Static | ZeroBOX

PE Compile Time

2023-07-20 22:57:36

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003127d 0x00031400 7.88301329676
.rsrc 0x00034000 0x000284ea 0x00028600 4.31727603543
.reloc 0x0005e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0005b4f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0005b9ae 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005bf04 0x000003c0 LANG_ENGLISH SUBLANG_ENGLISH_CAN data
RT_VERSION 0x0005bf04 0x000003c0 LANG_ENGLISH SUBLANG_ENGLISH_CAN data
RT_MANIFEST 0x0005c300 0x000001ea LANG_ZULU SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-;&&*~A
91_~?
,s&&~A
-r&&&&&&
-a&&&&&&~.
-X&&&~0
-~&&&~v
-{&&&~x
-G&+3~A
v4.0.30319
#Strings
dbhel.exe
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
PoweredByAttribute
SmartAssembly.Attributes
ModuleHandle
Dictionary`2
System.Collections.Generic
Convert
FromBase64String
Encoding
System.Text
get_UTF8
get_ASCII
GetBytes
HashAlgorithm
System.Security.Cryptography
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
IDisposable
Dispose
TextReader
System.IO
Stream
String
op_Equality
op_Inequality
Console
WriteLine
FileStream
FileMode
BinaryReader
ReadInt32
get_Length
Concat
Assembly
System.Reflection
GetExecutingAssembly
GetEntryAssembly
get_Location
ToString
Exception
get_Message
ReadToEnd
GetDirectoryName
Intern
Directory
get_Chars
Exists
IsNullOrEmpty
EnumerateDirectories
IEnumerable`1
Thread
System.Threading
Environment
GetFolderPath
SpecialFolder
CreateDirectory
DirectoryInfo
GetTypeFromHandle
RuntimeTypeHandle
Marshal
System.Runtime.InteropServices
SizeOf
ToUInt32
BitConverter
ToInt32
IntPtr
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
System.Collections
ProcessStartInfo
System.Diagnostics
set_Verb
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
set_UseShellExecute
set_CreateNoWindow
set_RedirectStandardOutput
set_RedirectStandardError
Process
WaitForExit
ReadLine
GetDirectories
DateTime
get_UtcNow
TimeZoneInfo
FindSystemTimeZoneById
ConvertTimeFromUtc
get_Assembly
ResourceManager
System.Resources
GetObject
GetManifestResourceStream
ParameterInfo
.cctor
object
method
Invoke
hfsdkffddfghseffdfaffdchd
fghhfgsfffrfddfdffddshfdasdfh
cdfffdfadfdfrsfsshdkfffgh
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hjfdffhgfadffdfdcdffffskhj
ffghrgfdffffffkhsjd
sfdfffdshdffgfefdfkfghj
sddddffhedfgddffffgjfsfkdgsacsafp
sgfhjffffgdhjsrfhddfhfffadfsfsscfgdb
dfjffsfhgdffafcfdssfkfhgj
ffchkffdafhfdssfsfj
jffgadffcffgfgfshfskffj
jcfsdfrfdfdsdgkfff
fdfcffrdgfdffsfssffj
jffffgffrfdffcsdsgkffj
jffffgfdsadfsdgkffff
gdddffdhfsfgh
fhfsdsfhfdfhhs
hfgggd
ffffffh
shssgfasd
sdffgfsf
sdffffss
sffdfggfs
ffdgfdshs
gsffddsd
gsddss
gfhfsfs
gdffdg
gsdffssg
gdadag
hdsffafs
adsfdads
jddssf
ggfssddfh
jfsgffdfhg
jffdfdffgfdgs
jsfdsfffdf
jdffdfa
gdfdsfffddj
kfdsgffh
fsffdfg
sfffaf
ffdssfs
sfffdsd
jdfffssk
wsfsssv
gsfffsds
gffssfdsx
startupInfo
jdhfdffsffsdkfj
hdffhfafsfsdkfsh
hdffhdffffffkdf
affdshhh
sdfffhdhff
hffdfffshdhs
hhhfgfffdfh
fffffffdhs
fdffss
hffdsffsf
jhfdfdfdh
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
dbhel.resources
{a9543ee4-de12-4838-be0e-d3089d773ba6}
System.Windows.Forms
Application
get_ExecutablePath
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_ParameterType
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
RijndaelManaged
InvalidCastException
StreamReader
FileNotFoundException
ResolveTypeHandle
GetFields
FieldInfo
BindingFlags
MemberInfo
get_Name
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetModules
Module
get_ModuleHandle
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
TryGetValue
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP"
h03B5!
n.uD?j.d
@E] /5}
UbdCN5
qhT`5B
8Y"Fxe4
W/x p9
eg#g+
\6/PB^-
=*O0g!
u:T\jI(
e,GF!)
+^g8m<
X_%d&f}
UIcccl[T
T`&8C
z2},SO^x'
q,P\KP
x(c3%UH
){58k~&
Zy;A;b5
m_al7RM
WP8}uV
[oRZS}
OU-\=!
;wv*o{
f_76j<
di&6V8
0YE9K@
sA]4%L
Fh^,&R
\{P,*^
/;8Tv[x
jWEs=d
o*gSeD
mah/':N7
u{_v|v
HE06wA
&7rIrwO
cd3l97
99}Z+Kz9
IX$Z4GE
$L,EPq
]{XgIs
^[~\'h9Vx
nl"1X5
!9.W;g
\S*$dXq
Jvu8M>
F>~ID1=}
IrA{~h
KTqs%S
Ek9L5%
^Od`/
/;]WE^
TFHI]
R|C(~W
iIP`,9
%pcX*Wzn`
4WY[Ip
RyhGuR
4 ?,[v
l!/?1v`
nXk_k~*
vNC3nA
(+,9U{
qw#4YX
#'gI')
{v|p-P@
SuN0q8i?
8Pv}/<
9\[;z'
la~S N7
%-((Zx
h&S<bp16
VMTCe@
%Z922^
OJP,V{
QgiS.(
[zIX06
|n+W}+
QoHJ`;
A\dbk'=
m/{@Z2
8vjLc
"u\Oo^
2vNF.&
1:oN^s
5*M?+c
4cvoGj
aUZx6q=
?G@,Uz
?G@,Uz
V$#\`Lf
L~*yxu
#r0T\+2
%7{.w\+'
>tM(e]
S*K3w%
.;?nUl
3XO_=3
Mw D,I"B}/
Y=eXzRqs
*:n$_b>
3XU#jN
L&=|EG
)]:8~m
6;MTcG
4+x{E.B
GrrPL"_
gv#'BU
B(/6bA
x b<'D
{8?,6[
]ulP0%
EL~*=$
abaup;
kU<,Vy
<(oq52
)oHie?
RL,Q;7
"-X@c:p
AgL*)c
a2512[Xv?
vEvB:Zc
?i=?6L~
PJL`"w
,;093\
h9\D!\
OPTs&
AxL&^h
i2kHTJpH2
{5!dPU
sNq_kY-
MR0.w9
i$K=&R
\OygCT
)f5&Ez
.d@'9|
kI/RNvQ
K^<K.l
Hkgc$T1
#K]poM
Yefj>wI
Q~1pIz_
%*[0s[rOw
cbI(|r
n`ZigQI
!$73</`
Lu2`p2
/6G*-G
:zp }-
t`BeI|
`^e"I
GNJLLp
'mf+*$4*J
$,BIz/x
<s/IDzR
-(d6$NEu
}9._>f
;$F*SE
tQTqGA
6=/?XaL
]zugOS
HRvk8f}
qSCp#>
]eH>Ln
vhfJMuU'Z-
2.Aqh#K
]#qR7xUl
#or-U
Z%>Z}S
gcn(h#
S^U([;[
-Z_Zgn:v
/8~9tC}
Jm!Avo
T&M=~}%
J|<GHk
dM)H^Z
XrE$`Ez
[j-G[nm
Azdd:w
"e~X:A
dfJ4Qd
)f&D8~
#[.Mt8{^
`,CMfc
61'd19)AT
dYDkV#
9`1}HP
x{+87"DD>
(A?{N.
zeOmm+
.Ix 7*
,=p4?0
HV]6"K
xE\Q"&
^<*/vCVu
&sz8,k
#\^%|+
O!N_#g
{$<m:^"/pe
fK]b3{
n1`39u]
q;njOa
j}AroX
{m>B@@d
"0zxGt
3K=v:\
cjd{&?
]/N@gB
>q,8'
0 $="TSVl
k/A^>,J7
$<A:0@u;P
jStrf+
=38D6|IqO
@P(^kS
9N0'k
G:'1Id
*Yify'
f(oq6h
\LYWEaX+
l.'/MCd
u m Qr
[Ky}HH
dvIv#I
^Lo#x"0-w`!
0P@P>.
Zr42;1$
={%pxP
Ah\ARRJ
Cl4wD0
jR~O7V
c<}>J%
yJ:HTO4w
$Hf>$l
"qg[^_
d#jai?
G5qZ I
=Y%&7d`qf#
C <MQ9
3A*Ti3das
fMCV3?Y*n
||e{:B
\t['Uo4S/
d}!5G
c_QM<t
G/]v:Y
[-]ueJ
pw;C;.
4gs+ZJ
fK[0f4
(aVf:M
g7\oXC?
4CT+>pm
rSiGt?
}^W^4 6K}
n/*L{
gW$VRCc$
hAPlhP,u{
230r:if
kSsPQa
yz%Z:=
u?5Pbe/
/>jNT8
mIy_zo/8(
!;yxyj^
.RU%r.B
}<qmjs
A,;QiM
w|t-?C
VIB19@
,SEplOE9jR0ZlRDh5VTc2UVlYZU1lSW05Q3BuQ3BpeWc=
ZGJoZWw=,SEplOE9jR0ZlRDhUaDROTExteUhNb205Q3BuQ3BpeWc=
RHluYW1pY0RsbEludm9rZVR5cGU=
RGJGWTd1UlZFZUE9 aFFOOWd4NzR3TjBrNVZtN1d2b09pdz09,M1VpSGNQTXBXcFlaeGYwd2FjdmJJYVl5L1JQSjhyeTU=,eTZKcFdFeGRIbmNCa3ZVOGs1RHNVSW05Q3BuQ3BpeWc=,UTRFNlcrakxvRmY5L1RGVDg5RStkWWkzQlcxL1RCdWw= eG45TE4vLzVMZHRQZnczeXVIRFBoZz09,Y25oQm5lNjZEZm81b1hBcVExQjRDTGRkZWJvbEZDeUo=,cVN4RGtLWEthTlFaeGYwd2FjdmJJYVl5L1JQSjhyeTU=,cDA2SzlWR2p1eFVCa3ZVOGs1RHNVSW05Q3BuQ3BpeWc= MVdPVk9KTys4bldadnNvZXBUNHhuZz09 SzliMDJZUnRnSnNrNVZtN1d2b09pdz09,ZWlucTltNTZsQldtbUQxcU90STNGTmMxYmVFenFITjg=
ZDovZmlsZTEudHh0
ZDovZmlsZTIudHh0$Q29udGVudCBvZiBmaWxlcyBpcyBzaW1pbGFy,Q29udGVudCBvZiBmaWxlcyBpcyBub3Qgc2ltaWxhcg==
c2FhZGFhYWFmeHQ=
U2QgICAgICAgOiA=
VGhlIHZhbHVlIGlzOiA=
ZGFkYWg=
ZGRkZGRkZGRkZA==
XGZpcmVmb3g=
ZmlyZWZveA==
bWtkaXIgIg==
ZmlyZWZveCI=hajVKUWxHZUdGd1hBMEVDZUN1WkJMYm9BQ2l0cW1VeTFyVEJ6bTRUOGM5aCt3VW5EMDFZdlBZRnIwdTZkd2FtWlRQV0hmSHBJelJvPQ== ZmlyZWZveFxmaXJlZm94LmV4ZSciIC9m
VXpDaEtNMmdIWkU9
ZmlyZWZveFxmaXJlZm94LmV4ZSI=
IA==$VmFsdWVzIGFmdGVyIHN3YXBwaW5nIGFyZTo=
UG9wcGVkIEVsZW1lbnQ6IA==
cnVuYXM=
Y21kLmV4ZQ==
RW50ZXIgVmFsdWUgb2YgTiA6IA==
Kg==$VW4tYm94aW5nIGEgaW50ZWdlciBudW1iZXI=
RDovU2FtcGxl
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
RWFzdGVybiBTdGFuZGFyZCBUaW1l RWFzdGVybiBTdGFuZGFyZCBUaW1lOiA=
SW5kaWEgU3RhbmRhcmQgVGltZQ==
SW5kaWEgU3RhbmRhcmQgVGltZTog
Q2VudHJhbCBTdGFuZGFyZCBUaW1l Q2VudHJhbCBTdGFuZGFyZCBUaW1lOiA=U2
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
{a9543ee4-de12-4838-be0e-d3089d773ba6}
MAINICON
VS_VERSION_INFO
StringFileInfo
000004b0
Comments
CompanyName
Foxit Software Inc.
FileDescription
Foxit PDF Editor
FileVersion
2023.1.0.15510
ProductVersion
2023.1.0.15510
InternalName
FoxitPDFEditor.exe
LegalCopyright
Copyright
2004-2023 Foxit Software Inc. All Rights Reserved.
LegalTrademarks
OriginalFilename
FoxitPDFEditor.EXE
PrivateBuild
ProductName
Foxit PDF Editor
SpecialBuild
Packager
Turbo Studio 23
PackagerVersion
23.4.13
VmVersion
23.4.3
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
www.wintertree-software.com
CompanyName
Wintertree Software Inc.
FileDescription
Sentry Spelling-Checker Engine
FileVersion
5.17.0.0
InternalName
LegalCopyright
Copyright
1994-2010 Wintertree Software Inc.
OriginalFilename
ssce55xx.dll
ProductName
Sentry Spelling-Checker Engine for Windows
ProductVersion
5.17.0.0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.66bb82ee05fc1373
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.a3d3f8
BitDefenderTheta Gen:NN.ZemsilF.36318.ap3@aqe!c7lO
VirIT Clean
Cyren W32/MSIL_Kryptik.JLT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Banker.MSIL.ClipBanker.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:hx3H9qlwfw8BjU+AKPixfg)
Sophos ML/PE-A
Baidu Clean
F-Secure Trojan.TR/Dropper.Gen
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan.Agent
GData Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.Gen
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Banker.MSIL.ClipBanker.gen
Microsoft Trojan:MSIL/Redline.AAFO!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5458972
Acronis suspicious
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AHBB!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.