Static | ZeroBOX

PE Compile Time

2023-06-06 15:32:37

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000164c 0x00001800 5.26264225814
.rsrc 0x00004000 0x000005ae 0x00000600 4.03167198397
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x00000324 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043c4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x403644 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
electronics_and_connectors
components
<>9__1_0
<>9__0_0
WindowsFormsApp32.Form2.resources
WindowsFormsApp32.Properties.Resources.resources
Dispose
InitializeComponent
GetFile
Iaszkq
.cctor
<Hire>b__1_0
<Near>b__0_0
set_AutoScaleMode
set_ClientSize
set_Text
GetDomain
GetInvocationList
DynamicInvoke
SuspendLayout
set_AutoScaleDimensions
set_Name
ResumeLayout
GetTypes
GetTypeFromHandle
CreateDelegate
get_UTF8
GetString
FromBase64String
GetAsync
get_Result
get_Content
ReadAsByteArrayAsync
get_Method
get_Name
op_Equality
get_FullName
electronics_and_connectors.exe
disposing
zmoilq
<Module>
WindowsFormsApp32
Ucpolhl
System.Windows.Forms
IContainer
System.ComponentModel
IDisposable
System
Container
ContainerControl
System.Drawing
Control
AppDomain
Thread
System.Threading
Assembly
System.Reflection
Delegate
Func`2
Enumerable
System.Linq
Action
Application
Encoding
System.Text
Convert
Object
HttpClient
System.Net.Http
Task`1
System.Threading.Tasks
HttpResponseMessage
HttpContent
MethodInfo
MemberInfo
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
CompilerGeneratedAttribute
STAThreadAttribute
AutoScaleMode
IEnumerable`1
System.Collections.Generic
RuntimeTypeHandle
String
DebuggingModes
mscorlib
System.Core
WrapNonExceptionThrows
$1df6ebc9-f43a-4c3c-b809-102575ae90c7
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Yrbuxgwoqcagorxzkzm
http://akdental.ro/Lwqqtiabce.dll
Outyeyqrvnyicacgzmxgpxsr.Opinxiralxdlpcpylpf
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
electronics_and_connectors.exe
LegalCopyright
LegalTrademarks
OriginalFilename
electronics_and_connectors.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Injuke.16!c
tehtris Clean
ClamAV Clean
FireEye Gen:Variant.MSILHeracles.84870
CAT-QuickHeal Clean
McAfee Artemis!582BD6F5D172
Cylance unsafe
VIPRE Gen:Variant.MSILHeracles.84870
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.MSILHeracles.84870
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/MSIL_Agent.FDL.gen!Eldorado
Symantec MSIL.Downloader!gen7
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent_AGen.ATY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Backdoor.MSIL.Remcos.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.84870
Rising Malware.Obfus/MSIL@AI.87 (RDM.MSIL2:aV6XSu8IwVjjLwP/vjcYfA)
Emsisoft Gen:Variant.MSILHeracles.84870 (B)
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Infected.xt
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Win32.Outbreak
GData Gen:Variant.MSILHeracles.84870
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=83)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.MSILHeracles.D14B86
SUPERAntiSpyware Clean
ZoneAlarm UDS:Backdoor.MSIL.Remcos.gen
Microsoft Trojan:Win32/Woreflint.A!cl
Google Detected
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.MSILHeracles.84870
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-Downloader.Ader.Rimw
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36250.am0@aCfxWog
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.