`A6
{oJvw?{
D{mz8}k
v%Ld:w
(*U#))"
S[[;mu
e<Cv0Z}
1@%%`$
t)i)S{W
r<^s\XS'
z?4%QT42
zQC(Hz
5=UY*8
]*7(*j
)RiIL
M;oKh p
<GMb")E
sH`IG[
DGc~&q]
Cq5(IR92
%e1mfA
h'aJpu
IL,VT(
6I:W\b
-D]Xg6
0"KblG
a)6C*P
sq>$P
U H==6
`9rQ
Lr"4;'
"l,:9$
4`kbG$*
1(We
?^5KW
f;5hFO
P=?.>&
Xul;PW3
=fN"t]
<p}wDml
/sl@qW8
,\sTI!
)rlDkDm
6Yg[[9
."v"p<u
_Y;h*(
ojm&hdd2eab4fcc0gcd)gdd#hdd
lfdIc`Ze[WTsZVTs\XWh]ZZ]_\\U_\]O`^_Lb_`Fd`b?eac;fbc8fbc5gcd0iee(ief#kgg
\XV{]XXs^Z[i_[]^a]_Vb_`Qb`aLdbcGgcd@hdf;iff9igf5jgg/khg)khg"mhj
_[Y|`\\ta]^jb_`_c`bWebdRgceNhdfHjehAjfh<lhi9lij6mij/njk(njk"plm
a\Z}b]\uc_`kdac`fbdXhdeSiegOjfhGlhiAmij<mik9okl5okl.plm'qll!rnn
c^^vd`alfccahdfZjfhUkgjOmijHnklBqmm>qmn:rno6soo.sop'tpp!wsr
ebaxgcdnjfhckgi[lhjUmikPokmIplnBqmo>snp;toq7tpq/upq(upq!ytt
hddyjfgnlhjcmik\njlVokmQrnoHsoqCtpq?uqr;vqr5vrs-wrs&xtu!
ieeykghnmikcnjm\olnWqmoQtppJuqrDvqr@wss<xtu6xtu.yuv'yuv!
kgg{mijpokmepln]rnpXtpqRvqsJvrtCwst8zuv'~yz
rnnTzvw#
tss{{xy
qnmN}~y
qmnM}~y
oklM|~y
qno.(M\
LHHX&('$
^Z[:~}}
ono}~{z
dbbK~zz
gffQlih
cab@}zz
_^^Ggdd
ZZ]E||~
p655
pH;;
p-pK
hdd*hdc!ied
~~knji
pfCC
pcpop
ZZ]0nnq
//k+p
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />
</application>
</compatibility>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
</windowsSettings>
</application>
</assembly>
DownloadData
http://renz.co.jp/blog/ConsoleApp3.jpg
ejhQAMGA3QCJcvAhVw.S6jTTLlVmw4YgMJFw1
Hp0iYwt3G
WindowsFormsApp41.Properties.Resources
/ P6pL
,/KPip
/-P?pR
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Bitnami
FileDescription
FileVersion
1.0.0.0
InternalName
ConsoleApp3.exe
LegalCopyright
Copyright Bitnami
LegalTrademarks
OriginalFilename
ConsoleApp3.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Tedy.55000
FireEye Generic.mg.5712d309e210b6fa
CAT-QuickHeal Clean
ALYac Gen:Variant.Tedy.55000
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Tedy.55000
K7GW Clean
Cybereason malicious.9e210b
BitDefenderTheta Gen:NN.ZemsilCO.34084.mm0@a0xIfRf
VirIT Clean
Cyren Clean
Symantec MSIL.Downloader!gen7
ESET-NOD32 a variant of MSIL/GenKryptik.FOSR
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky VHO:Backdoor.MSIL.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Tedy.55000
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Gen:Variant.Tedy.55000 (B)
Ikarus Trojan-Downloader.MSIL.Small
GData Gen:Variant.Tedy.55000
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=87)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Tedy.DD6D8
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MCrypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.