Static | ZeroBOX

PE Compile Time

2040-11-19 09:40:15

PDB Path

C:\PROJ\LOADERS\CS\hmloader\calcinstall\obj\Release\calcinstall.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000b14 0x00000c00 4.91549698747
.rsrc 0x00004000 0x000005bc 0x00000600 4.08025473577
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<Module>
SW_HIDE
System.IO
SW_SHOW
mscorlib
IDisposable
DownloadFile
destFile
set_WindowStyle
ProcessWindowStyle
set_FileName
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
calcinstall.exe
System.Runtime.Versioning
String
GetTempPath
cCalcInstall
calcinstall
kernel32.dll
user32.dll
System
System.Reflection
LoadandRun
set_StartInfo
ProcessStartInfo
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
Process
set_Arguments
set_EnableRaisingEvents
Concat
Object
System.Net
WebClient
GetConsoleWindow
ShowWindow
nCmdShow
WrapNonExceptionThrows
calcinstall
Copyright
2023
$df90f576-2862-4e28-8cd6-4503cce91df9
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\PROJ\LOADERS\CS\hmloader\calcinstall\obj\Release\calcinstall.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Texas1
Houston1
SSL Corp1402
+SSL.com Code Signing Intermediate CA RSA R10
230126090420Z
230608090420Z0D1
London1
SOAX LTD1
SOAX LTD0
<http://cert.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.cer0Q
https://www.ssl.com/repository0
<http://crls.ssl.com/SSLcom-SubCA-CodeSigning-RSA-4096-R1.crl0
=j.=`U#
Texas1
Houston1
SSL Corporation110/
(SSL.com Root Certification Authority RSA0
160624204430Z
310624204430Z0x1
Texas1
Houston1
SSL Corp1402
+SSL.com Code Signing Intermediate CA RSA R10
J:o207d
O51F~t
L='z"?
http://ocsps.ssl.com0
*http://crls.ssl.com/ssl.com-rsa-RootCA.crl0
Texas1
Houston1
SSL Corp1402
+SSL.com Code Signing Intermediate CA RSA R1
20230220154546Z0
GlobalSign nv-sa1*0(
!Globalsign TSA for CodeSign1 - R6
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
220406074538Z
330508074538Z0T1
GlobalSign nv-sa1*0(
!Globalsign TSA for CodeSign1 - R60
>-re+0
&https://www.globalsign.com/repository/0
-http://ocsp.globalsign.com/ca/gstsacasha384g40C
7http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
0http://crl.globalsign.com/ca/gstsacasha384g4.crl0
'v/i)~
.@]|Gt0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
180620000000Z
341210000000Z0[1
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G40
a:c|9#ymt
"http://ocsp2.globalsign.com/rootr606
%http://crl.globalsign.com/root-r6.crl0G
&https://www.globalsign.com/repository/0
$KtZ}r
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
141210000000Z
341210000000Z0L1 0
GlobalSign Root CA - R61
GlobalSign1
GlobalSign0
PmBf/M
'YLv9[
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
GlobalSign nv-sa110/
(GlobalSign Timestamping CA - SHA384 - G4
https://hamstersoft-app-install.s3.eu-west-2.amazonaws.com/calculator/1.8.5/smartcalc_update_1.8.5.exe
smcalc.exe
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
calcinstall
FileVersion
1.0.0.0
InternalName
calcinstall.exe
LegalCopyright
Copyright
2023
LegalTrademarks
OriginalFilename
calcinstall.exe
ProductName
calcinstall
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Adware.Win32.ConvertAd.2!c
tehtris Clean
MicroWorld-eScan IL:Trojan.MSILZilla.26047
ClamAV Clean
FireEye IL:Trojan.MSILZilla.26047
CAT-QuickHeal Clean
ALYac IL:Trojan.MSILZilla.26047
Malwarebytes Generic.Malware/Suspicious
VIPRE IL:Trojan.MSILZilla.26047
Sangfor Clean
CrowdStrike Clean
BitDefender IL:Trojan.MSILZilla.26047
K7GW Trojan ( 005a1d781 )
K7AntiVirus Trojan ( 005a1d781 )
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.BCMB-8741
Symantec ML.Attribute.HighConfidence
Elastic Clean
ESET-NOD32 a variant of MSIL/Agent_AGen.ARN
APEX Clean
Paloalto generic.ml
Cynet Clean
Kaspersky not-a-virus:HEUR:AdWare.MSIL.ConvertAd.gen
Alibaba Clean
NANO-Antivirus Riskware.Win32.AgentAGen.jvlzlk
ViRobot Clean
Rising Adware.ConvertAd!8.BA (CLOUD)
TACHYON Clean
Sophos Generic Reputation PUA (PUA)
F-Secure Clean
DrWeb Trojan.Siggen20.33167
Zillya Adware.ConvertAD.Win32.89548
TrendMicro Clean
McAfee-GW-Edition Artemis!PUP
Trapmine Clean
CMC Clean
Emsisoft IL:Trojan.MSILZilla.26047 (B)
Ikarus Trojan.MSIL.Agent
GData IL:Trojan.MSILZilla.26047
Jiangmin AdWare.MSIL.odke
Webroot Clean
Avira Clean
Antiy-AVL GrayWare[AdWare]/MSIL.ConvertAd
Gridinsoft Clean
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D65BF
SUPERAntiSpyware Clean
ZoneAlarm not-a-virus:HEUR:AdWare.MSIL.ConvertAd.gen
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!881BEF8377F4
MAX malware (ai score=80)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DD323
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet PossibleThreat
BitDefenderTheta Clean
AVG Clean
Avast Clean
No IRMA results available.