Static | ZeroBOX

PE Compile Time

2023-09-11 18:25:41

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
<F\x13!g&\x15( 0x00002000 0x00037344 0x00037400 7.99917665821
.text 0x0003a000 0x0000cf10 0x0000d000 4.88087668201
.rsrc 0x00048000 0x00001220 0x00001400 4.98272666476
.reloc 0x0004a000 0x0000000c 0x00000200 0.0980041756627
0x0004c000 0x00000010 0x00000200 0.142635768149

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00048130 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00048598 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000485ac 0x000003a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0004894c 0x000008d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x44c000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
n^G$K7
Ek^1oV
'^6D"a
(Ce; ANj
iu&f%>
]u5cJg
3jqSZT
JW`8h]
CW"Yq<
@psM0 <Z?
32+m0
m/@0"qF;
n]DSCB
1~jRk~
).%`+R
1/(V'c
PH)+3A)
D_dYS4
j0AD-%s
^0:Y'~
$K}8q3eQ=
7XxmCD
<P,o<[
zh1|IC#=
uj855z
C?mj/?
RS,ptE
."^MYi
jf8OU4
x`\Zs/
OuX9y-
J6Vge
kU`(L6J
~:*]'-
+x/)lC
ZZFB*rnP
}"i5U`
hPEiY/b
Wi7n*S
i;b!F+(Q5
SKg`Sn
a$cd *x
LXnCdt
F1{i),
kedGT"H,
twkU*yda
prLC^>l
f&:dp]^e>
:61Eb,
1t2:p\
:c@X_HT
Wk6cV9
1il&k18
71)%$S
l?r}yBt\
6tcBc(K
q&3JH
C]}rB
l;[_VM
n$*[([
/;T>uO
Mf<C~_]
y(3}$
HjSEZ
Y)*Z} Z
I"viLD
[:-ua\
){E}!u
r`%70Ln
m;^<R'g
L^03JB
Hz"V2l
PJYB.j
ORVe,3h
G}g1TDj
,5UR+x
<68Q}P
ZG</4N
ms-s~:'?0
Nb=V m&
e%}a$f
7_Nm[L
el!4W<FX&
t4x@`x
!zncdo.
Ge_v;3
b#Z.H`
JC].VfC
S[Ei9:
X0{oM'
|OBAU
lzJ0*H
S|34dQ
G7>du[^-
RXNBB7
@O]L*u
_|'R8Q
{]vR+CPi
*a]Ux6
cf5]|i6~
*e9}B
!xNG>VI
[{ YI6
2Ww44W
u#q4Yg
_$3~>-
Lou&[k
}sUeX?
\?+vPyD'k
.x82w`E
U?5bA:
l-M7A
PtjXwU
FMl7Fh,
AR w}my
i-44%$
)E=9D:5
~.o@Qz
gQ1%<
C6{@D)
a#1"Y
dcq}AQ
+FSa>f
P'x%@c
bbZ`
_zN8U/L)
/C>N",
;%|bT@]
)$:?5bn
/mL.G!&
Ol@>lX
Tyy7uT
x|3-%
f2}6jl
P8>m8?
EEf+"kK=?
s>Tn+h=
Xl{"wO
n.0P4}
=1h{YE
8VgWeh
muHS+/
rfXhpk
pgC>+6
KT3!`*A
;AwyO.z
MV\fkxa
Ua/KYK
!On:7/
kp=HHI
Lr,1II
SUgdgP
=W<?1x
A|r{8u
w+}i4v
:R0GI\
dm.sst*
RY=Wrl
kz>.SR
zZ `7R
%TRQ28
U3AMqIW
\7!U|\
3pH7C*
5A;v<Fd
Fx>_K>
_be^L_V
7G3?OxVA
W_nM3?
!1MqR!
`}EqcV
"H`{sb
^Nvj&s
@C%L"=
isoB2g
G/ Nw
!< .UYt
4e.T1~
Eug6w
^+h 80`
`)4#y\
=h5,yt
3.XKve
0|~^A0
q}_9a#
eX~]D2
*-Bal2
OK ZMd
j.}SaW
'JiT|X
pYBvj-
$Jv@wI
n4qwx+'
;Xhu;B+
T>*WD4
$<g6n)bj
?~M<o2
&!<"yC(R?mt
V@I`7h
a(DH>73
;8"1WL
lw$yOD
t8K>h?
+z\,gn
_p`1P}p
,@uupE
qAy8Kp
w0XZa29
S#\1qB
OMK:#8
^rUi#6
&3}J_"
=(%^J<2
3]O1t1Y
u?}ZX9
Xg\;LX
955Jae
Lw^H4ZW
5OT*LN
FeeF7-
6I,6Q
k?PPJ1
1?iHvrC
uA<W~b
8dI?|c
9aI0.C
TJFJaG
?.Q>8QP
WEi%3q
h?VC+U
Vo'8s>
:K}luJy
'Jn ?z
Rj!:%Ry
}?jCR'6L
|"jap0
}4[74i
]mWr^H
F ()eW
]Qajos
BQod71
vp\*"gun
ft@bB|
H#}j\`aC7
B6+h0u
w!<ftL
7~}`i{
Mpmc?
T5=/E8c
yvXED7"
rt;ZPT
1b!#H
0MOQw3
)*e1N0
x$P4zM
L vN,E?
5(0^7
k?]eyD
H;k+3;>k
OS]a:HWK
Ba_a8x
w./oN|
T||+YO
R}x_N
w0F[>8S7.a
@Dvktfs
?FwVtI
H,O5ak
fy7AIO
b,$iM#
ArGseD
s6"!i^
KLSK_Y
EQ$XFm
$E1CYwc
$@7+k=
:I\th0
kJ D*i
[tn1>
*"T/^8
f}Jl7]D
Z"v'Ve
Xxh/n^
V|\l3/
ESe7*h
vov#yU
4&KF*
?PUN?h
a[!84`
XhP[3#
8Ygb1^
C{([bj
8:}cp6Ra
%@]>Hqw
*&Lu-w
23[=O$
`h"W{|
}LVg|4/
45q]:H;6@g
Yh3?gJ
.6Qnb'^
_eJ}6gwxN.U
_%D90A
hadvXF
"rG7Tx
~ZGsjQ
@QPCf~j
s0_m3E
'9/&0i
i8CHYr
:|O}QG4
ynGSu
dJvLAf
^c}ewQ-
]%v=t7
oJV)5x
/)p{n-e
Gy. 1sb
E:5n+`
Xd9R32s0b,&
<:scV;la
Jy<0Aw
KZ.k0E
y, gez,gy
Flfo}b
y5i!{n
@&;(RN-
15a\R|
DGIb/c:
3Sg3C P
`EPv&69B aL<
BB+FYRz
\@{Un%
&1FyV
Q<'1Ol
bMlVvs
e#J>56
z_&n7^
!,={Q@
S ~((?
FH9fRW
"oA4r>
Jvf~3^
$lkF<O`
qaFK0{O
GC_>m
e_WYA'Q}B
[Ceer!
A.0/P[
.ZszxJ
),<Ed!
k%\K?q
V:\zi/S
|YA7o|V
Ee8s35n
oUBJpG
{zeYA^SUJ
isAc1+
9L:7#6a
v>U]z()
G[H/m3
i9584S
T,i<}\viw
j/*kwX
xK ~yH
Hwv[[p2Q
x/,gdi
)f=%VAd\
y?yy.m
Z(|Se8e
TMC?}LP
g#O@d)
50i98]I$
0s9[q1
%xSd]
Ni$kl9,W@
rl1,l
d[c^#F
/&(VFg
;*ek=e
@uYH+6
(Z IZR
%wvZ %
j_d%&8F
Tg%&8,
aZ @$*5a8
R%Xs%&8'
}zB%&8
'Z csY
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
24] `P
server1.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
VirtualProtect
kernel32.dll
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
Module
ResolveEventArgs
ValueType
Object
Stream
System.IO
Microsoft.VisualBasic
ConsoleApplicationBase
Microsoft.VisualBasic.ApplicationServices
Computer
Microsoft.VisualBasic.Devices
Hashtable
System.Collections
Equals
GetHashCode
ToString
InvalidOperationException
Exception
ResourceManager
System.Resources
CultureInfo
System.Globalization
MySettings
server.My
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
LoadLibraryA
kernel32
GetProcAddress
StringBuilder
System.Text
CreateProcessW
Delegate
Process
System.Diagnostics
MulticastDelegate
BeginInvoke
IAsyncResult
AsyncCallback
gsvjvMKgu
DelegateCallback
DelegateAsyncState
EndInvoke
DelegateAsyncResult
Invoke
bufrNLHMmfoED
AHXvead
NLHMmfoED
MNJyess
WGeKPWLwd
nNLHMmfoED
FRaVoTGH
ProcessModule
RijndaelManaged
System.Security.Cryptography
MD5CryptoServiceProvider
Encoding
HashAlgorithm
SymmetricAlgorithm
CipherMode
ICryptoTransform
CompareMethod
ConfusedByAttribute
Attribute
server1
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
System.Windows.Forms
GeneratedCodeAttribute
System.CodeDom.Compiler
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
DebuggerHiddenAttribute
StandardModuleAttribute
Microsoft.VisualBasic.CompilerServices
HideModuleNameAttribute
HelpKeywordAttribute
System.ComponentModel.Design
MyGroupCollectionAttribute
ThreadStaticAttribute
CompilerGeneratedAttribute
DebuggerNonUserCodeAttribute
STAThreadAttribute
server.Resources.resources
nYvgfCswKIbOvbpbaQAqojKAoOGp
Environment
String
UInt32
IntPtr
op_Explicit
GetTypeFromHandle
GetMethod
Concat
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
get_Module
Marshal
GetHINSTANCE
get_FullyQualifiedName
get_Chars
MemoryStream
ReadByte
get_Length
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Buffer
BlockCopy
get_UTF8
GetString
Intern
GetElementType
CreateInstance
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
get_FullName
get_Name
op_Equality
TargetInvocationException
Control
get_IsDisposed
Activator
Component
Dispose
ContainsKey
GetResourceString
ProjectData
SetProjectError
get_InnerException
get_Message
Remove
GetObjectValue
ReferenceEquals
get_Assembly
Synchronized
GCHandle
ToInt32
BitConverter
GetBytes
GCHandleType
AddrOfPinnedObject
ClearProjectError
GetDelegateForFunctionPointer
GetCurrentProcess
get_Handle
get_MainModule
get_FileName
get_ASCII
ComputeHash
set_Key
set_Mode
CreateDecryptor
Convert
FromBase64String
TransformFinalBlock
Strings
Replace
Information
UBound
ObjectFlowControl
ForLoopControl
ForLoopInitObj
Conversions
ToInteger
Operators
MultiplyObject
AddObject
ToLong
ForNextCheckObj
Random
DateTime
get_Now
get_Millisecond
VBMath
Randomize
ConfuserEx v1.0.0
WrapNonExceptionThrows
Important File
!Copyright
2023 Important File
$cc7fad03-816e-432c-9b92-001f2d358379
2.7.9.9
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.4.0.0
My.Settings
&(r5DG
/23J455
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
qN!yN!
N!$N!,N!4N!
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
0123456789
~`!@#$%^&*()_+=-{[}]|;:'<,>.?
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Important File
CompanyName
Important File
FileDescription
Important File
FileVersion
2.7.9.9
InternalName
server1.exe
LegalCopyright
Copyright
2023 Important File
LegalTrademarks
Important File
OriginalFilename
server1.exe
ProductName
Important File
ProductVersion
2.7.9.9
Assembly Version
5.4.8.8
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.0704e4ae55e1180a
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Trojan ( 004b957f1 )
BitDefender Clean
K7GW Trojan ( 004b957f1 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36662.ru0@ae2MbPj
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Injector.BRY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Emsisoft Clean
F-Secure Trojan.TR/Dropper.Gen
Baidu Clean
VIPRE Clean
TrendMicro Trojan.MSIL.BOILOD.SM1.hp
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.Gen
MAX Clean
Antiy-AVL Clean
Gridinsoft Trojan.Heur!.03013681
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.MSIL.Androm.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 CIL.StupidPInvoker-1.Heur
Cylance unsafe
Panda Clean
Zoner Probably Heur.ExeHeaderL
TrendMicro-HouseCall Trojan.MSIL.BOILOD.SM1.hp
Rising Malware.Obfus/MSIL@AI.83 (RDM.MSIL2:aXWkRn1jPBnQGCY7WjqZ5A)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG MSIL:GenMalicious-R [Trj]
Avast MSIL:GenMalicious-R [Trj]
No IRMA results available.