Static | ZeroBOX

PE Compile Time

2023-07-18 21:39:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0021f3ed 0x0021f400 4.86767881463
.rsrc 0x00222000 0x00004d12 0x00004e00 3.24215668554
.reloc 0x00228000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x002260c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x002260c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x002260c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x002260c8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0022657e 0x0000003e LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x002265f8 0x000004f4 LANG_MARATHI SUBLANG_NEUTRAL data
RT_MANIFEST 0x00226b28 0x000001ea LANG_MARATHI SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
-r&&&&&&
-a&&&&&&~[
-X&&&~]
,k+'~0
-G&+3~0
-;&&*~0
91_~N
-~&&&~
-{&&&~
v4.0.30319
#Strings
SIcpm.exe
<Module>
mscorlib
System
Sampafsle
Object
MulticastDelegate
ValueType
Attribute
GetString
SmartAssembly.Delegates
MemberRefsProxy
SmartAssembly.HouseOfCards
Strings
PoweredByAttribute
SmartAssembly.Attributes
value__
YELLOW
ModuleHandle
Dictionary`2
System.Collections.Generic
DateTime
get_UtcNow
TimeZoneInfo
FindSystemTimeZoneById
ConvertTimeFromUtc
String
Concat
Console
WriteLine
GetTypeFromHandle
RuntimeTypeHandle
Marshal
System.Runtime.InteropServices
SizeOf
Convert
ToUInt32
IsNullOrEmpty
Directory
System.IO
Exists
BitConverter
ToInt32
IntPtr
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
GetBytes
ToString
Assembly
System.Reflection
get_Location
Exception
get_Message
TextReader
ReadToEnd
Thread
System.Threading
Environment
GetFolderPath
SpecialFolder
GetEntryAssembly
GetExecutingAssembly
GetDirectoryName
Intern
op_Inequality
op_Equality
GetTempPath
WriteAllBytes
Process
System.Diagnostics
CreateDirectory
DirectoryInfo
Encoding
System.Text
get_ASCII
get_UTF8
HashAlgorithm
System.Security.Cryptography
ComputeHash
SymmetricAlgorithm
set_Key
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
TransformFinalBlock
GetName
GetDirectories
get_Assembly
ResourceManager
System.Resources
GetObject
FromBase64String
IDisposable
Dispose
Stream
get_Chars
EnumerateDirectories
IEnumerable`1
get_Length
BinaryReader
ReadInt32
System.Collections
FileStream
FileMode
ProcessStartInfo
set_Verb
set_FileName
set_Arguments
set_WindowStyle
ProcessWindowStyle
set_UseShellExecute
set_CreateNoWindow
set_RedirectStandardOutput
set_RedirectStandardError
WaitForExit
GetManifestResourceStream
ParameterInfo
.cctor
object
method
Invoke
hfsdkffddfghseffdfaffdchd
fghhfgsfffrfddfdffddshfdasdfh
cdfffdfadfdfrsfsshdkfffgh
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
hjfdffhgfadffdfdcdffffskhj
ffghrgfdffffffkhsjd
sfdfffdshdffgfefdfkfghj
sddddffhedfgddffffgjfsfkdgsacsafp
sgfhjffffgdhjsrfhddfhfffadfsfsscfgdb
dfjffsfhgdffafcfdssfkfhgj
ffchkffdafhfdssfsfj
jffgadffcffgfgfshfskffj
jcfsdfrfdfdsdgkfff
fdfcffrdgfdffsfssffj
jffffgffrfdffcsdsgkffj
jffffgfdsadfsdgkffff
gdddffdhfsfgh
fhfsdsfhfdfhhs
hfgggd
ffffffh
shssgfasd
sdffgfsf
sdffffss
sffdfggfs
ffdgfdshs
gsffddsd
gsddss
gfhfsfs
gdffdg
gsdffssg
gdadag
hdsffafs
adsfdads
jddssf
ggfssddfh
jfsgffdfhg
jffdfdffgfdgs
jsfdsfffdf
jdffdfa
gdfdsfffddj
kfdsgffh
fsffdfg
sfffaf
ffdssfs
sfffdsd
jdfffssk
wsfsssv
gsfffsds
gffssfdsx
startupInfo
jdhfdffsffsdkfj
hdffhfafsfsdkfsh
hdffhdffffffkdf
affdshhh
sdfffhdhff
hffdfffshdhs
hhhfgfffdfh
fffffffdhs
fdffss
hffdsffsf
jhfdfdfdh
CreateMemberRefsDelegates
typeID
CreateGetStringDelegate
ownerType
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
SuppressIldasmAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
SIcpm.resources
{a10f82f6-4785-4f69-8160-cda68821e54e}
System.Windows.Forms
Application
get_ExecutablePath
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
ToArray
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_ParameterType
RijndaelManaged
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
InvalidCastException
StreamReader
FileNotFoundException
ResolveTypeHandle
GetFields
FieldInfo
BindingFlags
MemberInfo
get_Name
ResolveMethodHandle
RuntimeMethodHandle
GetMethodFromHandle
get_IsStatic
get_FieldType
DynamicMethod
GetILGenerator
ILGenerator
OpCodes
Ldarg_0
OpCode
Ldarg_1
Ldarg_2
Ldarg_3
Ldarg_S
Tailcall
Callvirt
SetValue
GetModules
Module
get_ModuleHandle
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
get_Module
GetMethods
Ldc_I4
get_MetadataToken
TryGetValue
WrapNonExceptionThrows
6.9.0.114
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
A)s[0upO^
aKG^02mI
LW]VGHE
0y/aBc
= yhp|
d%e";bc-J
d%e";bc-J
mj9Hx0
;@LSxd
3=hmO]
`Y4>6=
Y<NsNn
BGbWIl
8@waK|
wqSa=;
eXXp:!
o6m9ct
k]&Cw-ZH
vvw#S%
`(`NNK
MrdrMz
(3-5Z/
e\2gWt
BakX6z
GO&=pcI.
Y0Emoz|
&5!yQ8=
S?E>Zt
%'9'V9S
kQ)raE
4G9JYJA
681e_,0
pQ~C`J
rXd%5k
wrWP,0
Glf<ZX
u$vVW8
H]w4|sS
eyAjLu
G]/V1?
rMzFwg?q5{++
$MCT =
Q(@Y"2
Q(@Y"2
*8GxZQk
0qKUt|
8~>a+R
!ZfwR'7h
J.#zH=X
cxpMHe
>S3j9k
61</4c
tfpE5H\7
(keXu,
/?>zR`
+F@kAp
)cEasA
JuuJ_8bTO
/.BCc^
G+`0ZV
k"7: o
B'94Oe
,m=>lI
WL(Ih{Z
dZ6q>d
tDz$N6
G@fFfN{{
IW@hz|U1
X$ID- S
uY6Luw
, ;+H
R>O8dA=
V=nirN
HiTQt9
nj{x,O
N<i|[j
S\NPAH
O-bY42
X6J/|L
4Vd2nTd
dD<Bo<
GQT*}@
.nR|Yx
e}Wey4
R`'@:-^
+J<oP\
@{+Pdw
F7+`9YUf
:X$lkb
%*l<1N
eD^P5WGq
6ugrb<
+'\:W]
Xyy?>-
aOQPn
i%Ybr-T
=catxK
lW/ipI
KjD]py6
_b~^KP
zz%kT^M
3]4Dbk
XLW\1k
.z,WEO
nM[;VM
$rJs*
Ym1;-A
?Ceu4t
/q )[z
RIS]$;
1Ge.`B
74BFd!
dlS0w]
xrjy59
$&v8ae
`[Ek7s^2;
!8N!l5
I9B>6I
e~L=GO
5H&N,^
Os3sk5
-Xkc>C
By}5Iu
OpXS<@
Fb1V+X0l
bRfqdg
KyK]c"R
ci3no/
P,aC_T6
FF%9"<=qai
E%X6&-
>.mngi
:?{i@Bz"
^k?uv/m
be_'zv
6Kg0w]
r-."^
hS+pe@
\w9ru\
9,>u[]_
!2OVa<gf
{MBY&c
.{#Tl?8y
Zf;G`qf4
_g+364
dG#hAg
DNzAiG
S1kETt
qYGaCM
{ c1IM
K?f9lt
=5&y9A
`ApND!
"L :.[
4F45uX
[4*v&^2
j:yDUT
XoBF&6
lY=!;r
/dv'}-
^,)<.bp
VE(1Bc+,
H!8!$bA
#l_l"+;
S$%G=N
AA_I/K
:h$#~'
HtE41v
IkE@Pu
T81'i
Txn06<
kR} ((
t2s}J4=
|Yl]ft
'EsCN.s
[*P.v
,[@dCL
7vo-?+
%#Y" ?
I`o j@Z
Y!%uHv=S
(EtGa]E
%@uhxA
($si0:~
z,eR}$
mbZ+U0l4
dDe^d|!5
a#g(hu;Z
~U{JX%
F0s4Gr
Ooh/0"
?[\$Uf
]}@-Kq
@M['^p6
,%uX7W%
pp<~)F
fVubvd
pp<~)F
fVubvd
pp<~)F
fVubvd
pp<~)F
fVubvdW
pp<~)F
fVubvd
pp<~)F
fVubvd
s^/pNk
pp<~)F
fVubvd
pp<~)F
+ol_q<
+BTeV`
^0EJ?0
?!4@=P
1Q>oq$
pZ0j)C
akPP4\
xwwhuUsM
R`5ttHz
h,lGoB
@*e=.c]
+vDbhp
g~NmZgd
lKDH#w
DJc8mw
Nx8+T
+}wq [
>00*##
)lhGnc
)V\FWr
#PewzQVx<n
@VTNMOY
m 6Sow
jw$<?JL
MhiPOI
e`d72g
V8)qm{K#
V8)qm{K#
V8)qm{K#
V8)qm{K#
V8)qm{K#
$2/Wh\
&}CX-eh%y0|6
"M[K.49
SRk}#S
){k~4n
){k~4n
IbP!Ky`c
o29;U7C
Lbf-Q8
Lbf-Q8
Lbf-Q8
IbP!Ky`c
pOU`,v1
){k~4n
){k~4n
iFB]E*
#hvn<A
>p H-/
l4A`8S
ggX"%#*
){k~4n
){k~4n
iFB]E*
[{Mi?g1
){k~4n
){k~4n
P+gk_/
ycnTh)B[
D-s}$X
z#wP1
;x:.nz
;x:.nz
P+gk_p!
b[*?Pp
l4A`8S
;x:.nz
;x:.nz
Ii_9_$
mO/L":
\L6[qhJ
\L6[qhJ
I]Zg%
\L6[qhJ
(fw6~*"
\L6[qhJ
(fw6~*"
~HFN{1
.wjA!G
;x:.ne
.wjA!G
;x:.nz
.wjA!G
;x:.nz
.wjA!G
.wjA!G
J9m?3DG.
"jMYF
;,9f?|
]dibNXoQ
) L<]w3
x4`s`K
-nPBS,M:
!Ye;D.
-nPBS,M:
!Ye;D.
9I)1t~
9I)1t~
"jMYF
{nbU
9I)1t~
9I)1t~
9I)1t~
;,9f?|
w14s6"
5vVf G+
K9g$=1]
K9g$=1]
K9g$=1]
K9g$=1]
K9g$=1]
1;ZE+"}
3Oc+*9
K@L&b?
ppV7LN
E7kJUo3
E7kJUo
E7kJUo
E7kJUo
E7kJUo}
E7kJUo
E7kJUo
E7kJUo+
E7kJUo=
E7kJUo
E7kJUo
E7kJUo=
E7kJUos
E7kJUo
E7kJUo
E7kJUoD
E7kJUo=
E7kJUo&X[
E7kJUo
E7kJUo
E7kJUo
E7kJUo=
E7kJUo
E7kJUo
E7kJUo
E7kJUo%
E7kJUo
E7kJUo
E7kJUo
E7kJUou`
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
nTTQc9
E7kJUo]m
E7kJUou`
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo9
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo@5
E7kJUom
E7kJUo
E7kJUo
E7kJUou`
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUou`
E7kJUo
E7kJUo
E7kJUos
E7kJUo
E7kJUou`
E7kJUo
E7kJUo
E7kJUo
E7kJUo
j9vdjF
j9vdjF
E7kJUo
j9vdjF
j9vdjF
'=m@?L#
YUm46:
E7kJUo
E7kJUo
j9vdjF
j9vdjF
Ti4~mt<
E7kJUo
y?y,@"l
V6CV0S
E7kJUo;`
YNO(Bwe
E7kJUo
E7kJUo
E7kJUo
E7kJUo
E7kJUo3
E7kJUo
E7kJUo
E7kJUo
"C4YGy
M0g(8o
'2wAl9e
eF*\U;
,OFZPMWkrcThrQmhhMEo0aTdOa2dTbWZFU05Md1Jrb2I=
U0ljcG0=,OFZPMWkrcThrQmg0NCtJUmd2LzZIMmZFU05Md1Jrb2I=
RHluYW1pY0RsbEludm9rZVR5cGU=
Z3c3RlZFeDhNT289 MUFKY1lSeEh2eGM0NW5pTC9VWXlsUT09,MUNjMkF6eG04M0E5VFJ3UVZicWpPVmE3Tnd0bzFybXo=,T2d6QmlCYTdpWFZQbHRuUkQ4OXpOV2ZFU05Md1Jrb2I=,dEROWE9PRnpoM3huYXJ3aHVNeWpROG5neXh5bmxqaFo= UTROYU51SGFYQzlNa1BmSFZ3L01Tdz09,bGtTOXpPak0rZU1rZWxuRys5Q0o5S1RBZklKOWZVU2Q=,b09DK3NoRUlSMXc5VFJ3UVZicWpPVmE3Tnd0bzFybXo=,ZHJrMGlYdGJCWU5QbHRuUkQ4OXpOV2ZFU05Md1Jrb2I= ckkvdm5qT1pYSVF5VURZRXAxWGdKZz09 YURUV3daWHNXb1E0NW5pTC9VWXlsUT09,MEFGcHdYRDgzUWVtaSsrb3htSkhpOWpVNTAvMmE3T20=
RWFzdGVybiBTdGFuZGFyZCBUaW1l RWFzdGVybiBTdGFuZGFyZCBUaW1lOiA=
SW5kaWEgU3RhbmRhcmQgVGltZQ==
SW5kaWEgU3RhbmRhcmQgVGltZTog
Q2VudHJhbCBTdGFuZGFyZCBUaW1l Q2VudHJhbCBTdGFuZGFyZCBUaW1lOiA=
IA==dZGJtY2FuZFNrQWNGb21jaGdyU1NmU2pub2lkbmFJaGJBZGRwZHBBZnJnZmdGY3BnbXBvY21mZWRraG1rSWdTRnBhU2tpbGxwSUln
XGNocm9tZQ==
XGNocm9tZS5leGU=
Y2hyb21l
bWtkaXIgIg==
Y2hyb21lIg==ha3hXMEY3RmJjR3N5bjBIaEpCZHNrVGVmbXFqcldMLzFjTW11K09CV29BdHBPVTFaR2FLeDRsM2FKNFBMa2dGVVBVcXhvN3k5T2hnPQ== Y2hyb21lXGNocm9tZS5leGUnIiAvZg==
M3paS0lvbHNWVWc9
Y2hyb21lXGNocm9tZS5leGUi
VGhlIHZhbHVlIGlzOiA=
(TmFtZSBpcyBub3QgYXZhaWxhYmxlIGluIEVOVU0=
TmFtZSA6IA==
RDovU2FtcGxl
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
ZDovZmlsZTEudHh0
ZDovZmlsZTIudHh0$Q29udGVudCBvZiBmaWxlcyBpcyBzaW1pbGFy,Q29udGVudCBvZiBmaWxlcyBpcyBub3Qgc2ltaWxhcg==
ZGFkYWg=
ZGRkZGRkZGRkZA==
UG9wcGVkIEVsZW1lbnQ6IA==$VW4tYm94aW5nIGEgaW50ZWdlciBudW1iZXI=
c2FhZGFhYWFmeHQ=
U2QgICAgICAgOiA=
cnVuYXM=
Y21kLmV4ZQ==
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
{a10f82f6-4785-4f69-8160-cda68821e54e}
dbmcandSkAcFomchgrSSfSjnoidnaIhbAddpdpAfrgfgFcpgmpocmfedkhmkIgSFpaSkillpIIg
MAINICON
VS_VERSION_INFO
StringFileInfo
000004b0
Comments
This installation was built with Inno Setup.
CompanyName
EaseUS
FileDescription
EaseUS Data Recovery Wizard Setup
FileVersion
15.6.0.0
LegalCopyright
Copyright (c) 2004-2022 EaseUS.ALL RIGHTS RESERVED.
ProductName
EaseUS Data Recovery Wizard
ProductVersion
15.6.0.0
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Ransom.Loki.8883
ClamAV Clean
FireEye Generic.mg.92899ca104e6ac22
CAT-QuickHeal Clean
ALYac Gen:Variant.Ransom.Loki.8883
Cylance unsafe
VIPRE Gen:Variant.Ransom.Loki.8883
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Ransom.Loki.8883
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36318.jo0@ayaHnZlG
VirIT Clean
Cyren W32/MSIL_Kryptik.JLT.gen!Eldorado
Symantec Trojan Horse
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:qadxE6D6dNpYxFPncVzMjQ)
Sophos ML/PE-A
F-Secure Heuristic.HEUR/AGEN.1307491
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Ransom.Loki.8883 (B)
Ikarus Trojan.Agent
GData Gen:Variant.Ransom.Loki.8883
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1307491
MAX malware (ai score=83)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Ransom.Loki.D22B3
ViRobot Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AHBB!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.104e6a
Avast Win32:PWSX-gen [Trj]
No IRMA results available.