Static | ZeroBOX

PE Compile Time

2023-09-16 12:08:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00074590 0x00074600 7.99533642222
.rsrc 0x00078000 0x00000556 0x00000600 3.91366608598
.reloc 0x0007a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00078090 0x000002cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0007836c 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x476588 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
*V?,Ki
"2aan{p
\z5h[z
3{AaUb)z
7y}+%}
:$6wZD
,VeqR{,
e/Q0C!
(F3dO8
G}PHA/
Y<j(5v
rF6q.?
*06uE\^
FJ3FU5#
rlRP T
99Ht4Y
lX`y,n
;si}4I
9I1ubs2
/EE_#a
lw+!?'
;t~G+31K
dj$a3j
DkRu(B
^"{FQC
:U NSc
8W):?L
_o~Zo-9
Rs8~*w
\_mQ0B
}3]trc
_-V!(^
S+Rs3
QXkgFA
ln~.kI
+m7B~A
5F`V$co
6WU;)S
.CK2tW
L> :BN
H\Am@^>
SBo@XY
Gh`ni}
5G}xDz
0AV48'
{jJL$If
!mL +l
IGr{R!
Y`'(-$h&
u\}(y*
r_yZ?D
(,MVQW
HU&,aj
{P~yG#
xx$hzufk
gl6&'q
nq0lJX=d
&$j<A><
"(EhI+
z]H*Er
h^+I;D
0#T)R;J
a&#B@]
hRM%Kl&
I!lu=q
}vc=R4h
~dn>fWkF
cO`<PI
Rtcw^k
?$^h!N
TTaL@'
/-b-g$
w(}&s]
1"[*9C
K"5-Ko
<0,f%{@%
oH8Bi
fCECZz~
}aC.ie
'qB=2M)
/('m~O
Ly$"mb]u
d8q?rI
B|D6B
7P'GE
D_3(N7
N("oO`
!^/qT!
)~P_=Q
wW_VVoc
lK!e{+
4.8,UO
_<E#?2a
3{k2&m
^G)fUFX
k(%`lW
SVz#(_
:VOu(,
dH=|x%s
c\8]'f
K+80l#T%Vi
zP@OG%!
{A4E+,
E]M%sx
RR0v$8
AO>w4CgY
xWhm<)f&
DfIzTE
.tb\j
p$BSuHY
7K[v>b<q
Nk^%{T
?kkK_~<
9|<X0p
WH>'cVhn~E
s:,tWYB
jZb}U
D7DH|1
mK9#Vd
,MurWj
n'H$rx
QpU2zB
(XJ13$>
$z=pQs
>D"w'E
2&-]6P
v2~?<G
ejse%(
gD>t rOT
,^B:$\hc
|bl$xu
bvCeC+0K
/U@zv
F]dM
u@"wrW
2+Rv41
^`&|Wc`
$~b+OB
O)Q7rn
]KX41#
kG8(n~
PmV;%374
tv71@Z`
4TOQRF
rswni
Mf=6h:
7$O5fa
0fn9`&
zQHCr)v6
m+,Z[K
VGLjj$
=Bmdu}M
6/]LPo
,Lz3<>
\5s:Wq
VNG`C9l
M;V$l.
= lMNa
b"K*.-q~
m(_*k}
R/7h)M
SEH:WA'
"/;ya$
fh`e-y|"
0FV!`e+
|JVy1^W
}1Y,B8o
61%foJ
0'f a3
a,63_v
'/{)|G
<5>|,:
'q.6ycs
?*pcp4
+t/5xQ"
V.Sb8M
TLlXjLH
=6c5i]
eX<*hY9
WJ%C<3;
#2Nw&*O7
<X[q3B
MS/Y6u
=|vHK*Vt
R;YcyxZ
mF+d_D
#\ $?]
$EsZdr
)`_<Ej*
5kfu~)
&N,-q'k#
j/xui/
Yx0sYd
`}V3BR
C;W7"#x
~^t0bs)
JGXrHa
i@*DcW
$t4,~+R(W
"J+a[o
B$MV>.
o2;u:G:OU
Aa{W/`_
~E?|US
%;5%>X
a$&XsG{
}*{qXb
ERJVEo
%t*]voSA
&tK"pY
0+>#yZ
(D'Rs&F&i`}
UuhBU0g
;p[y"hqL
3PoiL%
O>k&;Q
+7Uas|N
7(,`'i
++,_n8
+)+pU$|
'*DEE.
Zr?G<)
.Z|(5r
TOK?*/~
$D7Trx
e9lvmX
W.[cs]
Ww+(]
^"{@wE
Em7hOCx
,|aNI-|
V|Cbxz
QokYn0
Et'd*,M
f.Mu^7
4X.y%
H%xBc9
^zX$JE
["%X:G
Hm1WXdm
sh7RXW
SlxLt0(
6an|hz5
$!Sod@
k*8E-?=
sDGtgU
c_(yf%H
S1[J h^
'VPhK-
,fi_E>
0(>J%PF
%u1+'_c
w~0(T]
A)MAk>AV
\_n2$-
tJDD9<
xW\2x8
El~0<GN
Rl>Qjo
4/wSJ~
0Ro[>
.qu8x]
A{n-V}
}Cya~,kcyRV
x|T<`,
J?V!s4
cdT?F%
lJM,$T
TX["7B`
mx}7hA>
Dzjxn$K!=
?L"T/-
ga6PhGP
_WXHQI@<
Z}r*~"
3No`gN
@X7Ev8
+Vi8_h
^CRdrYTK
.PZH:p
ZhW 1n
J@#,,xg
\jD(/t
>H\](W
-QOU,IO
nqu"*c
;;=1[}
wM\0w-
7|^&^v
+Jz0&y
szmrYKW
;Z)*F?u
!"qD1Wf
:?Zavrk
)jK$}H
N)I~p_I
YyTP06
IDG\$uIs0
C)z.&K
#GGK-w
wwF'a*
qHoG$2
XL,Ao}&
z$,d"O
Vxx3v8
I30#O&D
Y#`@|<
cY(F(\
23Jee{
=k1O^$
Q)NXR4
-U=/*k
a>W*eJ
G6H0tl
}"8BSsx.
mMgA=.W/
G%0[i)g
w`{*)/
QUd&j!
fks~fP&
T\T>&
]h+^Y|
HShVVy
kS%V1/
S%8I%UZ]
"2+[d*gs
e":Iufw
[G$3"#
~M%>/Z
B^v&4$
X?(A!!8P@e
`:dTM}.|
`xYKXOB
$}u6Oj
W5DB9|@
O!,)[K
xDzlk
~= `/i
&&*tDqv
lBq_2/6
IbU8W0q
IsER8Eg
0Ehs2"v
dcIeV
{7]f|#
dcI_Z)/
:M:l?t
;p'JQrJ
x]3j|P\y@m
[bJS`
ay6$@~
16qa.bxW
3 gHt3
i@?M`_
mtbL|Q
]IRC-@XoFF-
s2nsU}
@9WbLD|J
Rq3d-t
&sb6vE
Ap~xKwm
;y?AcX
dF]Dw;
#e=\# W
^cIt0W
U:D1]dm
MbHK!pMq
8ou."yF
o|N*u}
RN^/nL
m]9fp(
5].xHxK
j;?Yah
V"wRu6p
i")_kEaD8
q1hDw"A
RasF|Y
wOy*n
qHyYxK
AI-N0yL
EO^~Zx
M LL\&#"
Ks!!RmfJ
S~8W8s
a?;zcn
aU7Qe3I
DN%6=8
a7nYxR
_t}.Moh
q-@>0-
k$Pp%Ay)
n@L&.y
_KKb}
#U{wqc
m40Rx]:l
K.NKn{|uK
\Sw)_S
8I`) 4
1ls'f
0fc"v%
5-l><p}
>wQLL?
"J$bd>p
&4=,u;
,__q!^
4R5A,=
e+Vs$2
ob6]a<0H
r?'ZF]
i}eR W
",G\>n
kOe}rt
azN48
I)SsP.|
I$;0e4c]T
2x)9M"&
y[%i~_
WUN0M&
Nzs#JB
QJhB(_
-|**5d
t?hF:C
*R=2\(K
E)}*'m
A_Ge6U
yTEECa
!Mxe 0
E:qeP/
z9PYu*
e1GSX0
T}fMso
mI.;eK
{0gEbB
Q]`C@O
D505:*r+
Gd VbCh}zG
61.CpJ
??|sYF$3
B.K=8
jrwj*N
~p6u-0B
2Fto`M
xog=<D
iN.=>fR
:455;d<-
Z0#`C]A
FZgrCP
~ 7z.J
kbC%Q?i}
&s&5l6S
x9[=V`NQ
#\@Wn_
_^k!-mIo
Uc75BSWT
7AV,y
Es}J38
52<]j1@Y
p"ZFxx
OLfP]Ut
A|DZ5I8
74MY=%|
iz"FC{
s:n`w
&Z`W;
9@4L^h
B2AQmA
sYg$jt,
WKla*>
QS~=TDf^j
m1pCT)
.Y B][m)
v5<_"@g
x*!5>'
Twi8o0>
~*f\u'
<^>zw
eV~IL2
7Zs`-F
Z9./V\0}
suS_$'(
_O;8<U
xM&c|[
yoZP\PA
[Q\pb3
&y Z}Vw0
C=p6iY
]'P'/[
pL2!M6
r@Hopokq
|RY!+j
88|q#1
05;VEHe
?iS%"$E
]'wLf=
"9+^xu
WnkXZE
?:gd|s>
]dUSn}
pyb<]y:*
UXL.jw
EFLJ5n
?t.%c_
t('W{C
Y+c*HQ
R&glX[
<@.%c+
cT'P8f)
B{Lv!YQ
SQ3`DG
`zxzFxgni
lJpNm! WI
Jm[/^l
%:?vb[
uVSIMj
!~QHgJ\
xJiZC\
8St5:;
/lS-)E
L?S7\#
bIwQ0f
(.)|5I
&a:Cl]
7nF2!
'[Adwu
O3k=`\We
=fx_Xnv
&Gu@Bc
t[/Zzar
7{8x!L
Jy8LA`
l</Tjs
i}gzMe
rdL6#T
`ZPh8U
ii'5Sm
!7y"=A3Z
@ l3ty
[q|eu]
gz@d/)
`]lE9y
n*#<ZZ\
\"3zAu
YDC-
RxScg%
O7*dc95
MQP(uHJ
AY:l"C]
?9)"?U
~(`+H4
55J|@O
&pj-?R
wUUB>K?
(J_t9g;q
U%RVs-
8'&Csv]
WY2xDr
_4q#~^
|!Q>g
+N15tP
g@ZZ~P
'konY=
7H"gwq
I0E_iPt
#qGosU
p:iDX'ka
xo|gVPEg
ONJH6+
49"jNV
Hn]ZHj
D(C@ja
jNoD~`\
.72g@C
@SeDsG9D
`k!L!%
xNSDGQk9!
T+1|HW+
C`}mEq
2Tf dN KGU
03N:Su
)44F`-
>u:^G)a
b te3>
G/>$cL
[3U/E^
lj@ %j,"
Tcnl7L
4LBr-y
W=7C-Q
?Fq _'|
#r;wf0
bQcH%B
MB;:k,
1Q\0`a
vYXEs8Cg
#dQj@'^
$UH'|n8
3-X)4;
zUsNct
WmU?o$NZ
4hg'%a
<|pf)^eS
:(B",g
wG0Z)=
Za&-iVNi
Z>3 >sD
tz`#B4
94M|,j
)9}0I[
7eTJCF
Bo=Z3L
Hn/+W~;
$&;\XQ
xBoB-fUV
LyGKHu!a
}LZ$S#
|R%53%X
[T(&%
q4qA`Z*g[
b5.:1C
+P []$5'
,!FooY
PAqOH*I
0La+rPz
$ep%Xe
X!o8u4
t\}NM14
BvvBZY
u~@7t/
CsJg/2.
bw'YG}nB\H
UNI.'r
[0+yj2
3\B{:8
p6&K2%
RiGu22
S||<g.
:bau)s
$p'vw`
uw? !j
~~$uO:
H"7)K&
.I]oH\!
JveHJ
^kmfX5>
gxjRlL
2S_X}1
%"t<qt
L~3GPoR
j}C5!s
qZzx|@
}jg:IZ|7Y
Q~qW?|:
Kz-u7Q
_8^Mg+
>nF,AGo
tYtz)-
,p%SbH
n20<bO
]kiM.v
}b]q%
7O"gaA
9^cTpS
J^*QB7
0<A4YE
e:&njWo
$,|u]4
708G !
yL(G/&
=6i!ggR
W)f[xIE
hH94ps
5n'Cq^
2!O\/i
J]$m9A(
LS[=hW
AmVIO%
SVm`E[H
?K['ufx
4Vp\"7
/7)zl9bP
jLMkRd
`EmoU2
Oh/~:s
u0A]TM
(ZBkn'
@1Mv:\-
C%J;5L
+,Bk{Q
/@m&w,
S:(;LB
|=FP<4
nKAhxp
[.{*?U
<;4#Lg
28*_7t
$rlTr-n
Scd:Nq
.p5q]y
"QI47^
GPjwi/x
x2<BlNf#Y
0=.KVU
F~B"t5
dAvcVL
i~V|X(
{@A}aB
HtWe}a
-gpwmO
|KUPc=H.
\Yr\4&
"~+Sik
7tcW@_
"[texc
>`F(iz
B'+uu!
tWk"Z<
Q'`p1
wH!CHU
T#.]wj
&-kbg(m
`Q\=iq
C2X]=
lH/1%W
-[.D!&
:G \|&
1rn4=Y
<dJpbH
APoje2
*\<G.A
xUb|&3Y
pKx?By
L+f?>bJ
(A(j\ff
xXBV%"-KF)
fG&!V`
$3"D;`
q.bq^xG
F!:=yS
@~O (5"
y@GVQ!
L[hh3K
_'UC;
~TOw,=
x([6(~
@qA eLF
miqOR!`C
z2t~wtx
U{.6j_
"79lR/
zPk'fl
2;X||WS!
;=$_Sdb+{"
ejBal?
!"' b
M=4c:F8
rk6!Gmx
"e|k,y
;Ut.qMl
sG]@gd5m
>L(1jU
=9YB0z
YI\9,wR
o/F1$v
HO!bT'
;Q,J yK
z"+s2<
Wr37&t
V<k1BK
*"C<ya
)[l/%?&
vf&&=4_
Yor6H2
Ss/:!^
AJfflNp:
&+yB>^I
I-)+?d
33(&=a5
oBG-hS
M"NYAk
@%h^T^7
XZe8{
*r&s45Kk
VYCb/+
FY>(dl
*`q[j'
REP<RX
fM[6\9
-|/3W@y
4K<>rI <=&b
kYa+iJ
[Dzh#B
'`55#c
H9fFPy
]kc$NA(,+
/g)on=
P[Lo/O
0`:f_Dh
zk&e^S
k(?Ir)V
Lj[/@y
=mp9>R
W-J?54
(t-<OG
pC6WE$=
Ug`O.P
]rmj\E
[1s2{ip
v4.0.30319
#Strings
resourceMan
resourceCulture
NullableFlags
<PropertyNameCaseInsensitive>k__BackingField
<WriteIndented>k__BackingField
<IgnoreNullValues>k__BackingField
_propertiesDictionary
<JsonConverterOptions>k__BackingField
<IntegerConvertBehavior>k__BackingField
<FloatConvertBehavior>k__BackingField
value__
UseDouble
UseFloat
UseDecimal
UseInt
UseLong
Epmqnmbai.Properties.Resources.resources
get_ResourceManager
get_Culture
set_Culture
get_Ejitet
DeserializeAsync
SerializeAsync
IsValidJsonAsync
Deserialize
Serialize
IsValidJson
ConvertToDynamicJsonClass
DeserializeToDynamicJsonClass
get_PropertyNameCaseInsensitive
set_PropertyNameCaseInsensitive
get_WriteIndented
set_WriteIndented
get_IgnoreNullValues
set_IgnoreNullValues
get_Properties
GetDynamicPropertyValue
SetDynamicPropertyValue
get_Item
set_Item
GetDynamicMemberNames
TryGetMember
TrySetMember
get_JsonConverterOptions
set_JsonConverterOptions
get_IntegerConvertBehavior
set_IntegerConvertBehavior
get_FloatConvertBehavior
set_FloatConvertBehavior
FromBase64String
CreateDecryptor
CopyTo
Dispose
ToArray
GetType
InvokeMember
GetTypeFromHandle
get_Assembly
GetObject
GetProperties
GetIndexParameters
get_Name
GetValue
GetProperty
SetValue
TryGetValue
ContainsKey
get_Keys
rh111.exe
stream
options
cancellationToken
propertyName
binder
result
ResourceManager
Culture
Ejitet
PropertyNameCaseInsensitive
WriteIndented
IgnoreNullValues
Properties
JsonConverterOptions
IntegerConvertBehavior
FloatConvertBehavior
<Module>
Program
Epmqnmbai
Silent
Resources
Epmqnmbai.Properties
EmbeddedAttribute
Microsoft.CodeAnalysis
NullableAttribute
System.Runtime.CompilerServices
NullableContextAttribute
IJsonConverter
JsonConverter.Abstractions
DynamicJsonClass
JsonConverter.Abstractions.Models
DynamicJsonClassOptions
FloatBehavior
IntegerBehavior
Application
System.Windows.Forms
Object
System
MemoryStream
System.IO
TripleDESCryptoServiceProvider
System.Security.Cryptography
Convert
ICryptoTransform
SymmetricAlgorithm
CryptoStream
Stream
IDisposable
Assembly
System.Reflection
System.Resources
CultureInfo
System.Globalization
Attribute
CancellationToken
System.Threading
Task`1
System.Threading.Tasks
DynamicObject
System.Dynamic
Dictionary`2
System.Collections.Generic
PropertyInfo
ParameterInfo
MemberInfo
IEnumerable`1
KeyCollection
GetMemberBinder
SetMemberBinder
STAThreadAttribute
EditorBrowsableAttribute
System.ComponentModel
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
System.Diagnostics
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
GuidAttribute
System.Runtime.InteropServices
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
ComVisibleAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
AttributeUsageAttribute
DefaultMemberAttribute
CryptoStreamMode
BindingFlags
Binder
RuntimeTypeHandle
EditorBrowsableState
DebuggingModes
AttributeTargets
mscorlib
System.Core
WrapNonExceptionThrows
$c54ecad6-86f1-443f-928b-a4e973c056f5
1.0.0.0
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
AllowMultiple
Inherited
AllowMultiple
Inherited
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Ejitet
aHwaH/NykbjGrnG4IPCv0g==
rK/HuqXtV5U=
Tiuxg.Umkkafv
Tpqyydxarem
Epmqnmbai.Properties.Resources
Ejitet
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
rh111.exe
LegalCopyright
LegalTrademarks
OriginalFilename
rh111.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan IL:Trojan.MSILZilla.28600
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!E6F506F57365
Malwarebytes Trojan.Crypt.MSIL
VIPRE IL:Trojan.MSILZilla.28600
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILZilla.28600
K7GW Clean
Cybereason malicious.527f6d
BitDefenderTheta Gen:NN.ZemsilF.36662.Dm0@a4RlPuj
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.GMEN
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Emsisoft IL:Trojan.MSILZilla.28600 (B)
F-Secure Trojan.TR/Dropper.Gen
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
Trapmine malicious.high.ml.score
FireEye Generic.mg.e6f506f57365deb1
Sophos ML/PE-A
Ikarus Trojan-Downloader.MSIL.Agent
GData IL:Trojan.MSILZilla.28600
Jiangmin Clean
Webroot Clean
Avira TR/Dropper.Gen
Antiy-AVL Clean
Gridinsoft Clean
Xcitium TrojWare.Win32.ZeroAccess.BQ@4q1fa4
Arcabit IL:Trojan.MSILZilla.D6FB8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac IL:Trojan.MSILZilla.28600
MAX malware (ai score=85)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Generic.Simw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Agent.PQW!tr.dldr
AVG RansomX-gen [Ransom]
Avast RansomX-gen [Ransom]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.