Static | ZeroBOX

PE Compile Time

2053-01-16 15:49:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002f554 0x0002f600 7.94834608694
.rsrc 0x00032000 0x0000063a 0x00000800 3.49970678391
.reloc 0x00034000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000320a0 0x000003b0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00032450 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
RI>,d-O*
|=RwX
sdLuVdX
L^?nIX
N/H9Vt
93$%s`
sdLuVdX
N/H9V'
L^?nIX
9W$i0Gg
sdLuVdX
IDEj^<
{(JV5C
F>y4k{
kX+$_T
CCDJbr=q/
VZ]>OM
I9::Gg
z~L{Jx
r#a?/S
6R2mX-c]
yefXR^<
Mf$?MJ
9g'4XJp
e4!jp'
,wVR3.
n"#<tXJ\zj'
yS^j0,X
P'rU+>
'}@bjb$
NMz,k}
19k/[%/
lsd:Z[Q
Bl41ZR
]4ww#!
o5.i@:
<0Ef!i
tj69fMl
"@6{m6
E-L+!n1v
F}|FWbTnW[
.h:5_V;
]:Ox}?
sxtv@3
h3ev4C
_pd7zE
?B]<p
i`#^[YM7
YVd23L$
['c[7R
$R4%a8
}LZ]On
M)z_et
.[Jmf6ht
o]:Xf#
#}dTC%
z/esn.z
[hR-YM
<j)sF}
+~*|ysR
6|o?{A
U9f282)
DQDKvWR7
s-Wz^}aS|
9aG0-Z
J?c|oA
u>*qVb%AU
fkb+B2[
qtD~)
tDc>[1"
B090X$
Swl-?Qw
Vc}^xF
@}5">r[
gv/9(S7
y9>OLQ
k'BVK<
23-}C2
i2\"/;
)pSy^
UKlN1[
]L 7B1>Y
c@.IaW
6pAn{ZOmA
[oHFvQA
F0Bj%z
jb#[r$
vD4(?h
xOL`[7
)-sRGW%@
5]VT`nq
b?<%lM
9#Lm"a
6`u!pQ
cLx;6]W
](IjO1I
W;G<W<~Ck`>
%10Q*k
Xu%p&q4
}*L[t7?
Ei&)KH
}jkxFh
B.4\\
6C_9B6
pzKV)3
!{.0Fn~
yI5um]
<sfV..i
]@e{ O*F|m
}Tcuh_
>DN?gb
VZOIb+
024=QV
beezxn
lm,=}s
+s~dqO
9FD43J
+@\|83
V<^/pQ
$K@rvu[
}KJ5g:g
}GXw^&
5$!T[M
4L$(4t(
33($flyG
*Pb-uu
1~s@[=
WV[j'0
)0T|_,
n!h]?.
w&=g/*Ed
Nj8dyI
,>z77\
/tJHfP
Kw:$w]
pE|6V;
u[h!%+
R!dKq~4x
1;A-4/H
)piFkh3=8+
o]).&X}
|+n@t=g
1{0=Jd
(G[k]u
=,fOA}
"w!R+*
A t`#$
E;w"cv8[<B
SDx<E=
j>d1I/
:Sn*ogWJx
0r4TD;xx
+o%;6-
rt3S&6
,f4kku
-i}p',+
r[LbV}
ACd@:y
?/jCK|
oSND\.
7uO^$n
hqeFl}%>]
5ED'9T3
eW_08%p
Q-r:L>_
:QkGP?sTU
XT&`<M,
JA8fvw
Q6k3cs
!OXZ(m
T(Pnp'
93#cWF
F_jOqWO
oMx( O
:~F D{
bt:2#?
)L,U%~{
,sH>d/
%\/#xJ
/pboM=
mpi}M~
YAS%_<~
=#Qc.0
s{d51E
6>iQ87}~K1
>&I WB
K_H#o+
~cv;8C
Ef$[Iy[
@U)bv
y;X[_!Hz{x
<;nwV{`
eQ5Mw7
#i}7Qb
S/8 Y-{
T>LCzt
}hhsPQ
#\(IvP
le;n.i
oJJn;/
|Ml/9^5g
:-3o<J
/,n(E'
VY&s)a
>iC,&>
0$yykx
wFjQE8N
5Q4Vw
)UMs_\+
<YMz7[
@r$$e49
l<Vmo*6t
g`cI?t
$?`Pms
%3Ywy0
GS.o(}~h+
13fiJ[n
#2j)7_
F~Y#)V
zRhZ(4
5@Ho&nb:
]U&8G:dQ'.u
*R_e'4L
grWT2{vENJ
)Au8y/
Op bMw
|!w"6BK
@;=o$[
VG|)O
IUJfE=
6j7?!e
xsbnA
togo8;
Pcmk:#
y+o I&u0h
SVFWI|
LLgBx?
S8*F kX
vYycW]
%A<02,
/2\WBi$
nhogv6W
DO5i@G
~il@tf
uT~|8*
Q?A#IC
'o:rij
Ky#u#O
zS.},,
tZX.kK
]n$T;6
yLISL6
}mg/3
ngQE%f
E4Vw6@;
Hq*;qI
{Ic}Hm)/
K0-xM($
`+A61@
(K~#d{
vOoH6
7"3A"Z
EsWBpqx
%vECNx
7:*BOd0
TkJ;jl
{yY!M@N
Oiwj%a
F@$sDy
LD6q U!,
&qKOBIh
Snti'-
LD6q U!,
f`9"k
F@$sDy
3W4\kz
,-Hd~^
RL8.JDk
,YD%h3>f
f:@r`n
[0P)Q+bg`
<eB21L
=t~BCbP
fACqMM
[ti9sb
+h$i2I:3
KjiG]6|p
W`TuIw
~AUMQ
DYFM&Z
EJ}ix
K'jqT3
EJ}ix
v4.0.30319
#Strings
<byte2>5__10
<bid>5__10
<>s__10
<>s__20
<ReadTicks>d__0
<offer>5__11
<>s__11
<>s__21
<br>5__1
<ReadTicks>d__1
IEnumerable`1
IEquatable`1
IEnumerator`1
<>m__Finally1
<volume>5__12
<>s__12
<>s__22
ReadUInt32
<incrementSize>5__2
<priceIncrement>5__2
<ReadMinutes>d__2
<>s__13
<>s__23
<price>5__3
<open>5__3
<recordCount>5__3
<>s__14
<>s__24
ReadUInt64
ReadInt64
<price>5__4
<high>5__4
<timeTicks>5__4
<>s__15
<byte1>5__5
<time>5__5
<low>5__5
<>s__16
<byte2>5__6
<volume>5__6
<close>5__6
<>s__17
<volume>5__7
<i>5__7
<spreadFlags>5__7
<x>5__18
<>s__18
<time>5__8
<mask>5__8
<bidOffset>5__8
<>s__19
<byte1>5__9
<askOffset>5__9
<>s__9
<Module>
<PrivateImplementationDetails>
System.IO
mscorlib
get_DataBasePracticalJob
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentManagedThreadId
<>l__initialThreadId
DateTimeKind
RootNamespace
set_Mode
CipherMode
get_BigEndianUnicode
strange
IEnumerable
IDisposable
ReadDouble
RuntimeTypeHandle
GetTypeFromHandle
AssemblyTitle
AssemblyName
DateTime
Volume
volume
ValueType
GetType
System.Core
get_Culture
set_Culture
resourceCulture
IsPublicRelease
IsPrerelease
System.IDisposable.Dispose
StrReverse
EditorBrowsableState
<>1__state
AssemblyMetadataAttribute
EmbeddedAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
ExcludeFromCodeCoverageAttribute
AttributeUsageAttribute
DebuggableAttribute
EditorBrowsableAttribute
AssemblyTitleAttribute
IteratorStateMachineAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyInformationalVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
RefSafetyRulesAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
IsReadOnlyAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
NCDMinute
ReadByte
NTDFileReader.exe
MidpointRounding
Encoding
System.Runtime.Versioning
ReadBigEndianULong
ReadBigEndianLong
ComputeHash
get_Length
NCDTick
NTDTick
TransformFinalBlock
Decimal
System.ComponentModel
get_BaseStream
<>3__stream
program
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
resourceMan
SeekOrigin
AssemblyFileVersion
AssemblyInformationalVersion
AssemblyVersion
AssemblyConfiguration
System.Globalization
System.Reflection
get_Position
NotImplementedException
NotSupportedException
ThrowInvalidOperationException
CultureInfo
TimeStamp
Timestamp
timestamp
InvokeMember
NTDFileReader
BinaryReader
SHA256CryptoServiceProvider
AesCryptoServiceProvider
Binder
get_ResourceManager
TaskManager
System.CodeDom.Compiler
IEnumerator
System.Collections.Generic.IEnumerable<NTDFileReader.NCDMinute>.GetEnumerator
System.Collections.Generic.IEnumerable<NTDFileReader.NCDTick>.GetEnumerator
System.Collections.Generic.IEnumerable<NTDFileReader.NTDTick>.GetEnumerator
System.Collections.IEnumerable.GetEnumerator
.cctor
CreateDecryptor
System.Diagnostics
AddSeconds
System.Runtime.CompilerServices
System.Resources
DebuggingModes
NTDFileReader.Properties
GetExportedTypes
ReadMinutes
AddMinutes
GetBytes
BindingFlags
Strings
System.Diagnostics.CodeAnalysis
Microsoft.CodeAnalysis
ReadTicks
Equals
DoubleExtensions
BinaryReaderExtensions
System.Collections
AttributeTargets
numIncrements
GetObject
System.Collections.IEnumerator.Reset
op_Implicit
op_Explicit
ReadBigEndianUInt
ReadBigEndianInt
Increment
increment
Environment
System.Collections.Generic.IEnumerator<NTDFileReader.NCDMinute>.Current
System.Collections.Generic.IEnumerator<NTDFileReader.NCDTick>.Current
System.Collections.Generic.IEnumerator<NTDFileReader.NTDTick>.Current
System.Collections.IEnumerator.Current
System.Collections.Generic.IEnumerator<NTDFileReader.NCDMinute>.get_Current
System.Collections.Generic.IEnumerator<NTDFileReader.NCDTick>.get_Current
System.Collections.Generic.IEnumerator<NTDFileReader.NTDTick>.get_Current
System.Collections.IEnumerator.get_Current
<>2__current
byteCount
AESDecrypt
MoveNext
System.Text
set_Key
System.Security.Cryptography
get_Assembly
ThisAssembly
op_Multiply
op_Equality
op_Inequality
NCDUtility
NTDUtility
NTDFileReader.Properties.Resources.resources
WrapNonExceptionThrows
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
NTDFileReader
ZReads the ticks from NinjaTrader 7 and 8 historical tick and historical minute data files.
RepositoryUrl+https://github.com/bboyle1234/NTDFileReader
AllowMultiple
Inherited
Nerdbank.GitVersioning.Tasks
3.1.91.19327
(NTDFileReader.NCDUtility+<ReadTicks>d__0
*NTDFileReader.NCDUtility+<ReadMinutes>d__2
(NTDFileReader.NTDUtility+<ReadTicks>d__1
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DataBasePracticalJob
EhsMCpLEkrOfkDrpUhiwfxv
Unknown time flag
Unknown price flag
Unknown volume flag.
Unexpected mask value for time
Unexpected mask value for price
Unexpected mask value for volume
rotavitcA.metsyS
CreateInstance
NTDFileReader.Properties.Resources
DataBasePracticalJob
2.0.0.0
NTDFileReader
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Reads the ticks from NinjaTrader 7 and 8 historical tick and historical minute data files.
CompanyName
NTDFileReader
FileDescription
NTDFileReader
FileVersion
InternalName
NTDFileReader.exe
LegalCopyright
OriginalFilename
NTDFileReader.exe
ProductName
NTDFileReader
ProductVersion
Assembly Version
2.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.67290769
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!9AD05DF0B2AC
Malwarebytes Malware.AI.1867732528
VIPRE Clean
Sangfor Infostealer.Msil.Kryptik.Vsdo
K7AntiVirus Trojan ( 005a625e1 )
BitDefender Trojan.GenericKD.67290769
K7GW Trojan ( 005a625e1 )
Cybereason Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/MSIL_Troj.CPN.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik_AGen.AUJ
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/Stealer.3e7be0fb
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Stealer.Agent!8.C2 (CLOUD)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Dropper.Gen
DrWeb Trojan.PackedNET.2052
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
FireEye Generic.mg.9ad05df0b2acb11c
Emsisoft Trojan.GenericKD.67290769 (B)
Ikarus Trojan.MSIL.Crypt
GData Trojan.GenericKD.67290769
Jiangmin Clean
Webroot W32.Trojan.MSIL.Stealer
Avira TR/Dropper.Gen
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D402C691
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
Microsoft Trojan:MSIL/SnakeKeylogger.DAB!MTB
Google Detected
AhnLab-V3 Trojan/Win.Injection.C5434966
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilCO.36250.mm0@aqP9@Ig
ALYac Clean
MAX malware (ai score=81)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CET23
Tencent Msil.Trojan-QQPass.QQRob.Iqil
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet MSIL/Kryptik_AGen.AUJ!tr
AVG Win32:KeyloggerX-gen [Trj]
Avast Win32:KeyloggerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.