Static | ZeroBOX

PE Compile Time

2023-03-07 02:59:21

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0001366c 0x00013800 5.74049689929
.rsrc 0x00016000 0x00001a00 0x00001a00 4.3618062946
.reloc 0x00018000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000165a0 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000165a0 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x000165a0 0x00000ea8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00017448 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00017478 0x000003d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001784c 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
&&+@}~
&&&&&+
&&&&&+
&&&&&+
&&&&&+
&&&&&+
&&&&&+
&&&&&+
&}.1+
v4.0.30319
#Strings
,Fg|
Plbiiyl
Plbiiyl.exe
mscorlib
System.Net.Http
System.Core
System
Microsoft.CSharp
Binder
Microsoft.CSharp.RuntimeBinder
CSharpArgumentInfo
CSharpArgumentInfoFlags
CSharpBinderFlags
Action
Action`1
Action`3
Activator
AggregateException
AppDomain
ArgumentException
ArgumentNullException
ArgumentOutOfRangeException
Attribute
AttributeTargets
AttributeUsageAttribute
Boolean
ConcurrentQueue`1
System.Collections.Concurrent
Dictionary`2
System.Collections.Generic
HashSet`1
ICollection`1
IDictionary`2
IEnumerable`1
IEnumerator`1
IList`1
KeyValuePair`2
List`1
Enumerator
Queue`1
IEnumerable
System.Collections
IEnumerator
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
Console
ConsoleColor
Convert
DateTime
DateTimeOffset
Decimal
Delegate
DebuggerHiddenAttribute
System.Diagnostics
Process
Double
Environment
EventArgs
EventHandler
Exception
Func`1
Func`2
Func`3
Func`5
CultureInfo
System.Globalization
DateTimeStyles
NumberStyles
IDisposable
IFormatProvider
IFormattable
Directory
System.IO
DirectoryInfo
DirectoryNotFoundException
FileAccess
FileMode
FileShare
FileStream
IOException
Stream
StreamWriter
StringReader
StringWriter
TextReader
TextWriter
IObservable`1
IObserver`1
IntPtr
Enumerable
System.Linq
ExpressionType
System.Linq.Expressions
IGrouping`2
IOrderedEnumerable`1
MarshalByRefObject
HttpClient
HttpContent
HttpResponseMessage
NotSupportedException
Nullable`1
Object
ObjectDisposedException
ObsoleteAttribute
ParamArrayAttribute
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
MemberInfo
MethodBase
MethodInfo
ParameterInfo
PropertyInfo
TargetInvocationException
TargetParameterCountException
CallSite
System.Runtime.CompilerServices
CallSiteBinder
CallSite`1
CompilationRelaxationsAttribute
CompilerGeneratedAttribute
DynamicAttribute
ExtensionAttribute
IsVolatile
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
Marshal
CallContext
System.Runtime.Remoting.Messaging
ISerializable
System.Runtime.Serialization
SerializationInfo
StreamingContext
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
UnverifiableCodeAttribute
System.Security
Single
String
StringComparer
StringComparison
Encoding
System.Text
Capture
System.Text.RegularExpressions
CaptureCollection
GroupCollection
StringBuilder
ThreadStaticAttribute
Interlocked
System.Threading
ManualResetEvent
Monitor
Task`1
System.Threading.Tasks
Thread
TimerCallback
WaitHandle
TimeSpan
UInt16
UInt32
UInt64
UnhandledExceptionEventArgs
UnhandledExceptionEventHandler
ValueType
<Module>
LogContext
Serilog.Context
DictionaryValue
Serilog.Events
ScalarValue
SequenceValue
StructureValue
Dispose
.cctor
GetEnumerator
MoveNext
Render
ToString
Equals
GetHashCode
value__
get_Encoding
Verbose
Information
Warning
CreatePropertyValue
Subscribe
get_PermitCrossAppDomainCalls
set_PermitCrossAppDomainCalls
PushProperty
destructureObjects
PushProperties
properties
Suspend
elements
get_Elements
output
format
formatProvider
get_Value
typeTag
get_TypeTag
get_Properties
GetObjectData
get_Current
PermitCrossAppDomainCalls
Elements
TypeTag
Properties
TSource
TScalar
TDestructuringPolicy
TValue
TFilter
TEnricher
get_Length
Append
get_Count
Invoke
CreateInstance
ToArray
get_CurrentThread
get_ManagedThreadId
GetTypeFromHandle
get_FullName
Concat
op_Equality
StartsWith
ContainsKey
TryGetValue
WriteLine
get_Key
Select
get_CurrentDomain
add_DomainUnload
add_ProcessExit
add_UnhandledException
get_IsTerminating
remove_DomainUnload
remove_ProcessExit
remove_UnhandledException
WaitOne
Enqueue
TryDequeue
FromMilliseconds
Change
ToUpperInvariant
ToLowerInvariant
Decrement
Exchange
get_Now
OfType
GetType
get_IsEnum
get_HasValue
GetValueOrDefault
get_UTF8
GetDirectoryName
IsNullOrWhiteSpace
Exists
CreateDirectory
op_GreaterThanOrEqual
get_Date
AddDays
GetFiles
GetFileName
OrderByDescending
FirstOrDefault
GetHRForException
ThenByDescending
ToList
Combine
Delete
get_OrdinalIgnoreCase
Compare
GetDomain
get_ASCII
GetString
FromBase64String
GetAsync
get_Result
get_Content
ReadAsByteArrayAsync
GetMethod
set_Item
Contains
IsNullOrEmpty
get_CurrentDirectory
GetFullPath
GetFileNameWithoutExtension
GetExtension
IndexOf
Substring
Escape
Replace
get_InvariantCulture
get_Success
get_Groups
get_Item
get_Captures
TryParseExact
op_Inequality
Remove
get_Chars
LastIndexOf
IsLetterOrDigit
IsDigit
IsPunctuation
get_IsGenericType
GetGenericTypeDefinition
Create
UnaryOperation
Target
GetMember
get_MachineName
ToDictionary
get_NewLine
Resize
TryParse
MemoryBarrier
OnNext
OnCompleted
get_Out
ResetColor
ReadLine
set_BackgroundColor
set_ForegroundColor
GetCurrentProcess
get_Id
GroupBy
get_Name
IsLetter
GetGenericArguments
get_CanRead
GetGetMethod
get_IsPublic
get_IsStatic
GetIndexParameters
InvokeConstructor
InvokeMember
GetProperties
GetValue
get_InnerException
op_LessThan
FromSeconds
FromMinutes
get_Ticks
FromTicks
LogicalGetData
LogicalSetData
messageTemplate
IUse named arguments with this method to guarantee forwards-compatibility.
AllowMultiple
Inherited
WrapNonExceptionThrows
Installer for SunsetScreen
Skytopia
SunsetScreen
"Copyright
2015 onwards Skytopia
$d7be1707-5868-44de-ba0b-68c8aaccafec
2018.11.15.1038
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
_CorExeMain
mscoree.dll
wwwwwwwxp
"""""/
"""""/
wwwwwwww
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>
"!.-/-21>=HGJIXWZYcbdbebfblkmk
loggerConfiguration
addSink
textWriter
outputTemplate
configureLogger
configureObservers
isEnabled
logEvent
filters
ThreadId
SourceContext
source
propertyName
predicate
bytes)
textFormatter
Exception while emitting periodic batch from {0}: {1}
addScalar
addPolicy
scalarType
destructuringPolicies
Null policy is not allowed.
transformation
maximumDestructuringDepth
Caught exception {0} while emitting to sink {1}.
Negative value provided; file size limit must be non-negative
Failed to create directory {0}: {1}
pathFormat
Zero or negative value provided; retained file count limit must be at least 1
The rolling file has been disposed.
Rolling file target {0} was locked, attempting to open next in sequence (attempt {1})
Error {0} while removing obsolete file {1}
http://192.227.162.28/tu/Tsbbnoxoksq.dat
Gysgbwz.Gfkqes
Gbtmkuawhgzh
addFilter
Null filter is not allowed.
logEventProperty
innerParser
messageTemplate
output
The old-style date specifier {0} is no longer supported, instead please use {Date}
{Date}
The date cannot form part of the directory name
-{Date}
(?<date>\d{
})(?<inc>_[0-9]{3,}){0,1}
yyyyMMdd
addEnricher
enrichers
Null enricher is not allowed.
Exception {0} caught while enriching {1} with {2}.
properties
property
sinkConfiguration
Unable to open file sink for {0}: {1}
enrichmentConfiguration
HasValue
setMinimum
levelSwitch
Property name must not be null or empty.
propertyFactory
MachineName
Property name is not valid.
Message
Timestamp
NewLine
Exception
Required properties not provided for: {0}
Positional property count does not match parameter count: {0}
Unassigned positional value {0} in: {1}
Named property count does not match parameter count: {0}
rawText
observer
At least one observer failed to accept the event
settings
copyToSink
ProcessId
tokens
Message template is malformed: {0}
,"{0}":{{
Renderings
Format
Rendering
Properties
RenderedMessage
MessageTemplate
_typeTag
additionalScalarTypes
additionalDestructuringPolicies
CreatePropertyValue
The property accessor {0} is a non-default indexer
The property accessor {0} threw exception {1}
The property accessor threw an exception:
Maximum destructuring depth reached.
The batching period must be a positive timespan
elements
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Installer for SunsetScreen
CompanyName
Skytopia
FileDescription
Installer for SunsetScreen
FileVersion
2018.11.15.1038
InternalName
Plbiiyl.exe
LegalCopyright
Copyright
2015 onwards Skytopia
LegalTrademarks
OriginalFilename
Plbiiyl.exe
ProductName
SunsetScreen
ProductVersion
2018.11.15.1038
Assembly Version
2018.11.15.1038
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Clean
Elastic malicious (moderate confidence)
MicroWorld-eScan Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Cybereason Clean
Avast Clean
No IRMA results available.