Static | ZeroBOX

PE Compile Time

2022-03-09 09:26:50

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000164c 0x00001800 5.45586517693
.rsrc 0x00004000 0x00000a56 0x00000c00 3.68394337226
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00004380 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00004380 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000044e4 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00004542 0x00000324 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000048a2 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
&+W,$+
+.+3+8
v4.0.30319
#Strings
Ialszf.exe
Ialszf
<Module>
mscorlib
Object
System
Settings
Npiir.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
Stopwatch
System.Diagnostics
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
AssemblyProductAttribute
System.Reflection
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyFileVersionAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyCopyrightAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
Npiir.Properties.Resources.resources
ServicePointManager
System.Net
set_SecurityProtocol
SecurityProtocolType
System.Collections
Dequeue
get_Elapsed
TimeSpan
get_TotalSeconds
GetEnumerator
IEnumerator
get_Current
Console
WriteLine
MoveNext
IDisposable
Dispose
Enqueue
Assembly
System.Core
Enumerable
System.Linq
Reverse
IEnumerable`1
System.Collections.Generic
ToArray
WebRequest
Create
GetResponse
WebResponse
GetResponseStream
Stream
System.IO
BinaryReader
ReadBytes
get_FullName
String
op_Equality
AppDomain
get_CurrentDomain
GetAssemblies
GetTypes
Boolean
GetMethod
MethodInfo
MemberInfo
get_Name
InvokeMember
BindingFlags
Binder
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
SettingsBase
Synchronized
KFCLEANER
WrapNonExceptionThrows
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
1.0.0.0
$d96ab8c1-2598-45dc-bca2-1244146c290e
Copyright
2014
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
wwwwwwwwwwwwwwp
DDDDDDDDDDDDDDp
DDDDDDDDDDDDDDp
LLLLLLLLLN
DDDDDDDDDDDDD@
wwwwwwwDDDDDDDGO
DDDDDD
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
_.#~.+B.3B.;
http://www.exataweb.com.br/images/icons/Ialszf.png
Wrxgnpzsmetffidieulcxivl.Izeoauxzuukzk
Fonbilnnojyi
Npiir.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
KFCLEANER
CompanyName
FileDescription
KFCLEANER
FileVersion
1.0.0.0
InternalName
Ialszf.exe
LegalCopyright
Copyright
2014
LegalTrademarks
OriginalFilename
Ialszf.exe
ProductName
KFCLEANER
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.a0d1e6b7a565c9ab
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.51cd80
Baidu Clean
VirIT Clean
Cyren Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Generic/MSIL@AI.92 (RDM.MSIL:6QjqDZqVUg92dsXpMMRjEQ)
Ad-Aware Clean
Emsisoft Trojan-Downloader.Agent (A)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A0D1E6B7A565
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34264.am0@aGAcf3e
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike Clean
No IRMA results available.