Static | ZeroBOX

PE Compile Time

2023-05-30 13:11:45

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00187f30 0x00188000 5.94462482954
.rsrc 0x0018a000 0x00010df4 0x00010e00 3.33940472101
.reloc 0x0019c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0018a130 0x00010828 LANG_NEUTRAL SUBLANG_NEUTRAL dBase III DBT, version number 0, next free block index 40
RT_GROUP_ICON 0x0019a958 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0019a96c 0x000002d4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0019ac40 0x000001b4 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADXAAAAADAASYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAMAAuADAALgAwAC4AMQAAAG4AbwBpAHMAcgBlAFYAIAB5AGwAYgBtAGUAcwBzAEEAAQAIADgAAAAwAC4AMAAuADAALgAxAAAAbgBvAGkAcwByAGUAVgB0AGMAdQBkAG8AcgBQAAEACAA0
v4.0.30319
#Strings
witout
witout.exe
System
mscorlib
System.Windows.Forms
System.Drawing
.resources
WindowsFormsApp53.Properties.Resources.resources
Action
AppDomain
Boolean
GeneratedCodeAttribute
System.CodeDom.Compiler
Component
System.ComponentModel
Container
IComponent
IContainer
Convert
Delegate
DebuggerNonUserCodeAttribute
System.Diagnostics
EventArgs
EventHandler
CultureInfo
System.Globalization
IDisposable
IntPtr
Object
Assembly
System.Reflection
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyCopyrightAttribute
AssemblyDescriptionAttribute
AssemblyFileVersionAttribute
AssemblyProductAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
ResourceManager
System.Resources
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
SuppressIldasmAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
RuntimeTypeHandle
STAThreadAttribute
Single
String
Encoding
System.Text
Thread
System.Threading
Application
AutoScaleMode
ContainerControl
Control
<Module>
Dispose
GetDomain
GetTypes
get_FullName
op_Equality
GetTypeFromHandle
CreateDelegate
DynamicInvoke
set_Text
set_ClientSize
set_Name
add_Load
ResumeLayout
SuspendLayout
set_AutoScaleDimensions
set_AutoScaleMode
get_ASCII
GetString
FromBase64String
get_Assembly
GetObject
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
WrapNonExceptionThrows
$c4a32de3-9a4c-41a9-b1ee-72a788697116
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPAD
Mnijjnsurmkwdkfaiffbrna
Mnijjnsurmkwdkfaiffbrna.Ywmswqmzxglymi
Yyxksrnaglwsfipslrkwc
WindowsFormsApp53.Properties.Resources
Mnijjnsurmkwdkfaiffbrna
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
witout.exe
LegalCopyright
LegalTrademarks
OriginalFilename
witout.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Generic.Malware
MicroWorld-eScan Gen:Variant.MSILHeracles.53274
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!993D95F1880C
Malwarebytes Malware.AI.4167570563
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.MSILHeracles.53274
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Gen:NN.ZemsilF.36250.Mn0@a8MFdMb
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.91 (RDM.MSIL2:sByWiag4lwpnPC/H4g1ChA)
TACHYON Clean
Sophos Generic ML PUA (PUA)
Baidu Clean
F-Secure Heuristic.HEUR/AGEN.1323353
DrWeb Trojan.Inject4.30942
VIPRE Gen:Variant.MSILHeracles.53274
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.th
Trapmine Clean
FireEye Generic.mg.993d95f1880cbd21
Emsisoft Gen:Variant.MSILHeracles.53274 (B)
Ikarus Trojan-Spy.AgentTesla
GData Gen:Variant.MSILHeracles.53274
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1323353
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.MSILHeracles.DD01A
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.MSILHeracles.53274
MAX malware (ai score=87)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
AVG TrojanX-gen [Trj]
Cybereason malicious.f220a1
Avast TrojanX-gen [Trj]
No IRMA results available.