Static | ZeroBOX

PE Compile Time

2076-01-29 06:49:19

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00018704 0x00018800 6.19382499459
.rsrc 0x0001c000 0x000094fe 0x00009600 4.69975722862
.reloc 0x00026000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001c130 0x00008ea0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00024fd0 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00024fe4 0x00000330 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00025314 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
C$QbWH
":J$c&
H:Pn.4
74 /ED
Y_cX*j
%-"&s*
X+|D(
_bj2
_bY*
Z_bX
'P,d(
`o$/+
7?Vo+
Y_c
Y_c
Hult+
KDBM(E
&t<5+
v4.0.30319
#Strings
__StaticArrayInitTypeSize=100
__StaticArrayInitTypeSize=10
<>9__0_10
<MSValue1>b__0_10
<>p__10
get_MSValue10
set_MSValue10
MSObject10
__StaticArrayInitTypeSize=20
<>p__20
MSValue20
MSObject20
__StaticArrayInitTypeSize=30
<>o__30
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=80
__StaticArrayInitTypeSize=90
<>9__0_0
<MSValue1>b__0_0
<DomainExists>b__0_0
<>c__DisplayClass0_0
<GetWindowsVersion>g__HKLM_GetString|11_0
<>9__1_0
<GetDefaultIPv4Address>b__1_0
<>9__2_0
<MSValue1>b__2_0
<>9__4_0
<MSValue3>b__4_0
<>9__8_0
<ListOfPrograms>b__8_0
<>c__DisplayClass8_0
<>9__9_0
<.ctor>b__9_0
<AvailableLanguages>b__9_0
<.cctor>b__0
<>o__0
<>p__0
MSValue01
<MSValue1>b__11
<>p__11
get_MSValue11
set_MSValue11
MSObject11
<>p__21
MSValue21
MSObject21
MSObject31
<>9__0_1
<DomainExists>b__0_1
<>9__1_1
<GetDefaultIPv4Address>b__1_1
<MSValue1>b__1
<.cctor>b__1
<>p__1
Func`1
Nullable`1
IEnumerable`1
IOrderedEnumerable`1
CallSite`1
ICollection`1
IEnumerator`1
IList`1
ChannelFactory`1
get_MSValue1
set_MSValue1
MSObject1
__StaticArrayInitTypeSize=102
MSValue02
__StaticArrayInitTypeSize=12
<>9__0_12
<MSValue1>b__0_12
<>p__12
get_MSValue12
set_MSValue12
MSObject12
__StaticArrayInitTypeSize=22
<>p__22
MSValue22
__StaticArrayInitTypeSize=32
ConvertFromUtf32
Microsoft.Win32
MSObject32
ToUInt32
ToInt32
__StaticArrayInitTypeSize=42
__StaticArrayInitTypeSize=152
__StaticArrayInitTypeSize=62
__StaticArrayInitTypeSize=72
__StaticArrayInitTypeSize=282
<>9__0_2
<MSValue1>b__0_2
<DomainExists>b__2
<>p__2
Func`2
KeyValuePair`2
Dictionary`2
get_MSValue2
set_MSValue2
<>p__13
get_MSValue13
set_MSValue13
MSObject13
<>p__23
MSValue23
MSObject23
<MSValue1>b__3
<>p__3
Func`3
Action`3
get_MSValue3
set_MSValue3
MSObject3
__StaticArrayInitTypeSize=14
<>p__14
get_MSValue14
set_MSValue14
MSObject14
__StaticArrayInitTypeSize=24
<>p__24
MSValue24
MSObject24
__StaticArrayInitTypeSize=34
__StaticArrayInitTypeSize=144
__StaticArrayInitTypeSize=44
__StaticArrayInitTypeSize=154
__StaticArrayInitTypeSize=54
__StaticArrayInitTypeSize=64
FromBase64
ToInt64
<>9__0_4
<MSValue1>b__0_4
<>p__4
Func`4
get_MSValue4
set_MSValue4
MSObject4
<>p__15
get_MSValue15
set_MSValue15
MSValue25
MSObject25
<MSValue1>b__5
<>p__5
Func`5
get_MSValue5
set_MSValue5
MSObject5
__StaticArrayInitTypeSize=16
<>p__16
get_MSValue16
set_MSValue16
MSObject16
__StaticArrayInitTypeSize=126
__StaticArrayInitTypeSize=26
MSValue26
MSObject26
__StaticArrayInitTypeSize=36
__StaticArrayInitTypeSize=56
__StaticArrayInitTypeSize=66
__StaticArrayInitTypeSize=6
<>9__0_6
<MSValue1>b__0_6
<>o__6
<>p__6
get_MSValue6
set_MSValue6
<>p__17
MSValue17
MSObject17
MSObject27
<MSValue1>b__7
<>p__7
get_MSValue7
set_MSValue7
MSObject7
__StaticArrayInitTypeSize=18
<>p__18
get_MSValue18
set_MSValue18
MSObject18
__StaticArrayInitTypeSize=28
MSObject28
__StaticArrayInitTypeSize=38
__StaticArrayInitTypeSize=48
__StaticArrayInitTypeSize=58
__StaticArrayInitTypeSize=78
__StaticArrayInitTypeSize=98
get_UTF8
<>9__0_8
<MSValue1>b__0_8
<>p__8
get_MSValue8
set_MSValue8
MSObject8
<>p__19
MSValue19
MSObject19
MSObject29
<MSValue1>b__9
<>p__9
get_MSValue9
set_MSValue9
MSObject9
<Module>
<PrivateImplementationDetails>
System.Drawing.Drawing2D
get_ASCII
BCRYPT_INIT_AUTH_MODE_INFO_VERSION
get_JSON
FromJSON
ToJSON
BCRYPT_AUTHENTICATED_CIPHER_MODE_INFO
BCRYPT_OAEP_PADDING_INFO
BCRYPT_PSS_PADDING_INFO
System.IO
BCRYPT_KEY_LENGTHS_STRUCT
value__
cbData
ProtectedData
bEncryptedData
cbAuthData
pbAuthData
mscorlib
DecryptBlob
System.Collections.Generic
SystemMetric
metric
RcHdrFd
get_SessionId
set_MaxBytesPerRead
GetDecoded
BytesToStringConverted
<MSValue10>k__BackingField
<MSValue11>k__BackingField
<MSValue1>k__BackingField
<MSValue12>k__BackingField
<MSValue2>k__BackingField
<MSValue13>k__BackingField
<MSValue3>k__BackingField
<MSValue14>k__BackingField
<MSValue4>k__BackingField
<MSValue15>k__BackingField
<MSValue5>k__BackingField
<MSValue16>k__BackingField
<MSValue6>k__BackingField
<MSValue7>k__BackingField
<MSValue18>k__BackingField
<MSValue8>k__BackingField
<MSValue9>k__BackingField
<irrpre>k__BackingField
i>k__BackingField
<Main>k__BackingField
<Settings>k__BackingField
<Result>k__BackingField
<First>k__BackingField
ReadToEnd
CreateBind
method
NetworkInterface
Replace
IsNullOrWhiteSpace
distance
CreateInstance
cbNonce
pbNonce
source
set_Mode
FileMode
set_SmoothingMode
chainingMode
X509CertificateValidationMode
set_CertificateValidationMode
set_InterpolationMode
set_TransferMode
set_PixelOffsetMode
SecurityMode
SelectSingleNode
XmlNode
xmlNode
get_Unicode
get_BigEndianUnicode
FromImage
set_Message
get_CurrentInputLanguage
AddRange
EndInvoke
BeginInvoke
ReadContextTable
IEnumerable
IDisposable
ToDouble
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
Rectangle
ReadFile
profile
Console
FileScannerRule
hModule
get_Name
procName
fieldName
tableName
GetTempFileName
fileName
get_EnglishName
get_FullName
ItemName
get_UserDomainName
get_UserName
ChromeGetName
GetProcessesByName
get_DisplayName
filename
DateTime
get_CreationTime
ReadLine
AppendLine
get_NewLine
Combine
LocalMachine
DataProtectionScope
dataProtectionScope
OperationContextScope
pszBlobType
ChangeType
ValueType
MessageCredentialType
set_ClientCredentialType
ExpressionType
GetType
GetElementType
get_PropertyType
FileShare
Compare
System.Core
get_irrpre
get_Culture
get_InvariantCulture
GetImageBase
WebResponse
GetResponse
Dispose
Reverse
get_ServiceCertificate
Create
MulticastDelegate
posState
Delete
CallSite
DynamicAttribute
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
DataMemberAttribute
EnumMemberAttribute
CompilationRelaxationsAttribute
DataContractAttribute
ServiceContractAttribute
OperationContractAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ConfusedByAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
ToByte
prevByte
pszAlgMSValue
get_Value
GatherValue
get_HasValue
GetValue
SetValue
ReadContextValue
Remove
Tallith.exe
get_Size
cbSize
_pageSize
set_MaxReceivedMessageSize
ChangeSize
_sqlDataTypeSize
MaxAuthTagSize
set_MaxBufferPoolSize
inSize
outSize
newSize
windowSize
GetVirtualDisplaySize
dictionarySize
Serialize
Deserialize
Resize
SizeOf
get_ItemOf
IndexOf
authTag
get_Png
NetTcpBinding
_dbEncoding
GetEncoding
get_CurrentEncoding
System.Drawing.Imaging
System.Runtime.Versioning
Mapping
ToString
GetString
GetHexString
Substring
System.Drawing
ConvertToULong
scannerArg
Search
GetMd5Hash
ComputeHash
dbPath
profilePath
GetFolderPath
rootPath
get_Width
VirtualScreenWidth
get_Length
dwMinLength
set_MaxJsonLength
set_MaxStringContentLength
get_RowLength
dwMaxLength
set_MaxArrayLength
StartsWith
Tallith
set_MaxDepth
get_Au
AsyncCallback
callback
IsLoopback
PreCheck
AllocHGlobal
FreeHGlobal
get_Local
Marshal
X509CertificateRecipientClientCredential
cbLabel
pbLabel
System.ServiceModel
CreateChannel
IContextChannel
maxLevel
kernel32.dll
user32.dll
System.Xml
MSObjectReaderSql
FileStream
GetResponseStream
inStream
outStream
MemoryStream
stream
Program
get_Item
get_Is64BitOperatingSystem
phAlgorithm
HashAlgorithm
Random
RootNum
rowNum
op_LessThan
IsLittleEndian
TimeSpan
CopyFromScreen
get_PrimaryScreen
get_Main
set_Main
get_FileVersion
dwInfoVersion
GetWindowsVersion
get_Authentication
X509ServiceCertificateAuthentication
get_Location
System.Net.NetworkInformation
UnicastIPAddressInformation
GatewayIPAddressInformation
UnaryOperation
BinaryOperation
pszImplementation
System.Globalization
System.Runtime.Serialization
System.Web.Script.Serialization
System.Reflection
InputLanguageCollection
MatchCollection
UnicastIPAddressInformationCollection
GatewayIPAddressInformationCollection
ManagementObjectCollection
connection
SearchOption
searchOption
CryptographicException
InvalidOperationException
System.ServiceModel.Description
StringComparison
Intern
CompareTo
FileInfo
fileInfo
TimeZoneInfo
CultureInfo
pPaddingInfo
FileSystemInfo
FileVersionInfo
GetVersionInfo
CSharpArgumentInfo
DirectoryInfo
PropertyInfo
IsLocalIp
Bitmap
MessageSecurityOverTcp
Microsoft.CSharp
System.Linq
InvokeMember
GetMember
GetSerialNumber
MessageHeader
CreateHeader
AddressHeader
XmlReader
StreamReader
XmlTextReader
MD5CryptoServiceProvider
OpenAlgorithmProvider
IFormatProvider
provider
StringBuilder
dataFolder
SpecialFolder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
rangeDecoder
Buffer
ManagementObjectSearcher
FileCopier
Handler
IPv4Helper
SystemInfoHelper
CryptoHelper
ToUpper
CurrentUser
GetDelegateForFunctionPointer
adapter
BitConverter
ToLower
JavaScriptSerializer
IEnumerator
ManagementObjectEnumerator
GetEnumerator
.cctor
connector
InvokeConstructor
DeviceMonitor
IntPtr
base64str
set_ReaderQuotas
XmlDictionaryReaderQuotas
Graphics
GetSystemMetrics
System.Diagnostics
Fields
get_Bounds
GetGraphicCards
GetAllNetworkInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
get_ChildNodes
AvailableLanguages
get_InstalledInputLanguages
Matches
EnumerateDirectories
GetDirectories
_masterTableEntries
_tableEntries
GetIPProperties
IPInterfaceProperties
GetProperties
properties
ExpandEnvironmentVariables
EnumerateFiles
GetFiles
profiles
GetSubKeyNames
expires
ListOfProcesses
get_UnicastAddresses
get_GatewayAddresses
numPosStates
StripQuotes
FromMinutes
_fileBytes
ReadAllBytes
ConvertToBytes
GetBytes
GetLogicalDrives
CSharpArgumentInfoFlags
CSharpBinderFlags
dwFlags
configs
get_Settings
OnGetSettings
settings
CallArgs
EventArgs
browserPaths
AddMonths
get_Ticks
get_Credentials
ClientCredentials
Equals
Models
System.ServiceModel.Channels
NumBitLevels
numBitLevels
ListOfPrograms
System.Windows.Forms
domains
Contains
System.Web.Extensions
System.Linq.Expressions
System.Text.RegularExpressions
System.Collections
StringSplitOptions
searchPatterns
patterns
get_Chars
get_OutgoingMessageHeaders
scanners
RuntimeHelpers
GetBrowsers
GetProcessors
FileAccess
success
GetCurrentProcess
GetDefaultIPv4Address
IPAddress
get_Address
GetProcAddress
EndpointAddress
address
System.Net.Sockets
numTotalBits
numPosBits
numPrevBits
Arguments
Supports
get_Exists
DomainExists
get_OperationalStatus
AddDays
arrays
Concat
AppendFormat
ImageFormat
ManagementBaseObject
hObject
ManagementObject
cbKeyObject
pbKeyObject
object
Select
Unprotect
System.Net
Target
GetOffset
offset
get_Height
VirtualScreenHeight
set_RecursionLimit
cbSalt
GetValueOrDefault
get_Result
pcbResult
IAsyncResult
result
System.Management
XmlElement
get_DocumentElement
dwIncrement
SqlStatement
Environment
XmlDocument
NetworkInterfaceComponent
get_Current
Content
IRemoteEndpoint
get_Count
set_MaxNameTableCharCount
MSObjectRoot
StringDecrypt
TrimStart
Convert
WebRequest
XmlNodeList
ToList
get_First
set_First
set_Timeout
set_SendTimeout
set_CloseTimeout
set_ReceiveTimeout
set_OpenTimeout
timeout
cbInput
pbInput
cbOutput
pbOutput
FileExt
StringExt
UserExt
MoveNext
System.Text
ReadAllText
cipherText
get_InnerText
chiperText
ReadFileAsText
cbMacContext
pbMacContext
ReadMasterOfContext
OperationContext
get_Now
GetIndex
startIndex
rowIndex
endMSValuex
startMSValuex
OrderBy
oldArray
InitializeArray
ToArray
FromBase64CharArray
ToCharArray
get_Key
OpenSubKey
chromeKey
stringKey
bMasterKey
hImportKey
RegistryKey
System.Security.Cryptography
GetCallingAssembly
GetExecutingAssembly
get_AddressFamily
SelectMany
BlockCopy
entropy
LoadLibrary
CollectMemory
ChannelFactory
get_Directory
baseDirectory
CreateDirectory
get_SystemDirectory
profilesDirectory
Registry
op_Equality
op_Inequality
System.ServiceModel.Security
System.Security
set_Security
NetTcpSecurity
CreateDnsIdentity
EndpointIdentity
IsNullOrEmpty
GetProperty
pszProperty
Confuser.Core 1.6.0+447341964f
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
Recycle Bio Lab Tool
Tools for control bio tech
BioTech
BioTech Corp. 2022
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4*
MSObject8T
Namespace
ApiLayer
MSValue1
MSValue2*
MSObject9T
Namespace
ApiLayer
MSValue3
MSValue4
MSValue5
MSValue6+
MSObject10T
Namespace
ApiLayer
MSValue7+
MSObject11T
Namespace
ApiLayer+
MSObject12T
Namespace
ApiLayer+
MSObject14T
Namespace
ApiLayer+
MSObject16T
Namespace
ApiLayer+
MSObject17T
Namespace
ApiLayer+
MSObject18T
Namespace
ApiLayer
MSValue8
MSValue9
MSValue10
MSValue11
MSValue12
MSValue13
MSValue14
MSValue15*
MSObject1T
Namespace
ApiLayer
MSValue16
MSValue18*
MSObject3T
Namespace
ApiLayer*
MSObject4T
Namespace
ApiLayer
ContractTUwSystem.ServiceModel.SessionMode, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SessionMode
MSObject5T
Namespace
ApiLayer*
MSObject7T
Namespace
ApiLayer
_CorExeMain
mscoree.dll
0hD'%[=y!T:
,mC5#a;
3\&)Aj3
@^03]D4J]H3
q]+._F
#K!.%M$
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
LM#N$O'P6QGRJTMUR
&%'%)(.-/-10203040506070;:=<@?[Z\Z]Z^Z_Z`ZaZbZcZdZeZfZgZhZiZjZkZlZmZnZoZpZqZrZsZtZuZvZwZxZyZzZ{Z|Z}Z~Z
net.tcp://
localhost
426c3050a8906b1f289a38024fa7d0e5
Authorization
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Tools for control bio tech
CompanyName
BioTech
FileDescription
Recycle Bio Lab Tool
FileVersion
InternalName
Tallith.exe
LegalCopyright
BioTech Corp. 2022
OriginalFilename
Tallith.exe
ProductName
ProductVersion
Assembly Version
32.23.2.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
FireEye Generic.mg.4fda10dd689cf07f
CAT-QuickHeal Clean
ALYac IL:Trojan.MSILZilla.26869
Cylance unsafe
VIPRE IL:Trojan.MSILZilla.26869
Sangfor Spyware.Msil.Redline.V77u
K7AntiVirus Spyware ( 005995c91 )
BitDefender IL:Trojan.MSILZilla.26869
K7GW Spyware ( 005995c91 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/MSIL_Agent.FHJ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Spy.RedLine.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Stealer.4c4a7e71
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILZilla.26869
Rising Spyware.RedLine!8.1309C (CLOUD)
Emsisoft IL:Trojan.MSILZilla.26869 (B)
F-Secure Heuristic.HEUR/AGEN.1351453
DrWeb Trojan.PWS.RedLineNET.6
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.cm
Trapmine suspicious.low.ml.score
CMC Clean
Sophos Mal/Reline-B
Ikarus Trojan.Agent
GData MSIL.Trojan.PSE.107IM90
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1351453
MAX malware (ai score=83)
Antiy-AVL Clean
Gridinsoft Malware.Win32.RedLine.bot
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D68F5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:MSIL/RedLine.EM!MTB
Google Detected
AhnLab-V3 Trojan/Win.JB.R572463
Acronis Clean
McAfee GenericRXVW-VS!4FDA10DD689C
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.MalPack
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDENZ
Tencent Msil.Trojan-Spy.Stealer.Gplw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet MSIL/RedLine.A!tr.spy
BitDefenderTheta Gen:NN.ZemsilF.36196.im0@a8wp8xo
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
No IRMA results available.