Static | ZeroBOX

PE Compile Time

2022-01-18 14:28:54

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00039598 0x00039600 7.90616320299
.reloc 0x0003c000 0x0000000c 0x00000200 0.101910425663
.rsrc 0x0003e000 0x00009620 0x00009800 6.78751344191

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00042630 0x00004b3c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00042630 0x00004b3c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00042630 0x00004b3c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00042630 0x00004b3c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00042630 0x00004b3c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0004716c 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000471b8 0x0000027c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00047434 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.reloc
B.rsrc
%&l("
@_-%~
DBRfhn M
Hvemfj
x= @^`
`EiC'm:B
S[!~/8
w-,y +C
az"D7f
+M$[uZ
WQ6?}r9
Cakmo=M
K?c&K+[s
NCRH|V
Gnri~"Rb?
o<db$%
Bq*/0K
jNd'Zlg
&|m1A"
=1^cSFw
6?aS +\
.j{X,^
{(yh\<U
hyC^1u
v.v]kj
r,1n?t
R1//CN
G]]O",
Grp{JN
,d655<
xEFWX2
zX=/C[1
(TP2/FLE
DT82"b
*xT#byd
l:hq1vr
5ku%yF[
24/5t-
Ir(mC}L
Oe`.X$=
t}<2bc^
6K1a&7
>zA1x;`
2;?sFt~
*BG94~
0-]}#P
(<_z m
,!V8JH
kfzs<S~)6
H`i?3aWlf9
,JlZHI~W
%4oi^b
aP~.DP
n2c{|VVy
d<`.`GF
HmNvhk
3\V-rzX
{nMCdM=
?klMFk
lJ-s'us
t'f,Hz
b_3JY]~
!8Z:?&A
ac0J@y
$#+^q<5
{Z,aY(R&i@1:
QWLB^6-%
~79k{-u
!`^.5
y&&{C*k
LO+^b&
|YJ~d@
'jl)OC
J9)|&%0*
!Dd6r?
x[AO+}gkQj
sU%<cM:Gw
_^_#Jm
yrqFs`
o]a*hH2;
Z<$f|1
M:`]$vI
r[IP C1
r=SKe'
D>CFcI(
m}'A4r
T?T!-Zo
s&w6da
skk{4:D
VT^O,m
t<"wL9{F
{!jnTO
jZ\D',(
,|}ZEZ
-t'OG'@
ySh6N$
xL8,#6
z^_[u?'d
bQB/E]
g[hC1^
XKZvM=a
V?Gy6
yfqMB5<i4
A088hDc
V|s9F|x%'
t^`7-W
JneR{y>S
'8`00\
M%d?A]e
MdA!:
53g>1.AmOY)+
%#~9K=f
:Tc"9U
,Vg8#hqR
;=KGIwZ
e hW8
mdC#Gk?
zFz9Zzb
Pz4^4P
MXg#MX
{|&>oi
]M{Y,A
JP9b^q)
<&5V:[
'!%5c-
RggB&
FeQ2K/
!QX>'Fxc
R`p/jh
Je&*^?c
aga`N;
=lRF}#,
8\YX:
p_hhoC
C? 7._75s
;\fR6:#35
C27e=.0
vfs'1}
:""c"pe
^Q4!Lp
l!(13)2
s//6@N8
IncRdG
'Q/2:C
 J#5Ly
^v$EA<
@MzKalm
cM!m*e
bDo[o}\6v
$KAm|
Q]sXNg3(
m7Kc'f
{5WNTD
zK.2O]5
&c2DSR
kaBj`
puB4A9@
sKLu2e
v?jk,@
IN~:nt=
"|{Ox`
@=k_K
_BsiY}
T=;=e.
1lFtt.
7zW!BfQ
5C>J-S
Os@%4`
@FDwsp
R}h #~
MYb<i
u~@AwGn
t&ZN2i"
]iM|8!q`
{t!8N^
PN-~ttG
P|Qo/r
5:)V*%s
7<uF>W
jwGBj\A
eASOU6
_%&Tm?
|Xt-XMU!.
RAIP*E
c?p}c$K/J
FKU,gd
?>$.Mb
R01F"8
)jkXoi%
d652 Q
(SDj`K!
6Gp>U67
EJ1Y,L
ulbv>v
#_46X&0
qZO5~]&
B5 ~b?C
ywsjR
*E2n%[
E<#Sy+_
}1B$}4
kZ]8`Tgl
cT0A^~
Qna0fd(e
f:`0r#
,{y]=:
dg!_ 7A
15=k;:
BuIkG?
HN|l>{!
7ix`&+J
lE-W#T
WSl6.!
Pww?A5
JSqMw}yt
w8Et!I
L|UcuzZ
"oZ2^0
[>E#9y
XWpoj<
^(<-`W
NCR_06
/}o9PE#j
dSe|\M
to,)IC
U>0'g
\]_[-y1
^w165V
#B>*=K
n/,<7'
]*J3O<"
8X,87R
W_!AY!0
sYuN7N
Xt4'4M
}U,SYI
I6Mg]y
t^CJ*u
,xyU@;
d^*`4,
pcelB,#:
\k"`c(
QyE+UT
8I_P3%
kEgqp)
q1Za$!
P("*]3r
A(gw#)$
$sc\ts
hnDvfT
\$D~"L
2BAc,|:X
RXi2^:
y@WrT;B!
9:"UeL
[9&XuU
[+@~6r)@
Lf:LI.n
hKSv_K
Honc;+.F
`]Gf=#
kzfn1i1l7
Su\n_~*#
Zuy:g4
IGsR,Y
dfYNF`=
cwmw+@
3&`FF-l
cx^6oj
{GrzL
WfYS"PQ
m&vyoMvQ
ZS~m* ps
![*8{U
d4hY$S
Y|k\;H|
xw,%p$
Xt?sZH
d_g43-ZF
s=go^N
H!f9U(
@_h[W
_xlGyNH
t-uGG2f:P
]l"qUn
jIcQJgS+
^wd**}M%
F>WG$1xi5
xrtT4]
X=9{y^
P]@yQl
.C-RH3
~6f3zO
Hm:1 )
2!ij]\
WD+2Ns5
Hv%EmA.
|I_2n[3D
<.aUh1
(^}pr
,mw"+g
a{+;(0bS
Ym$0-#
y!1!ZP
{~@|S8
~7+7Ko
V;7M%]
:0TSqjC
0TG*N ^
7[~<tW
U&Zugts>,
h:PN&P
]{,=,o
)0{B,,
IvWGA^
_sf;{|_
x+P^Q;
#XDf,)T
E\UK9~g
%3(jwc
CFELhe
pKnez'
P'\L>"D
1:,2!F
$n,Z*Wg
Gh/&hX
H'[K}e~
;v=$bu
],Q[Q)KS
(*m$[5I
6|#B<HI
^G3wS
_wx4H+
' bJC<
FNx|NL
o}DO,t
k[Af[~Wc
W>Xq[*
F7}x=
Y|]KH'
v4.0.30319
#Strings
BZCBNZCNBZCMNZCMBCGDS
BZCBNZCNBZCMNZCMBCGDS.exe
mscorlib
System
BZCBNZCNBZCMNZCMBCGDS&&
AppDomain
AsyncCallback
Attribute
BitConverter
Boolean
Buffer
Convert
Delegate
Double
Exception
NumberStyles
System.Globalization
IAsyncResult
IntPtr
CompressionMode
System.IO.Compression
DeflateStream
MemoryStream
System.IO
Stream
ModuleHandle
MulticastDelegate
Object
Assembly
System.Reflection
Binder
BindingFlags
ConstructorInfo
DynamicMethod
System.Reflection.Emit
ILGenerator
OpCode
OpCodes
FieldInfo
MemberInfo
MethodBase
MethodInfo
Module
ParameterInfo
ResolveEventArgs
ResolveEventHandler
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
CompilerGeneratedAttribute
RuntimeCompatibilityAttribute
RuntimeMethodHandle
RuntimeTypeHandle
DESCryptoServiceProvider
System.Security.Cryptography
ICryptoTransform
SymmetricAlgorithm
Single
STAThreadAttribute
String
Encoding
System.Text
Monitor
System.Threading
UInt16
UIntPtr
ValueType
<Module>
caef35a5024727fdd85953be8c05e4431
AssemblyInfoAttribute
cf8f758b265c34f98371544fadb29ece9
c59a25f821a63189c7a63822b5816d955
c3764e3a512bfb7284a9d7d3dae06ed66
c53a26616e74b452f90fcc58e8d24b952
c7a8a44bb7b1deb5f954466b297e86a99
c0411340b33aa45bbb34b786f1b3aa1f4
ca3db5c162c6faa89f055c978f3f649d3
c8b6a80ee69742fda602bf485c03dc123
cfb8712f8058bc023c1ca18a2312d80dd
c0383d70af1d14aeb0bafb0e424487530
ced64b8c4656fd899e66f4f25d3db014d
c8ef3706ea4f3a0275829ba986652ffdf
c6c74cef8d64e35365f80e2eae866e328
caef44a26c39c00d89e782b76645d3775
cb751f94dd38575d9c96e76d4dba53ddc
c703249169a956f6a4920df58effd2062
c2609eb82254f8866708ca680f4161e55
cbeaeaf1909a3d8d9ca7b734aa3ba2e83
c1dfbdead7a0d5f726424af0f1e8c0d82
c0191917e22d342a9b8eccd6a45a4468d
c02803e97fab6b4d468bf142f3010aff7
c04e2decae7a7d176d575f8b07fe3593f
c07a76587ccba06ca924d4792f7d54f00
c097c9c636cb8907a133badd83fd363e5
c15c8e5537c3ea5d532a1e0d345af86d4
c18b0f1f7da0ac71e56f99c2ab2a0f5ce
c195ae96a08cd07062133a5b57d81b06e
c1ff7870b7b6dff22b7eac86ebbf76e0b
c2542521d2117d33113537961d31af26e
c2c71dce91dcd422754c6baf71e16a160
c2d34ae57ad6ee19d0048d3b88c7750f1
c2dc9a2c2068054dad88c7d44fd66d692
c304c98f0b0b94040e011383f33a4a7b3
c3073ffd24d4da75b74368c4a62a54b81
c32c7b0f61077735641c276614d1d02d5
c3443aad8b47a6cc6dc0a608cefa36b4c
c35aff7d90b65070275b0ce3c75892d0b
c36e77839660c39bcd6c147555253cf97
c3a04810e5ad43dd93b76c06a806adfd4
c3d7e62361eab048e0b76a15d75944280
c3e6b5ea70d4d74d8d848b384eb3b4721
c41d07532407833dbe6b9d3828afe815d
c424288d1ec317bcfd4aca9562291781d
c4cfd0d3d02acccf1f36064340f723ee0
c514d7e72f6839eb2c92ba6f3173f179d
c5441e0df292b506c8eb890f04479b276
c5620ab3fc18e6ea00cdfd0fcfde39360
c587845170a55cb6fc8328ad499291206
c62194b0e6eff2d49d5df8b54cfc750ba
c62d2f06dad087be80a385f216959d5a4
c6b6845a6e0f1a52b6fc8a84ab6d9c078
c6e4ba73b45685af2aaf1399afa32edde
c764d88d10d5dcd332fa318d62b15d373
c774aa5a57cb7c10f22b16e45166cdba0
c781118d5919deec857b0cba9d4a7661b
c78f8730e2fd904ecd7753548bc575a47
c7a1b4eec7efcb9b7f8826a8a775fe73a
c7e36952c2fab507432a5425b9237cae8
c82758f1a54fb64ec5c849dd71dae9a6d
c85163867334996cd33ecbbc392ead5a7
c8ad5c714ad77a1f17090fb3efb3b437c
c8ba95abc3c76ca8e2f978e61bfe6284a
c8c8b3ff3fc617fe717af17c2c4632d2d
c8e02e81ba6e756a8917eb0f25f2af3be
c8f66af10c1bfb232db2b767ba1d0a338
c92cc19a0c2a15c61d01478563923d883
c930a9fb9ac2630de9288b5635e6d4943
c9668a732ca9845640eef4e9df51f19db
c976ea723791a4ecfe67336a80f863495
c9c728e7b5ca73c5b49d148cc61af54ec
c9e16f8a9035d5535beec9fac76a3fc38
caabefb4f84d6242feaf7d86df4be829d
cb7cbe97913bac336a90e897b61cf4575
cbd4aa0e331fc8c13660567e3de03d26e
cbe1cb8ed1a20522c40e885766cc7f075
cc1f8cbb9ffc3c26d3f4097a397e6c43b
ccb949ba21470368e551350a2f6a57296
ccf62fc64938619e728dadc4f790d70a4
cd037fe5f6c84901e1e1cae0339028c8d
cd9ed58f2e2e0022285fbb7df8f35f514
cdc1d0e6bb855d93c017f4e2521beb523
cdc65668ea1497526cabe15b7f54f4a5a
cdee2849b5aa6c7cb475e8bad6c1012c1
ce53e9c193d6b5fa0448cc0b9c22e9638
ce83ca251bf4ee0567d7b904d5a57a95e
cf050c8211bcdde116c145be96261b182
cf43ee601289323c2d1a42b26e15def79
cf508fee92f21438b97448434d161be79
cf84155fe9638cc7a3966431f0672e035
cfbf9159ae3e4dcac6ad0d037bca0b39e
cfda3d70bfdcee662672159205af00df0
cfe56e2e9372e0144be63969470e0e895
.cctor
c2efb8ae3f7eee5b7f281c80161897850
c9a10939ac9dd897e755c5f039c4c5b66
c9697cddc2e290ac350d9a21ba8b51205
c057d25d50c8557f15b9f593b069b3a2e
cf4df033509ba35e45ac2056c6a76880b
ce1252f0df3d35b2e46bfe7d603f7952a
c1d9ca05347fe772e21113ea3f96c80f1
c11f064ef693b2212a8b8f7b08853de58
c8e946ad764709c44ffa4515ac75309ff
cac1314a0ae22bc5136b45b07acc75d58
c72ea620d70b4531da56d1218ca70b666
c4b5c4f9e9704092e183b49a28da188b3
c732d34670b702db24871c5e531120209
c3bdbc9af9db56ebeb21caf28c60981e7
c8c197b290a07860a994b51a8415e0090
cc48d31e58c26cff6b723a72bc6fa80c6
c36460b5553d2498887ae6b8b9bd20536
cbd690ad66b64d85b8baab2a48719c015
ca55939dff900546be1ff57e24e9afc3d
c6481478dc4a3dda9b85fbc073922eb6c
c41c4f0675852290c297692969cc261aa
cfcb36abd980f17e54cefa1025ef8db0a
c2317c6b5f2b6810c6dd31787a79c08e2
c2b7785a17a85fafba2eb389df972823e
cee647084f6340fe25e88cc6e73d85b50
c466c721a547052f8b9262d19db235abe
c05719c5eb9733a2bd80eaaa3b0354bb8
Invoke
BeginInvoke
callback
object
EndInvoke
result
ca0b82d5c8ccbca72b8f9011f4daa0970
c91f5be9c47106e6519ed022cb4bf39d1
c74c12a01b55b4060f51a80fbfcc94bab
c2b2d7e0730b5676b4e47f37e39381fda
cc9b5b4120232c7a7507cd5a77573c674
ca753d46dc295ed3dbc990fd0e4964a56
c6d8bf298b09758ccf62f7f97bf2d0355
c42dd465166872c63bf4d0348b5a3b59d
c57b11bc9e6729065ec766bc12a1b1979
cc1676e8c81895d4b4d7656d155662951
c0a55ae1ce86e5454a15da8bfbfd5c7cf
c0bc1ee4e10ed701e860cd967f01e9d1a
c9df40e1e6cec55b4266bea278c24c11a
c8259e5fda2d0a0ccfa2daa297fb9b78c
c72e26c2337102e7744f911cc90499f5e
c75d9217fe74cd183eab08e7676ea91b7
c47f5d39eb09ed80ff2ba34020dd82e9c
cd84a49edea594cfd56280c208c2dae41
c7b195843384089cd9eee63cccda4a450
cb6c94bedd354dc91cd39fb0902db248e
cc0c8110c9d5f473b8f45614e9773f6ec
cf049444c6df7c77d00ce7215d7c24481
cc4fcf15718acb43d6050b2b39b0fd903
c3c12cd42ddbdfb0e1ed4160c57c0caa0
c301f93298fbeb71ad78a00d808a75a82
c1053c25e1e2fdd9c82340fc78cd97691
c97ef460ed48f9c0669c98755ada83545
c7df5fe5cd0bb10418a64258be75ac415
c9d3651ded06c0ad20a06f00a767d713c
cc452a6519e7196546c3837f18fe6ecde
c370ba23319ae93940141384b50b13233
c847911d76427ebb64d980776482858f1
cc4d76122d1e8e369327a6e53e5b4fc1b
c9654377fe2c71bdd30f64a6ea1d76845
cb064681ce8b2beb24d2980822413aa34
cfef3fc0ab5c621329673a6564cd753a2
c06532a736177eeecee2bfc385f8afd2c
c5a91a1808d4d65f5ff8f45a601c9d039
cd6a474c4e045f3def5ecc222bbf76ea5
c8441edf1820918ea52cdd0f318083df7
cd749ab0c34395d027ba89051654b8a69
cad0940e18ec784a2b84459b7ced1b861
c46694e116b0afa45e684f3859ae48a6f
c5d9d13f4c9d3927e465707469b256336
cb778b455fb65367b1d02ce82d7b90b6b
c779c65f464be31325f35ce7bd6740c51
cc96e2635061636543ff63e1ec5f36ec9
c6e2a5cae34c76d76811f9180074175d4
c1c49397738d78c4fc3d9c745e5ef9dcc
ca617556815a55470f4a66944a207f9bb
c9b6ff30075151f4c96b0a84b9e1c3490
c866ba5f6739af400a458aa6ee763c624
c765f65bda2fd7d3e41e6326401e35324
get_c9f879ee1a8f349a6397a317b33bef0e0
c724cc2036279752189d79500419e651c
c8f385e7a122a11ffb4beac2aae7e7c3a
cb218668128d2d622cd0a01e058399a09
cadc312e2545c5cb7f81776fac7965203
cda68cabc48d1eec4d0ee4729bbc28e89
ce7294ea35f852dba074e399f483339f4
c42aa6effe19e02a44912adb9563b948c
c65964b4493ffeea9cedc196d0b6f8d8b
c1e5719a2cf328e49102dfe98600f8968
c9f879ee1a8f349a6397a317b33bef0e0
c336fb374ed9093e40f9c544a03d89db6
cd9507e49067e9e6985aac7cb65caecdf
c9c2f93e978c18b8ccb50e5ddf2b365d1
c6352ff45211cb1ec92d036f7e9716d72
c81dd8a0d43cf397feec4e8d825af6ba0
GetManifestResourceNames
InvokeMember
GetTypeFromHandle
GetType
TransformFinalBlock
Concat
get_ManifestModule
set_Capacity
Substring
get_CurrentDomain
StartsWith
get_InputBlockSize
ReadByte
add_ResourceResolve
ToArray
add_AssemblyResolve
set_Key
GetBytes
GetManifestResourceStream
set_Position
GetExecutingAssembly
CreateDecryptor
GetFields
get_FullName
get_Assembly
IndexOf
set_IV
op_Equality
get_OutputBlockSize
FromBase64String
get_Name
SetValue
Reverse
ResolveType
ResolveMethod
TransformBlock
CreateDelegate
get_MetadataToken
get_Chars
Replace
get_Position
get_Length
get_UTF8
GetString
ToInt32
ToInt64
ToSingle
ToDouble
BlockCopy
get_Unicode
Intern
GetModules
get_ModuleHandle
ResolveTypeHandle
ResolveMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
GetParameters
get_DeclaringType
get_IsValueType
MakeByRefType
get_ParameterType
get_ReturnType
GetILGenerator
Ldarg_0
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
get_IsFamilyOrAssembly
Callvirt
Newobj
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
P+|%je_
WzhXWF
y_.UuMS
~e3-s:
(61Im=
msf_\n
oW_K1H6l
;>eL9v
yl=m6O4
i\ol>}x,
*Tk#[!
Es[9vk.
$K)iXWFY
Bt]Z5",G@#oL
`z2Id*iB(M
Hz;gHX
LZ'jbv
i^@5~|
?P"G J
8}]NHpqT
T!`|(nI
'CU^6n
29Gsil
=c_+@J
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA0
180823201956Z
191123201956Z0
Washington1
Redmond1
Microsoft Corporation1%0#
Microsoft America Operations1&0$
Thales TSS ESN:0DE8-2DC5-3CA91%0#
Microsoft Time-Stamp Service0
Chttp://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl0X
<http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA0
180712201119Z
190726201119Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
r:xcf.
6+0@YHF
E0C1)0'
Microsoft Operations Puerto Rico1
229803+4379500
Ehttp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl0Z
>http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0
A14p,C
/=aJcY
0O)/;GY
microsoft1-0+
$Microsoft Root Certificate Authority0
100831221932Z
200831222932Z0y1
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA0
?http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
`Ge`@N
microsoft1-0+
$Microsoft Root Certificate Authority0
070403125309Z
210403130309Z0w1
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA0
microsoft1-0+
$Microsoft Root Certificate Authority
?http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
8http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0
1Jv1=+r
L&*H$_Z
Washington1
Redmond1
Microsoft Corporation1#0!
Microsoft Code Signing PCA
http://microsoft.com0
Washington1
Redmond1
Microsoft Corporation1!0
Microsoft Time-Stamp PCA
180927000037Z0#
C$oD}u
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
180712200848Z
190726200848Z0t1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Corporation0
E0C1)0'
Microsoft Operations Puerto Rico1
230012+4379650
Chttp://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0
)`'v4$
oIoX]i*
T5fgr|
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20110
110708205909Z
260708210909Z0~1
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 20110
Ihttp://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl0^
Bhttp://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0
3http://www.microsoft.com/pkiops/docs/primarycps.htm0@
*?*kXIc
QEX82q'
WqVNHE
Washington1
Redmond1
Microsoft Corporation1(0&
Microsoft Code Signing PCA 2011
http://microsoft.com0/
20180927000038.726Z0
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:179E-4BB0-82461%0#
Microsoft Time-Stamp service
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
180823202653Z
191123202653Z0
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:179E-4BB0-82461%0#
Microsoft Time-Stamp service0
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
Y1LXi
:ZTd=!
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
100701213655Z
250701214655Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
$`2X`F
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
oK0D$"<
r~akow
Redmond1
Microsoft Corporation1-0+
$Microsoft Ireland Operations Limited1&0$
Thales TSS ESN:179E-4BB0-82461%0#
Microsoft Time-Stamp service
p<$OjD[
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
20180927065439Z
20180928065439Z0w0=
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
"3D9B94A98B-76A8-4810-B1A0-4BE7C4F9C98DA2#
QlpDQk5aQ05CWkNNTlpDTUJDR0RTJQ==
QlpDQk5aQ05CWkNNTlpDTUJDR0RTJA==
PublicKeyToken=
publickeytoken=
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
FileVersion
0.0.0.0
InternalName
BZCBNZCNBZCMNZCMBCGDS.exe
LegalCopyright
OriginalFilename
BZCBNZCNBZCMNZCMBCGDS.exe
ProductVersion
0.0.0.0
Assembly Version
0.0.0.0
Legal_policy_statement
Legal_Policy_Statement
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Lazy.98073
Malwarebytes Malware.AI.2062028253
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Lazy.98073
K7GW Trojan ( 0058d21b1 )
Cybereason malicious.026b08
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.GKM.gen!Eldorado
ESET-NOD32 a variant of MSIL/Kryptik.ADZU
APEX Malicious
Avast Win32:PWSX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanPSW:MSIL/Agensla.6b139963
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Lazy.98073
Rising Clean
Ad-Aware Gen:Variant.Lazy.98073
Emsisoft Gen:Variant.Lazy.98073 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader44.34374
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Generic.mg.2e83d1cc862e6efa
Sophos Mal/Generic-S
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Lazy.98073
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.MSIL.Gen
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Lazy.D17F19
ViRobot Clean
Microsoft Trojan:Win32/Formbook.AT!MTB
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!2E83D1CC862E
MAX malware (ai score=86)
VBA32 Clean
Cylance Unsafe
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CAI22
Tencent Win32.Trojan.Falsesign.Hufz
Yandex Clean
Ikarus Clean
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.ADZU!tr
BitDefenderTheta Gen:NN.ZemsilF.34160.rm2@aG8GC5o
AVG Win32:PWSX-gen [Trj]
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.