Static | ZeroBOX

PE Compile Time

2023-03-29 18:37:34

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00012e24 0x00013000 5.50507304488
.rsrc 0x00016000 0x00002c9e 0x00002e00 5.14094042064
.reloc 0x0001a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00016100 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000186b8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000186dc 0x000003c8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00018ab4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x414e1c _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Tgvcksbjgf
ReceiveDataChanged
SendDataChanged
ConnectedChanged
dataChanged
numberOfClientsChanged
CoilsChanged
HoldingRegistersChanged
NumberOfConnectedClientsChanged
LogDataChanged
tcpClient
ipAddress
transactionIdentifierInternal
transactionIdentifier
protocolIdentifier
length
unitIdentifier
functionCode
startingAddress
quantity
udpFlag
portOut
baudRate
connectTimeout
receiveData
sendData
serialport
parity
stopBits
connected
<NumberOfRetries>k__BackingField
countRetries
stream
dataReceived
receiveActive
readBuffer
bytesToRead
akjjjctualPositionToRead
dateTimeLastRead
timeStamp
request
response
startingAdress
startingAddressRead
startingAddressWrite
quantityRead
quantityWrite
byteCount
exceptionCode
errorCode
receiveCoilValues
receiveRegisterValues
sendRegisterValues
sendCoilValues
portIn
ipAddressIn
server
tcpClientLastRequestList
<NumberOfConnectedClients>k__BackingField
localIPAddress
holdingRegisters
inputRegisters
discreteInputs
numberOfConnections
serialFlag
baudrate
serialPort
udpClient
iPEndPoint
tcpHandler
listenerThread
clientConnectionThread
modbusLogData
<FunctionCode1Disabled>k__BackingField
<FunctionCode2Disabled>k__BackingField
<FunctionCode3Disabled>k__BackingField
<FunctionCode4Disabled>k__BackingField
<FunctionCode5Disabled>k__BackingField
<FunctionCode6Disabled>k__BackingField
<FunctionCode15Disabled>k__BackingField
<FunctionCode16Disabled>k__BackingField
<FunctionCode23Disabled>k__BackingField
<PortChanged>k__BackingField
lockCoils
lockHoldingRegisters
shouldStop
lastReceive
nextSign
lockProcessReceivedData
filename
instance
syncObject
2F1EE281848602F6204161D2571044C5EF136C0D6E609643B9A8074BCA4F1B44
C26B35EE14BF756C17E0A0CABA50B801479044D77439F5657C90D41D00A7A1D3
value__
LowHigh
HighLow
ModbusTCP
ModbusUDP
ModbusRTU
buffer
<Ticks>k__BackingField
<>9__21_0
localArray
modbusServer
ArrayList
Sddodsv
Gxinqn
get_NumberOfRetries
set_NumberOfRetries
add_ReceiveDataChanged
remove_ReceiveDataChanged
add_SendDataChanged
remove_SendDataChanged
add_ConnectedChanged
remove_ConnectedChanged
Connect
ConvertRegistersToFloat
ConvertRegistersToInt
ConvertRegistersToLong
ConvertRegistersToDouble
ConvertFloatToRegisters
ConvertIntToRegisters
ConvertLongToRegisters
ConvertDoubleToRegisters
ConvertRegistersToString
ConvertStringToRegisters
calculateCRC
DataReceivedHandler
DetectValidModbusFrame
ReadDiscreteInputs
ReadCoils
ReadHoldingRegisters
ReadInputRegisters
WriteSingleCoil
WriteSingleRegister
WriteMultipleCoils
WriteMultipleRegisters
ReadWriteMultipleRegisters
Disconnect
Finalize
get_Connected
Available
get_IPAddress
set_IPAddress
get_Port
set_Port
get_UDPFlag
set_UDPFlag
get_UnitIdentifier
set_UnitIdentifier
get_Baudrate
set_Baudrate
get_Parity
set_Parity
get_StopBits
set_StopBits
get_ConnectionTimeout
set_ConnectionTimeout
get_SerialPort
set_SerialPort
get_LogFileFilename
set_LogFileFilename
add_dataChanged
remove_dataChanged
add_numberOfClientsChanged
remove_numberOfClientsChanged
get_NumberOfConnectedClients
set_NumberOfConnectedClients
get_LocalIPAddress
AcceptTcpClientCallback
GetAndCleanNumberOfConnectedClients
ReadCallback
get_FunctionCode1Disabled
set_FunctionCode1Disabled
get_FunctionCode2Disabled
set_FunctionCode2Disabled
get_FunctionCode3Disabled
set_FunctionCode3Disabled
get_FunctionCode4Disabled
set_FunctionCode4Disabled
get_FunctionCode5Disabled
set_FunctionCode5Disabled
get_FunctionCode6Disabled
set_FunctionCode6Disabled
get_FunctionCode15Disabled
set_FunctionCode15Disabled
get_FunctionCode16Disabled
set_FunctionCode16Disabled
get_FunctionCode23Disabled
set_FunctionCode23Disabled
get_PortChanged
set_PortChanged
set_LocalIPAddress
add_CoilsChanged
remove_CoilsChanged
add_HoldingRegistersChanged
remove_HoldingRegistersChanged
add_NumberOfConnectedClientsChanged
remove_NumberOfConnectedClientsChanged
add_LogDataChanged
remove_LogDataChanged
Listen
StopListening
ListenerThread
ProcessReceivedData
CreateAnswer
sendException
CreateLogData
get_NumberOfConnections
get_ModbusLogData
get_SerialFlag
set_SerialFlag
get_Instance
get_Filename
set_Filename
.cctor
Invoke
BeginInvoke
EndInvoke
get_Ticks
set_Ticks
get_TcpClient
get_Buffer
get_NetworkStream
<GetAndCleanNumberOfConnectedClients>b__21_0
get_Item
set_Item
GetExportedTypes
op_Inequality
InvokeMember
ToString
ToLower
FromBase64String
get_ASCII
GetString
GetAsync
get_Result
get_Content
ReadAsByteArrayAsync
Dispose
Combine
CompareExchange
Remove
Concat
get_Now
GetExecutingAssembly
GetName
get_Version
WriteLine
set_PortName
set_BaudRate
set_WriteTimeout
set_ReadTimeout
add_DataReceived
get_IsOpen
get_PortName
BeginConnect
get_AsyncWaitHandle
WaitOne
EndConnect
GetStream
GetBytes
ToSingle
ToInt32
ToInt64
ToDouble
get_Default
get_Length
InitializeArray
remove_DataReceived
DiscardInBuffer
get_BytesToRead
get_Client
get_LocalEndPoint
set_ReceiveTimeout
Receive
ToBoolean
ToInt16
ToByte
get_Status
BeginAcceptTcpClient
EndAcceptTcpClient
get_RemoteEndPoint
BeginRead
GetEnumerator
get_Current
Equals
MoveNext
RemoveAll
get_Count
get_AsyncState
EndRead
BlockCopy
Format
get_Address
ToUInt16
get_ReceiveBufferSize
Tgvcksbjgf.exe
Ggemahn
registers
registerOrder
floatValue
intValue
longValue
doubleValue
offset
stringLength
stringToConvert
numberOfBytes
startByte
sender
values
timeout
asyncResult
client
networkConnectionParameter
message
timestamp
innerException
context
object
method
callback
result
numberOfCoils
register
numberOfRegisters
NumberOfRetries
Connected
IPAddress
UDPFlag
UnitIdentifier
Baudrate
Parity
StopBits
ConnectionTimeout
SerialPort
LogFileFilename
NumberOfConnectedClients
LocalIPAddress
FunctionCode1Disabled
FunctionCode2Disabled
FunctionCode3Disabled
FunctionCode4Disabled
FunctionCode5Disabled
FunctionCode6Disabled
FunctionCode15Disabled
FunctionCode16Disabled
FunctionCode23Disabled
PortChanged
NumberOfConnections
ModbusLogData
SerialFlag
Instance
Filename
TcpClient
Buffer
NetworkStream
<Module>
WindowsFormsApp88
ModbusClient
EasyModbus
ModbusProtocol
NetworkConnectionParameter
TCPHandler
ModbusServer
StoreLogData
SerialPortNotOpenedException
EasyModbus.Exceptions
ConnectionException
FunctionCodeNotSupportedException
QuantityInvalidException
StartingAddressInvalidException
ModbusException
CRCCheckFailedException
<PrivateImplementationDetails>
RegisterOrder
ReceiveDataChangedHandler
SendDataChangedHandler
ConnectedChangedHandler
ProtocolType
DataChanged
NumberOfClientsChanged
Client
CoilsChangedHandler
HoldingRegistersChangedHandler
NumberOfConnectedClientsChangedHandler
LogDataChangedHandler
HoldingRegisters
InputRegisters
DiscreteInputs
__StaticArrayInitTypeSize=256
Object
System
System.Collections
Assembly
System.Reflection
String
Convert
Encoding
System.Text
HttpClient
System.Net.Http
Task`1
System.Threading.Tasks
HttpResponseMessage
HttpContent
IDisposable
System.Net.Sockets
System.IO.Ports
DateTime
Delegate
Interlocked
System.Threading
AssemblyName
Version
Console
SerialDataReceivedEventHandler
IAsyncResult
WaitHandle
Stream
System.IO
ArgumentException
BitConverter
RuntimeHelpers
System.Runtime.CompilerServices
SerialDataReceivedEventArgs
Thread
Exception
Socket
UdpClient
System.Net
IPEndPoint
EndPoint
TimeoutException
Boolean
System.Net.NetworkInformation
PingReply
IPStatus
ValueType
TcpListener
List`1
System.Collections.Generic
AsyncCallback
Monitor
Enumerator
Predicate`1
IsVolatile
ThreadStart
ParameterizedThreadStart
UInt16
StreamWriter
TextWriter
SerializationInfo
System.Runtime.Serialization
StreamingContext
MulticastDelegate
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
CompilerGeneratedAttribute
DebuggerBrowsableAttribute
DefaultMemberAttribute
SecurityAction
System.Security.Permissions
SecurityPermissionAttribute
BindingFlags
Binder
RuntimeFieldHandle
DebuggingModes
DebuggerBrowsableState
mscorlib
WrapNonExceptionThrows
Opera GX Installer
Opera GX Installer
Opera Software
Opera GX Installer
Copyright Opera Software 2023
$17cebf8c-ae43-43e8-b060-feba6f318c86
96.0.4693.104
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
_CorExeMain
mscoree.dll
5#)y>)0
3!'U=(/
5#)4=(/
7$+^>'7
8%+9=(5
:&-j>(1
9&,H=(0
9&,/=(/
;&-y>)0
;&-X>)0
:&,6=(/
;'-i=(/
;'-A=(/
>)0[>)0o>)0u=(/{>)0
=(0}>(0y>)0v>)0r>)0n=(/i<'.'
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Expnqwcy
Vlztkgwikda
http://192.3.215.60/uo7/Cbqta.png
127.0.0.1
EasyModbus library initialized for Modbus-TCP, IPAddress:
, Port:
EasyModbus Client Library Version:
Copyright (c) Stefan Rossmann Engineering Solutions
EasyModbus library initialized for Modbus-RTU, COM-Port:
EasyModbus library initialized for Modbus-TCP
Open Serial port
Open TCP-Socket, IP-Address:
connection timed out
Input Array length invalid - Array langth must be '2'
Input Array length invalid - Array langth must be '4'
Received Serial-Data:
FC2 (Read Discrete Inputs from Master device), StartingAddress:
, Quantity:
SerialPortNotOpenedException Throwed
serial port not opened
ConnectionException Throwed
connection error
ArgumentException Throwed
Starting address must be 0 - 65535; quantity must be 0 - 2000
Send Serial-Data:
Send ModbusTCP-Data:
Receive ModbusTCP-Data:
FunctionCodeNotSupportedException Throwed
Function code not supported by master
StartingAddressInvalidException Throwed
Starting address invalid or starting address + quantity invalid
QuantityInvalidException Throwed
quantity invalid
ModbusException Throwed
error reading
CRCCheckFailedException Throwed
Response CRC check failed
TimeoutException Throwed
No Response from Modbus Slave
FC1 (Read Coils from Master device), StartingAddress:
Send MocbusTCP-Data:
FC3 (Read Holding Registers from Master device), StartingAddress:
Starting address must be 0 - 65535; quantity must be 0 - 125
FC4 (Read Input Registers from Master device), StartingAddress:
FC5 (Write single coil to Master device), StartingAddress:
, Value:
FC6 (Write single register to Master device), StartingAddress:
FC15 (Write multiple coils to Master device), StartingAddress:
, Values:
FC16 (Write multiple Registers to Server device), StartingAddress:
FC23 (Read and Write multiple Registers to Server device), StartingAddress Read:
, Quantity Read:
, startingAddressWrite:
Disconnect
Destructor called - automatically disconnect
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
EasyModbus Server listing for incomming data at Port {0}, local IP {1}
EasyModbus RTU-Server listing for incomming data at Serial Port
Received Data:
Send Data:
dd.MM.yyyy H:mm:ss.ff
' +!,"-#.
-&-+-@-E-J-O
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Opera GX Installer
CompanyName
Opera Software
FileDescription
Opera GX Installer
FileVersion
96.0.4693.104
InternalName
Tgvcksbjgf.exe
LegalCopyright
Copyright Opera Software 2023
LegalTrademarks
OriginalFilename
Tgvcksbjgf.exe
ProductName
Opera GX Installer
ProductVersion
96.0.4693.104
Assembly Version
96.0.4693.104
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Trojan.GenericKD.66159699
ClamAV Clean
FireEye Trojan.GenericKD.66159699
CAT-QuickHeal Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Agent.Vusw
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.66159699
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec Trojan Horse
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AILO
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Agent!8.C2 (CLOUD)
TACHYON Clean
Emsisoft Trojan.GenericKD.66159699 (B)
F-Secure Clean
DrWeb Trojan.DownLoaderNET.586
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Sophos Clean
SentinelOne Clean
GData Trojan.GenericKD.66159699
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1309829
Antiy-AVL Trojan/MSIL.GenKryptik
Gridinsoft Malware.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Generic.D3F18453
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!EEBDD5B69B2F
MAX malware (ai score=81)
VBA32 Downloader.MSIL.gen.rexp
Malwarebytes Spyware.Stealer.MSIL
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.MSIL.Krypt
MaxSecure Clean
Fortinet W32/Malicious_Behavior.SBX
BitDefenderTheta Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.