Static | ZeroBOX

PE Compile Time

2022-05-12 07:46:47

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001534 0x00001600 5.41687936207
.rsrc 0x00004000 0x00029c00 0x00029c00 3.58335437546
.reloc 0x0002e000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0002cfbc 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0002d434 0x00000092 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002d4d8 0x000003ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002d8b4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
IEnumerable`1
grace1
Dictionary`2
<Module>
System.IO
mscorlib
System.Collections.Generic
OpenRead
Synchronized
GetMethod
DynamicInvoke
Enumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
set_WindowStyle
ProcessWindowStyle
set_FileName
SecurityProtocolType
GetType
System.Core
ApplicationSettingsBase
Dispose
CreateDelegate
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
grace1.exe
System.Runtime.Versioning
System.ComponentModel
set_SecurityProtocol
MemoryStream
System
System.Configuration
System.Globalization
Action
System.Reflection
ValueCollection
MethodInfo
CultureInfo
ProcessStartInfo
System.Linq
ResourceManager
ServicePointManager
System.CodeDom.Compiler
get_bvgr
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Boszcj.Properties.Resources.resources
DebuggingModes
Boszcj.Properties
get_Values
Settings
Process
set_Arguments
Object
System.Net
WaitForExit
WebClient
get_jcwu
get_jcwv
set_jcwv
set_CreateNoWindow
ToArray
get_Assembly
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.10.0.0
WrapNonExceptionThrows
SandBoxie Manager
sandboxie-plus.com
Sandboxie-Plus
7Copyright (C) 2020-2022 by David Xanatos (xanasoft.com)
$a1099c6c-09a1-49ae-9b8d-22f5b3fb4b59
1.0.10.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
KKLOO308H
D"NOO/[
h2==M(
14!XZZ
VJzzzx
SSSTk5
e188xM
R255Mq
|@H)9}
f!^^^f
2)+Bcj
6:@sj
"XYF8.
ta2kAR
Bk?[A?rm
?RX.P-Wx
{{i\Y <
X]g.h'
J4$d3x
sss,//
x.~:Ax
N ri*S
[2+Oqg
sujqy]
0zr4gg!h"=w]
j\M@+g3
u+WlP%
C!zz{y
344DOO
T*UVVV
.]bS_
+p#TV`
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Shtztjiesghnpwzipbowvrt.Xkbeua
http://62.197.136.3/grace1_Chzjerjr.png
powershell
Cydvkjjbqfuooxbgztrfcpz
-enc UwB0AEEAcgB0AC0AUwBsAEUAZQBQACAALQBzACAAMgAwAA==
Boszcj.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
SandBoxie Manager
CompanyName
sandboxie-plus.com
FileDescription
SandBoxie Manager
FileVersion
1.0.10.0
InternalName
grace1.exe
LegalCopyright
Copyright (C) 2020-2022 by David Xanatos (xanasoft.com)
LegalTrademarks
OriginalFilename
grace1.exe
ProductName
Sandboxie-Plus
ProductVersion
1.0.10.0
Assembly Version
1.0.10.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Generic.mg.d4dea4d4639e4161
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Kryptik.GRB.gen!Eldorado
Symantec Clean
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Small.CUV
APEX Malicious
Paloalto generic.ml
ClamAV Win.Malware.Generictka-9941797-0
Kaspersky HEUR:Trojan-Downloader.MSIL.PsDownload.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Generic ML PUA (PUA)
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R06CH0CEC22
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.VNTE!tr
BitDefenderTheta Gen:NN.ZemsilF.34666.km0@ayFjDF
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_70% (D)
No IRMA results available.