Static | ZeroBOX

PE Compile Time

2023-04-18 16:06:06

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00005430 0x00005600 5.61769519567
.rsrc 0x00008000 0x00010ef4 0x00011000 1.63720762385
.reloc 0x0001a000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00008100 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0
RT_GROUP_ICON 0x00018938 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001895c 0x0000039e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00018d0a 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x407428 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Cmairv>k__BackingField
<DiffNodeType>k__BackingField
<DiffType>k__BackingField
<Origin>k__BackingField
<Comparison>k__BackingField
<XPath>k__BackingField
<Description>k__BackingField
<OriginLineNo>k__BackingField
<CompLineNo>k__BackingField
<DiffId>k__BackingField
Descendants
<IgnoreCase>k__BackingField
<IgnoreAttributeOrder>k__BackingField
<IgnoreChildOrder>k__BackingField
<IgnoreAttributes>k__BackingField
<IgnoreNodes>k__BackingField
<IgnoreNamespace>k__BackingField
<IgnorePrefix>k__BackingField
<TrimWhitespace>k__BackingField
<StripWhitespace>k__BackingField
<MatchDescendants>k__BackingField
<MatchValueTypes>k__BackingField
<TwoWayMatch>k__BackingField
<MaxAttributesToDisplay>k__BackingField
<IgnoreTextTypes>k__BackingField
xmlFromDoc
xmlToDoc
fromFilename
toFilename
options
<DiffNodeList>k__BackingField
value__
Removed
Changed
Attribute
XmlString
XmlInteger
XmlDouble
XmlDateTime
<>9__10_0
<>9__10_1
<>9__16_1
matchNodes
parentDiffId
diffNumber
<>9__2
walkToCsv
<>4__this
walkToString
Knrgbtm
Zvcszqul
Lauiylt
Bkztilmq
Cqjnlxf
get_Lfye
get_Bpngi
get_Obyjn
Haunkl
get_Cmairv
set_Cmairv
get_DiffNodeType
set_DiffNodeType
get_DiffType
set_DiffType
get_Origin
set_Origin
get_Comparison
set_Comparison
get_XPath
set_XPath
get_Description
set_Description
get_OriginLineNo
set_OriginLineNo
get_CompLineNo
set_CompLineNo
get_DiffId
set_DiffId
get_IgnoreCase
set_IgnoreCase
get_IgnoreAttributeOrder
set_IgnoreAttributeOrder
get_IgnoreChildOrder
set_IgnoreChildOrder
get_IgnoreAttributes
set_IgnoreAttributes
get_IgnoreNodes
set_IgnoreNodes
get_IgnoreNamespace
set_IgnoreNamespace
get_IgnorePrefix
set_IgnorePrefix
get_TrimWhitespace
set_TrimWhitespace
get_StripWhitespace
set_StripWhitespace
get_MatchDescendants
set_MatchDescendants
get_MatchValueTypes
set_MatchValueTypes
get_TwoWayMatch
set_TwoWayMatch
get_MaxAttributesToDisplay
set_MaxAttributesToDisplay
get_IgnoreTextTypes
set_IgnoreTextTypes
get_DiffNodeList
set_DiffNodeList
CompareDocuments
MatchAttributes
MatchElement
SelectSiblings
SelectAllMatchingSiblings
GetSiblingPosition
CompareNodes
MergeDiffs
CompareText
CompareTextValue
GetXPath
PrettyPrintXPath
EscapeQuotes
ToCSVString
ToString
ToJsonString
<GetXPath>b__20_0
.cctor
<CompareDocuments>b__10_0
<CompareDocuments>b__10_1
<CompareNodes>b__16_1
<CompareNodes>b__0
<CompareNodes>b__2
<ToCSVString>b__0
<ToJsonString>b__0
Reverse
ToArray
FromBase64String
get_ASCII
GetString
GetByteArrayAsync
get_Result
Dispose
GetTypeFromHandle
GetMethod
Invoke
GetExportedTypes
GetMethods
CreateDelegate
DynamicInvoke
Format
get_Message
CreateNavigator
Select
AddRange
get_Count
get_HasAttributes
MoveToFirstAttribute
get_Prefix
op_Inequality
get_NamespaceURI
Concat
get_LineNumber
get_LocalName
get_Value
MoveToNextAttribute
GetAttribute
MoveToFirst
get_NodeType
MoveToNext
get_Item
IsSamePosition
MoveToChild
Enqueue
Dequeue
Contains
get_HasChildren
MoveToFirstChild
GetEnumerator
get_Current
MoveNext
get_Item2
ForEach
get_Item1
Replace
TryParse
op_Equality
Equals
IsNullOrEmpty
Insert
MoveToParent
TrimEnd
get_Chars
Append
get_NewLine
get_Length
AppendLine
OrderBy
safe.exe
Rauvmgww
ywpzgua
fromXml
sourceFromName
sourceToName
fromNav
nodeInfo
aSibling
xmlFromNav
xmlToNav
fromList
mergeList
result
fromValue
toValue
node_sub
diffList
Cmairv
DiffNodeType
DiffType
Origin
Comparison
Description
OriginLineNo
CompLineNo
DiffId
IgnoreCase
IgnoreAttributeOrder
IgnoreChildOrder
IgnoreAttributes
IgnoreNodes
IgnoreNamespace
IgnorePrefix
TrimWhitespace
StripWhitespace
MatchDescendants
MatchValueTypes
TwoWayMatch
MaxAttributesToDisplay
IgnoreTextTypes
DiffNodeList
<Module>
WindowsFormsApp86
Ynnazcho
Vggcgjg
Keeeplb
XmlDiffNode
XmlDiffLib
XmlDiffOptions
XmlDiff
DiffTypes
DiffNodeTypes
IgnoreTextNodeOptions
<>c__DisplayClass16_0
<>c__DisplayClass16_1
<>c__DisplayClass23_0
<>c__DisplayClass25_0
IEnumerable`1
System.Collections.Generic
Enumerable
System.Linq
String
System
Object
Convert
Encoding
System.Text
HttpClient
System.Net.Http
Task`1
System.Threading.Tasks
IDisposable
Assembly
System.Reflection
MethodInfo
MethodBase
Action
Delegate
List`1
HashSet`1
XPathNodeType
System.Xml.XPath
XPathDocument
StringReader
System.IO
XmlException
System.Xml
Exception
XPathNavigator
Func`2
IXmlLineInfo
XPathItem
Queue`1
Tuple`2
Enumerator
Action`1
System.Text.RegularExpressions
DateTime
StringBuilder
Environment
Func`3
IOrderedEnumerable`1
IEnumerator`1
IEnumerator
System.Collections
CompilerGeneratedAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
RuntimeTypeHandle
TextReader
Double
StringComparison
StringSplitOptions
DebuggingModes
mscorlib
System.Core
WrapNonExceptionThrows
$Make Computer faster and more secure
$Make Computer faster and more secure
KDE Softwares
Computer Sentinel
$f098e32b-32ec-4329-b711-b0125039a3b0
1.7.1.28
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
http://95.214.24.37/SystemEnv/uploads/safe_Zocicwhx.bmp
ERROR: An error was encountered in the XML data. Make sure the document is a valid XML document.
Messge: {0}
ERROR: An error occurred while comparing XML documents.
Message: {0}
No matching namespace @
No matching attribute @
Node children not found
No matching node found.
Node not found
Text node does not match |
"ID",Result,XPath,Description,Type,"OriginLineNo","CompLineNo",Origin
"Edit":
"Delete",
"Insert",
"Update",
"XPath": "
"Diff ID": "
"Description": "
"Node Type": "
"Origin Line No":
"Comp Line No":
"DiffNodeList":
"Descendants":
FromXml
$+3?OV]my
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Make Computer faster and more secure
CompanyName
KDE Softwares
FileDescription
Make Computer faster and more secure
FileVersion
1.7.1.28
InternalName
safe.exe
LegalCopyright
LegalTrademarks
OriginalFilename
safe.exe
ProductName
Computer Sentinel
ProductVersion
1.7.1.28
Assembly Version
1.7.1.28
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Seraph.4!c
tehtris Clean
ClamAV Clean
FireEye Trojan.Generic.33485585
CAT-QuickHeal TrojanDownloader.MSIL
McAfee Artemis!F5DEFF8B2ECF
Malwarebytes Trojan.MalPack
VIPRE Trojan.Generic.33485585
Sangfor Downloader.Msil.Seraph.Vu6o
K7AntiVirus Trojan-Downloader ( 005a013e1 )
BitDefender Trojan.Generic.33485585
K7GW Trojan-Downloader ( 005a013e1 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Trojan.Win32.GenusT.EGJX
Cyren W32/MSIL_Kryptik.IDH.gen!Eldorado
Symantec MSIL.Downloader!gen7
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OXE
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Seraph.1bc53b37
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.Generic.33485585
Rising Downloader.Agent!8.B23 (CLOUD)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.rxock
DrWeb Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0DDK23
McAfee-GW-Edition RDN/Generic Downloader.x
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Trojan.Generic.33485585 (B)
SentinelOne Clean
GData Win32.Trojan.Agent.TMF57Z
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Redcap.rxock
MAX malware (ai score=85)
Antiy-AVL Trojan[Downloader]/MSIL.Seraph
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Malware@#29bt6zzzp11ug
Arcabit Trojan.Generic.D1FEF311
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Seraph.gen
Microsoft Trojan:MSIL/Seraph.RB!MTB
Google Detected
AhnLab-V3 Trojan/Win.Mardom.R573400
Acronis Clean
BitDefenderTheta Clean
ALYac Trojan.Generic.33485585
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Downloader.MSIL.gen.rexp
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DDK23
Tencent Msil.Trojan-Downloader.Seraph.Vwhl
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Trojan.Malware.74570710.susgen
Fortinet MSIL/GenKryptik_AGen.UO!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.