Static | ZeroBOX

PE Compile Time

2023-05-23 09:16:48

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000139f8 0x00013a00 6.21510256979
.rsrc 0x00016000 0x00004200 0x00004200 6.01154284243
.reloc 0x0001c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000197f4 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000197f4 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_ICON 0x000197f4 0x00000468 LANG_NEUTRAL SUBLANG_DEFAULT GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00019c5c 0x00000030 LANG_NEUTRAL SUBLANG_DEFAULT data
RT_VERSION 0x00019c8c 0x000002e4 LANG_RUSSIAN SUBLANG_RUSSIAN data
RT_MANIFEST 0x00019f70 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
TX+\
jX+n
ir'& <r'&aa
ni0f @
!aefeXE
e ;M7(af Q
be :aP
s kJB"a I
Yfef pO
Z)&X g<
*Xf w'/
>W$Xe
Kd/!X =g
Xee !%
cfe mZ?
Xfe xK%
aefe Z=
hXfe
feef u
fAI1f
afffe
u@$af
=PS*e
Xfefe 7fm
Yef q{
lnR&Xe
'Xf p*
`"Y qW
-w)Xe
>*Xefe
ae Nu/
+&fe Y
}*X CUh
"Xe YwY
Xff D_
B1$Y t
BXfe /(
'hEH
X -,{"Y8
6$XX z
vI"aa
feX h+
#a )mx&Y*
b* \5Q
nNM!afe*
c* BY>
Ye* _c
zX* J
D9 bO.
a* f|$
Ye* 3*
:&f r:
_b`}L
_d}L
?` zu_
?` <u_
?` >u_
?` Nu_
?` :u_
?` Tu_
@@3%>4"
rs%)O\
?ib`"}E@
,U$*=mS~
Gy]0LOi-
fg;4M0g:$z^
b6Yizq
4y"[m
FY*?"a
eNJar
6(F]1c!>
v4.0.30319
#Strings
#Strings
#Schema
<>9__2_0
Ldc_I4_0
Ldloc_0
Stloc_0
Ldarg_0
Ldc_I4_M1
Ldloc_1
Stloc_1
Ldarg_1
IEnumerable`1
Task`1
UserControl1
checkBox1
ReadInt32
ToInt32
WindowsFormsApp72
Ldloc_2
Stloc_2
Ldarg_2
Func`2
UserControl2
Ldloc_3
Stloc_3
Ldarg_3
UserControl3
ReadInt64
Ldc_I4
Conv_I4
UserControl4
Ldc_I4_5
ReadUInt16
get_UTF8
<Module>
GetHINSTANCE
get_ASCII
System.IO
Ldloc_S
Stloc_S
Brfalse_S
Ldarg_S
Bne_Un_S
get_IV
set_IV
GenerateIV
GetData
mscorlib
System.Collections.Generic
get_IsStatic
GetAsync
ReadAsByteArrayAsync
GetProcessById
get_CurrentThread
add_Load
add_CheckedChanged
set_Checked
Interlocked
set_DoubleBuffered
get_Millisecond
set_IsBackground
DynamicMethod
DefineMethod
GetMethod
OpCode
set_AutoScaleMode
CryptoStreamMode
HttpResponseMessage
DynamicInvoke
EndInvoke
BeginInvoke
GetEnvironmentVariable
Enumerable
IDisposable
Hashtable
ReadDouble
get_Handle
RuntimeFieldHandle
ResolveFieldHandle
RuntimeMethodHandle
ResolveMethodHandle
get_ModuleHandle
RuntimeTypeHandle
ResolveTypeHandle
GetFieldFromHandle
GetMethodFromHandle
GetTypeFromHandle
ReadSingle
get_Module
DefineDynamicModule
get_ManifestModule
get_Name
set_Name
get_FullyQualifiedName
get_FullName
get_ProcessName
GetName
AssemblyName
DateTime
get_FieldType
DefineType
CreateType
get_IsValueType
MakeByRefType
get_DeclaringType
get_ReturnType
SetReturnType
get_ParameterType
GetType
System.Core
MethodBase
ButtonBase
Dispose
Reverse
CreateDelegate
MulticastDelegate
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
LegalBlockSizesValue
LegalKeySizesValue
SetValue
add_ResourceResolve
Zhazpwadddz.exe
set_Size
set_BlockSize
get_InputBlockSize
get_OutputBlockSize
set_AutoSize
set_ClientSize
set_KeySize
Deserialize
SizeOf
IndexOf
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
ReadString
GetString
disposing
System.Drawing
BinarySearch
get_Length
Newobj
AsyncCallback
TransformFinalBlock
TransformBlock
DeclareLocal
Marshal
DefineLabel
MarkLabel
System.ComponentModel
kernel32.dll
ContainerControl
UserControl
GetManifestResourceStream
get_BaseStream
CryptoStream
MemoryStream
get_Item
System
SymmetricAlgorithm
Random
get_CanReuseTransform
ICryptoTransform
Boolean
AppDomain
get_CurrentDomain
Application
set_Location
Action
System.Reflection
ControlCollection
set_Position
InvalidOperationException
StringComparison
CopyTo
FieldInfo
MethodInfo
MemberInfo
ParameterInfo
ConstructorInfo
System.Net.Http
System.Linq
InvokeMember
BinaryReader
MethodBuilder
ModuleBuilder
TypeBuilder
LocalBuilder
ParameterBuilder
AssemblyBuilder
Binder
Buffer
ParameterModifier
ResolveEventHandler
IContainer
DefineParameter
GetDelegateForFunctionPointer
BinaryFormatter
set_UseVisualStyleBackColor
GetILGenerator
.cctor
GetConstructor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
System.Diagnostics
GetMethods
System.Runtime.InteropServices
System.Runtime.CompilerServices
OpCodes
DebuggingModes
GetTypes
MethodAttributes
TypeAttributes
ParameterAttributes
NextBytes
KeySizes
BindingFlags
ResolveEventArgs
get_CanTransformMultipleBlocks
System.Threading.Tasks
Equals
get_Controls
System.Windows.Forms
Contains
set_AutoScaleDimensions
System.Collections
get_Chars
GetParameters
SetParameters
AssemblyBuilderAccess
GetCurrentProcess
GetProcAddress
Concat
Format
Object
op_Explicit
System.Reflection.Emit
FirstOrDefault
get_Result
IAsyncResult
HttpClient
Decrement
Increment
Environment
Component
get_Content
HttpContent
ParameterizedThreadStart
Convert
Callvirt
FailFast
SuspendLayout
ResumeLayout
PerformLayout
System.Text
set_Text
Pjlacov
Fjoipfew
Fhfioew
get_Now
set_TabIndex
CheckBox
Duqvivx
ToArray
ToCharArray
get_Key
set_Key
GetPublicKey
GenerateKey
System.Security.Cryptography
get_Assembly
GetExecutingAssembly
get_IsAssembly
BlockCopy
System.Runtime.Serialization.Formatters.Binary
LoadLibrary
Zhazpwadddz
WrapNonExceptionThrows
$63922d20-268d-4c0e-87ef-8a35c66bcb8f
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
180928000000Z
200201235959Z0
Beijing1
Beijing1*0(
!Beijing Qihu Technology Co., Ltd.1
!Beijing Qihu Technology Co., Ltd.0
http://sf.symcb.com/sf.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sf.symcd.com0&
http://sf.symcb.com/sf.crt0
Qp.8U,
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Code Verification Root0
110222192517Z
210222193517Z0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
,N<jPl
3BH8Q:|8
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
100208000000Z
200207235959Z0
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA0
https://www.verisign.com/cps0*
https://www.verisign.com/rpa0
[0Y0W0U
image/gif0!00
#http://logo.verisign.com/vslogo.gif04
#http://crl.verisign.com/pca3-g5.crl04
http://ocsp.verisign.com0
VeriSignMPKI-2-80
VeriSign, Inc.10
VeriSign Trust Network1;09
2Terms of use at https://www.verisign.com/rpa (c)101.0,
%VeriSign Class 3 Code Signing 2010 CA
http://www.360.cn 0
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
191218021701Z0#
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
180928000000Z
200201235959Z0
Beijing1
Beijing1*0(
!Beijing Qihu Technology Co., Ltd.1
!Beijing Qihu Technology Co., Ltd.0
http://sv.symcb.com/sv.crl0a
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0
http://sv.symcd.com0&
http://sv.symcb.com/sv.crt0
M#OS];
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
131210000000Z
231209235959Z0
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA0
+ojr\`
http://s2.symcb.com0
http://www.symauth.com/cps0(
http://www.symauth.com/rpa00
http://s1.symcb.com/pca3-g5.crl0
SymantecPKI-1-5670
Washington1
Redmond1
Microsoft Corporation1)0'
Microsoft Code Verification Root0
110222192517Z
210222193517Z0
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
Dhttp://crl.microsoft.com/pki/crl/products/MicrosoftCodeVerifRoot.crl0
,N<jPl
3BH8Q:|8
Symantec Corporation10
Symantec Trust Network100.
'Symantec Class 3 SHA256 Code Signing CA
http://www.360.cn 0
20191218021702Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G3
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2008 VeriSign, Inc. - For authorized use only1806
/VeriSign Universal Root Certification Authority0
160112000000Z
310111235959Z0w1
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0.
http://s.symcd.com06
%http://s.symcb.com/universal-root.crl0
TimeStamp-2048-30
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA0
171223000000Z
290322235959Z0
Symantec Corporation10
Symantec Trust Network110/
(Symantec SHA256 TimeStamping Signer - G30
?'J3Nm
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0@
/http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
http://ts-ocsp.ws.symantec.com0;
/http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
TimeStamp-2048-60
U){9FN
Symantec Corporation10
Symantec Trust Network1(0&
Symantec SHA256 TimeStamping CA
191218021702Z0/
/1(0&0$0"
MIrXTW
"!&%'%-,.,/,
36un6+WJooCx+eyB76a98O7KzaGn+u2G4Kvv2OWQybyg7fml/6Gx8uKI9emz+vS7yqe4886F4bfv8PC7xbyx7vWF4Lug5ruD6aaL0+WK66a8pMeB+Iat7+Wi/r251+GK6L6xpOeB+I2a/u2Bt5u6++Wcw7TvzeWF6IGg7emK6+mV++Tf67egwNCL/7ug9u+Kt7Wx69+n+aCm+u6QyL25/umKt4Gx68SF+LPvrLHTtOHv3vOX6b+28/m36aCi+vLf37u57+yBzaGn+u2G4KuR5/CI46Cx7buG7bCx8/aJt6G58OuB+Len6w==
DefineDynamicAssembly
TripleDES
Rijndael
System.Security.Cryptography.
, System.Security.Cryptography.Algorithms
Could not load type {0}
Create
MAINICON
VS_VERSION_INFO
StringFileInfo
040904e4
CompanyName
AeroAdmin LLC
FileDescription
AeroAdmin
FileVersion
3.6.1.2
InternalName
AeroAdmin.exe
LegalCopyright
AeroAdmin LLC
LegalTrademarks
AeroAdmin
OriginalFilename
AeroAdmin.exe
ProductName
AeroAdmin
ProductVersion
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
FireEye Generic.mg.24781c1e54454da8
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OXE
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:MSIL/Generic.b8ee478c
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-Downloader.Ader.Cujl
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Trojan.Win32.AMADEY.YXDEWZ
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!24781C1E5445
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 CIL.HeapOverride.Heur
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Downloader.W32.Upatre.jdyn_228553
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36196.hm2@ayh8imaI
AVG FileRepMalware [Misc]
Cybereason malicious.92f28b
Avast FileRepMalware [Misc]
No IRMA results available.