Static | ZeroBOX

PE Compile Time

2022-03-29 07:42:21

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000015d4 0x00001600 5.66921326465
.rsrc 0x00004000 0x0000f7bf 0x0000f800 7.52377477521
.reloc 0x00014000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00008768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00008768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00008768 0x0000a9cb LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0001316f 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000131e9 0x000003b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000135d5 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+&+++0+5+6
v4.0.30319
#Strings
Sexnamz.exe
Sexnamz
<Module>
mscorlib
Object
System
Settings
Vhjcxwn.Properties
ApplicationSettingsBase
System.Configuration
PoweredByAttribute
SmartAssembly.Attributes
Attribute
Stopwatch
System.Diagnostics
ResourceManager
System.Resources
CultureInfo
System.Globalization
.cctor
Culture
Default
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
System.Reflection
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
.resources
Monitor
System.Threading
ConcurrentQueue`1
System.Collections.Concurrent
Enqueue
ToArray
String
GetMethod
MethodInfo
MethodBase
Invoke
IsNullOrWhiteSpace
WebRequest
System.Net
Create
GetResponse
WebResponse
GetResponseStream
Stream
System.IO
CopyTo
MemoryStream
IDisposable
Dispose
AppDomain
get_CurrentDomain
Assembly
ServicePointManager
set_SecurityProtocol
SecurityProtocolType
GetType
get_IsRunning
get_Elapsed
TimeSpan
get_TotalSeconds
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
SettingsBase
Synchronized
WrapNonExceptionThrows
Sky Email Sorter
www.skyextractor.com
+www.skyextractor.com. All rights reserved.
$8503e05e-827c-4bb6-8bd5-25536880bb56
8.0.2.3
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5(
#Powered by SmartAssembly 8.1.0.4892
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
_CorExeMain
mscoree.dll
B0E&L?<
bN@5'a
4iaL3/
PynNu3
hvZrjZ6
T%|t+-9
;;pG 
&x5eaG
=n-?fG
?>Ri,Q
C?<T.~
u;,fM\M
g{jr=
vAI)U[?
Jorze}Xv!3
WqeZv/}
E>).r8
l$4q,L
+3i\Ytmg
Uq|?\[
CY>dG@
KVZp#*X
aC[uXw
dZL1#1
JKFqGP
=t|ht;
"lG}NB
s/.sF7ZBB
~:>^Lm
(c6FwC
y5Q"aD
8>&lM~
rCN^n(
&7]}R9
dIA6UUiaP
!q`+E;
A7b%%N
iGK^a)g
=@/tQ^8
'SNoiY$0
\`xaS#
'.6n:!rY9
4'Gs[M
-]70#)C
Al^P4F
Q~x9 x
E$&>-N
)mIDAT
!jE.s
[O?,h
8Q~,v+;
$`P!hl
SH%O~Pp
ASA)#n6
2^[cZn
0dx(.v
D}V/&S
@9(p\\
tn^i5_3z
X"G#we
fdh,-]^
DQ!XeJ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Qekubmugm
https://rbmimport.com/emmk/Sexnamz_Qesgbdlk.png
Yfttqbjvdolwnheunbrtlkbc.Cekfod
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Sky Email Sorter
CompanyName
www.skyextractor.com
FileDescription
Sky Email Sorter
FileVersion
8.0.2.3
InternalName
Sexnamz.exe
LegalCopyright
www.skyextractor.com. All rights reserved.
LegalTrademarks
OriginalFilename
Sexnamz.exe
ProductName
Sky Email Sorter
ProductVersion
8.0.2.3
Assembly Version
8.0.2.3
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!976F76EBEDA1
Cylance Unsafe
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilCO.34294.em0@aqXg5Qo
VirIT Clean
Cyren W32/MSIL_Troj.BWV.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan-Downloader.MSIL.Agent
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.8d69b3
Avast Win32:DropperX-gen [Drp]
No IRMA results available.