Static | ZeroBOX

PE Compile Time

2023-05-30 06:13:53

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00043af4 0x00043c00 7.97927430944
.rsrc 0x00046000 0x0000059e 0x00000600 4.09077782461
.reloc 0x00048000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000460a0 0x00000314 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000463b4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
RI>,d-O*
|=RwX
sdLuVdX
L^?nIX
N/H9Vt
93$%s`
sdLuVdX
\XHL]O
N/H9V'
L^?nIX
sdLuVdX
XbP8ah
IDEj^<
F>y4k{
S~'c2=/
kX+$_T
CCDJbr=q/
VZ]>OM
BJE)^j
vS1.io
I9::Gg
z~L{Jx
Xf.qYf}
aE*d z
r#a?/S
6R2mX-c]
Mf$?MJ
9g'4XJp
e4!jp'
n"#<tXJ\zj'
sgdwo^X
yS^j0,X
P'rU+>
)@bjb$
19k/[%/
U,P8%D
@lsd:Z[Q
Bl41ZR
o5.i@:
<0Ef!i
tj69fMl
"@6{m6
E-L+!n1v
yFWbTnW[
.h:5_V;
]:Ox}?
h3ev4C
GZM.m=
_pd7zE
?B]<p
i`#^[YM7
YVd23L$
['c[7R
$R4%a8
}LZ]On
I|c2e<
M)z_et
[Jmf6ht
z/esn.z
VOM>LK
=Q0 %7
/LRM%c
<j)sF}
^dfV i~
U9f282)
DQDKvWR7
9aG0-Z
J?c|oA
u>*qVb%AU
fkb+B2
qtD~)
tDc>[1"
VSqiZ
Swl-?Qw
'ABV48=
Vc}^xF
@}5">r[
gv/9(S7
y9>OLQ
k'BVK<
31;~iA
23-}C2
)pSy^
UKlN1[
]L 7B1>Y
c@.IaW
6pAn{ZOmA
[oHFvQA
F0Bj%z
jb#[r$
vD4(?h
xOL`[7
)-sRGW%@
5]VT`nq
b?<%lM
9#Lm"a
6`u!pQ
cLx;6]W
](IjO1I
W;G<W<~Ck`>
%10Q*k
Xu%p&q4
}*L[t7?
Ei&)KH
`9B^D&
$Vux?9+`5
<$S='%/
^Qy`n4^C
T~N7xH
,;!hX&
{`4}`N
m{%_v(2_
d!IU7$
r/3xZP
Ww,dyf
9`( 8O
]_Ie]r(E
-{@(mL
h^Yf}-
WA&WY>
1u|l%2
9@E`P
e(oX 6
mh{7nC
_|j5Xq
63I!7L
&oAqz&}K
QM]cGf=-}
Bm$~?g
Pb5"!|
j%^O9{rGj
1H9XCM
W(^CxI`x|
t.?2{d
7=L![s
8!4uS:
k}Q6'Ei
nEZ}.Y
$.{8#9Z<
sHgay<@
CX[y@A
QRqm}M
wx.k^Y
vjSB]6J
Vr#NID,
$Y{&Io
nG'U+^
@WildF@
W{r|{:
%M^CJ.f%
6.AS0X
UcHfEJ
}W&|:%TJc
TQWeQp|
Rr(fHru
WDTNxwF
!o /!g
VekwkX
zbv|^U
"nLRK`
$D2PM.F
NZ)[+@
T@TaPU{
/&"rVwT
9*kkz@H
R}(:`G
1c#J (
Q\6B#H
@!GM!{
4@GrhN
Rjai[:
88z7.~
`G*v]=V
<rVWaA
az</2;
~}xw4{
Xa&w}}
1FI[(&~
_l<B<*,
'ZpZ`k
{xK[^[
X$-Fzo
A},v5Z
}cv;Ffn#9
4i1x$"5jP
$*0nSb
+[AQ;`
:y]l^
FIO<fl
zd`tc|
(hu8k(
!Un#&h
be$=kT^>
)VuZxhw
AO"=LUKyN
:q0RR}
DK~N<d]t
]CNN[=+|E
m!Z;4M)
xHa =Kl
cxQK*A
4*NP%5<#
P 3ymn
e14:9^lmu
o2c]88.
+aO#:H7.)
O8!`hB
$$0>Ec
Z%yZRi
=,j8eDo3
jZF&E"
|rOkR4*y
z.kno%N
Ol,^1p
G&Vu3g94U
.NFMg>
, Rb29
M_-=VVx
Zs<]`g
74r"{/
[e"`v
T]b??W
:d7F__
\,yh%#'
IA7$Zt
}6q5kr
E7&5jz
U)1HC9kJ
I;R:/?
fJugI=
{4aL.\
G# T[uB
]#baIC</
)FWp.[
Kqs9i~
6Re.~t
d{U!J%\]
*pqPN{t
$tbmwUs.
vmYjdy;@
ah1@p0
jr{J8;E
Nn{/m%O
7_(<E"
uuv1*N!f
^*8uV5
KU.bC\Im
GUE4.
)2UaR!
pc^S5h
/gp.\40
mnwq%(
#~oJ:v
$c- S=
#N&E9M5
8e](a.
Xu{Zfk
3ltM.F
|JV\db
8[B{>\
xs>0x[
Z||?:m(
%I)#wi
iN=iy}s
XU9CCw
o@2;l,
LMCnHg
$O3{)D-
dBoZIJ0(
kO)wt~9^SE
D*LNpT
Yi=9KQ
bLN?Iy
Wc#)_w\W
UpJK9{
X.D2=D
kB9PGy
hkzs6'
gH&3pV
BG96-i
\8C)%8Y
y83h'LY
\76b!y}
z^B$)p
GG4{>*
AP!Rhg
go:]`l
psa'^M
i5"$nQ1
AKo'A[
8M6e|T)e\
O6-kMa
HK%ws+
g~miNW
!1O@E
"+Mlq&
[9\(~fL
B=t~(!J
llOk3XP
)gqnj_(
5o;oD)
%yCwyfFpGG
Y36!u:
g^y$k1
TM:}D+
>[RLq[
IB1XD&
&Y6q.6dA
NCxny@%k
Tk~bJ-$[
/W8Rb:
kbL%9LE
WO;`G>
5+,_X]
pV$G <
pf{x'V
'gU-vT
<XePo"}
FJkC;
ICl< Bk6
s;u)ny
#EfDphw$@
U=lgK@
eaH/]Mh
KQ,8aG]1T
``@mb`
gpA9kZ
|vkn]A
1#'j#n
+ar5#,
s.wi*R]
CNA"23
N+tn8@@|z'
O^aNYo
](pj]&
K_dX}E
x/\tVg"X
~XL~z,?
~agwjO
%C X"Xu
|vn rv
]?hyn;k
bNM2iO
vQ(Q2q
9/N7tUIl
SNn8!=
O^CV,x`
io65g6
4Gz{k2
[T@Q!t
/yzuhb
@j;-A~
vE>N<72t
43%r1y7
Wi;4l`
jb2u.3d(
4mE8I=
/L[.[b
&gqxgDe
.YtJ\(
m_~(LV
s)#K5"
HNAHWB'Dm<^9
TqSR(*
IxX1NP^
70a;?f
4Zw@U[z\
+>P@U!B
x4C4Y{;
2`yG!
A3#gC9,
Fcq2TQ"
-roQ!3I4
dA_>V"-
D9$\vIY
byJ5p'h
~16F&[
3:-ucL"
Q=_p*/Fv
0d6.y
OO2#UQed
7gI %T
)]UZ^Q
}sTFWr
6j7?!e
xsbnA
togo8;
Pcmk:#
y+o I&u0h
SVFWI|
LLgBx?
S8*F kX
vYycW]
%A<02,
/2\WBi$
nhogv6W
DO5i@G
~il@tf
uT~|8*
Q?A#IC
'o:rij
Ky#u#O
zS.},,
tZX.kK
]n$T;6
yLISL6
}mg/3
ngQE%f
E4Vw6@;
Hq*;qI
{Ic}Hm)/
K0-xM($
`+A61@
(K~#d{
vOoH6
7"3A"Z
EsWBpqx
%vECNx
7:*BOd0
TkJ;jl
{yY!M@N
Oiwj%a
*Pkn?MUbYc
_'JH#z`6
*Pkn?MUbYc
&qKOBIh
oY0GR`
]G-&-
$~>R[&
iAy,?R
R`"P%wo
XIlWmy
zB5/}s
;9b]tz
>DR.qs
(4?g?8
4b8JS
^Tn=??
)-Q8ZN
_j*x"'
Cs^W`-
xn>GJ42
Sa}|V'
^'M{yV
fT*&AT
M;t^{
c^HApn*H
JB]EZ_
'u4Xc~
#tT6Qp
>!<F[
]4]n*;
~AUMQ
DYFM&Z
EJ}ix
K'jqT3
EJ}ix
v4.0.30319
#Strings
<>9__0_0
<.ctor>b__0_0
<>c__DisplayClass0_0
<>9__1_0
<ToXml>b__1_0
<>c__DisplayClass2_0
<>c__DisplayClass4_0
<>c__DisplayClass5_0
<TryGetMember>b__0
<>p__0
<>9__1_1
<ToXml>b__1_1
<>9__4_1
<TryGetMember>b__4_1
<>9__5_1
<TryGetMember>b__5_1
<.ctor>b__1
<>o__1
<>p__1
IEnumerable`1
CallSite`1
ICollection`1
IEnumerator`1
List`1
<>9__1_2
<ToXml>b__1_2
<TryGetMember>b__2
Func`2
KeyValuePair`2
IDictionary`2
<>9__5_3
<TryGetMember>b__5_3
<>o__3
Func`3
Action`3
<>9__5_4
<TryGetMember>b__5_4
Func`4
Func`5
<Module>
mscorlib
get_DataBasePracticalJob
System.Dynamic
ToDynamic
ConvertDynamic
System.Collections.Generic
Microsoft.VisualBasic
System.Collections.Specialized
Append
Replace
IsNullOrWhiteSpace
set_Mode
CipherMode
get_BigEndianUnicode
strange
Invoke
IEnumerable
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Single
get_Name
DynamicCompatableName
get_LocalName
objectName
elementName
get_IsGenericType
get_ReturnType
GetType
System.Core
get_Culture
set_Culture
resourceCulture
Dispose
StrReverse
Create
Aggregate
EditorBrowsableState
CallSite
XAttribute
DynamicAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Value
Remove
CerealBox.exe
Encoding
System.Runtime.Versioning
ToDynamicCompatableString
DeserializeFromString
SerializeToString
ComputeHash
EndsWith
StartsWith
TransformFinalBlock
System.ComponentModel
DynamicXml
FlattenXml
Program
get_Item
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
resourceMan
System.Globalization
System.Reflection
DynamicNameValueCollection
nameValueCollection
DynamicJson
ToJson
CultureInfo
CSharpArgumentInfo
Microsoft.CSharp
System.Xml.Linq
System.Linq
InvokeMember
TryGetMember
SHA256CryptoServiceProvider
AesCryptoServiceProvider
StringBuilder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
GetMemberBinder
DynamicMetaObjectBinder
ConvertBinder
binder
get_ResourceManager
TaskManager
AttributeMarker
System.CodeDom.Compiler
XContainer
TypeSerializer
JsonSerializer
IEnumerator
GetEnumerator
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
CerealBox.Properties
GetExportedTypes
Attributes
GetBytes
get_Values
BindingFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
Strings
DynamicExtensions
XNameExtensions
StringExtensions
XElementExtensions
System.Text.RegularExpressions
System.Collections
RegexOptions
JsonArrayObjects
ConvertAttributesToElements
get_Keys
get_AllKeys
ElementAt
Concat
Format
DynamicObject
JsonObject
jsonObject
GetObject
Select
Distinct
Target
result
XElement
xElement
get_Current
current
get_Count
AESDecrypt
TryConvert
ToList
MoveNext
ServiceStack.Text
System.Text
CerealBox
ToArray
get_IsArray
get_Key
set_Key
System.Security.Cryptography
get_Assembly
DynamicDictionary
ToDictionary
dictionary
op_Equality
op_Inequality
CerealBox.Properties.Resources.resources
WrapNonExceptionThrows
CerealBox
Copyright
2013
$90f073cb-2f04-41e7-8c8b-d7cecda73380
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8A
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DataBasePracticalJob
EhsMCpLEkrOfkDrpUhiwfxv
<{0}{1}>
Append
<{0}>{1}</{0}>
</{0}>
{{"{0}":
"{0}":
"{0}":[
ToJson
"{0}":{1}
_Attribute
{0}="{1}"
rotavitcA.metsyS
ecnatsnIetaerC
(?<=.)-(?=.)
CerealBox.Properties.Resources
DataBasePracticalJob
_Attribute
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
CerealBox
FileVersion
InternalName
CerealBox.exe
LegalCopyright
Copyright
2013
LegalTrademarks
OriginalFilename
CerealBox.exe
ProductName
CerealBox
ProductVersion
Assembly Version
1.2.7.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.1867732528
VIPRE Clean
Sangfor Trojan.Win32.Agent.V9lg
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.ebc677
Baidu Clean
VirIT Clean
Cyren W32/Trojan.JYBZ-1846
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Generik.BNJUVXV
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Agent!8.C2 (C64:YzY0OnGZi5Q4C81F)
Emsisoft Clean
F-Secure Heuristic.HEUR/AGEN.1308654
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
Trapmine malicious.high.ml.score
FireEye Generic.mg.908da2b3f1932cce
Sophos ML/PE-A
Ikarus Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1308654
MAX Clean
Antiy-AVL Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Trojan-Stealer.MailPSW.0WXCGZ@gen
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!908DA2B3F193
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.NEGASTEAL.YXDE4Z
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AIVP!tr
BitDefenderTheta Gen:NN.ZemsilF.36250.rm0@aGSBCbo
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.