Static | ZeroBOX

PE Compile Time

2023-08-16 08:08:12

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005a9f4 0x0005aa00 7.77043544898
.rsrc 0x0005e000 0x00028824 0x00028a00 1.70218560399
.reloc 0x00088000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0005e130 0x000281c8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000862f8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0008630c 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00086638 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
T7K*]`
NhmDc9
myS+zf
N\@9IY
aHB%`uW
78Ml&I
pnePS{
i1<dVW
RiV;
Fi6J&K!"
? ;,H
`wkj-J
AC,FyY
#<2w!,
Y~bHJ"$
98%?FH
FzH/Nv
ej9K*s
##*D`n
mZ~6Bf
-3L6+:P
.@c-&?Pigx
1;~;I#
%q6a7\z
Nv=WE3Ea
f6$BgmX%1
j?QCc+"a;^
e)2':e@WP[;
XH^<qJ
mFh%H
-p{%jCO
)8TmV""
TV}em9
Dh`d'%
B:pd{1
DQ[Rxx
6rO>&?
EI]$m5"
I:>)>\h
f`asN`
?\ew`%k)
;&YW2
TSLE5:
-*LW%^
vy);L=
Bi.#I[
HB~tz{Pp
*10zN;
xV@;ZF
j+FI*LJV&
~gL*K\Cq
5o{:B*>
gck .
E*L Fs
ZMFF~
27K*]`
u'SoEG;
1wRiGq
Tvf,3\
NhmDc5
\\O9X1An]
^ kmv^
W>D-gA
{78Ml&E
yqUF-ea
i><uV?
1p",mp
A$B-G"
- 4,Y
`xk{-"
#.2x!=
n)_y|+,
98%?FD
gj9*K,
-!L9++P
\h.@c-&3P{gw
w0l|m1=R
|6ed=t~W&
P$BgmX)1
j-QLc:"
FWonUu*Mo
THL<~J
jO^TmV""
jBtxD,
3oPc"`
Vhod6%
' "??v
3oh$:pd{1
I:2),\g
;&UW
:7*#5:
'_iLw3
-;L?D*
9r)$A6f
j+Mv(~
yj_nCd
NWVzN;
j9FF*]J>G
**K\Cq
5o{:N*,
gck "
{FHyT,x
ZMFFr
57]*B`
T7K*]`
i:TMY
I>\\tTds
dw$a(
*V_&vEd
G/yhX<
e%?h}4
cr=E=9M
Jl=/lJ
4MEO`3e
GnMUO60K
hVIK
m;VK2[
O]or"M
]8rWBVf
8@hv]V
hVzf(@]
-T6N]<
bDi!,i
p+TZdq
4F'%Dv
$.D>OM{S*
GDcdgX7l
hEa N+
wLdm:`}"
&_g6j`
< HlXr
WG$mZW
HLCs+C
Q,p$PX
!@_g~hM
`$gL]F
1l<}t-+
B]^u1-
CzemUd
[$`!mw
s[67vf
#UKa?
JfvD0)[
i2bXow
Y`c*d?f
](xreF0
.z4\ZB
,P5]`C.
ziFI.hi
A%hlUJ
zH]#Uj
L.56I/I,
sbJFl8
rbZ&k+
)z<1n)
o3Jfjw
WPY_`.
|$oN<A
iJZY
^LnUAe
:%-=4ffk
E:$y{@
9qvmcoV
=3jysz
r,Z&af
`?E7y*
E1}e?
\et.s&2
E{pToF:{JR
DMe2Bu
t$%[QiZdpm
bjGje8
3~26"A
Czyk|2
^"hyb
BsLusBT
J2zQ0}
(xr3V
89:2}9
J9NhlM
aK-ov&Y
NB(xG?V*
\.[yDa
hX&`5%
%Wxl\X
%.EPo?NP
PR<{Ai
]:`WnddL
W7u2ej
uG+c`,
[Vu#8Ry
i%Q(<5
^"/>$9
fwHc]6
mc`RkP
ZfvZU
:'b@ \
|++D:Q/
$ete@>=
gN4uJ"
]=vd\ju
AVB$Q1?
d3GrRo
X-;Xc;
B$:Q_q
ggiQn-
8HS5c&
t\1w#7
2U>BF!
))$AtM
!ivdj}
Bz`Y9D
w"pUmoDm
?#"xbi
l$soG_:
fjI+0R
|.6'niP]
:lJ'_a
/;e;"eX*
q.'IBWo/l{
h";TPz
L~7P#R
vVM9hy:g(?
`ws'<
`q/R^Y
(/q_f3
Cu5}N=
ng@D,+
Pu+pP(
r# Tz-
B>5K?Od
XJj1~I
yP^YUm
s#*{r6
mp`37E/
BYLH7i
5P5}xI
ZGy1>G
qv_j]N
wYg+0\
K3mM|
hS8oz
Swf7'H
di;RP``
n8o*36
upA/4qQ
*1(4Jx
Vr::cx
"6i)z0
ZH4<C&ny
s$B8a!
a,:3w)cm
3$usG@HV
$gtJ6A
>`C'o-
{vObN2
_f;#Yr
785z&H3Z
W8}:,Z
;eiWH>j
w_n<:
B&5-{c
%}cH|q
?q$N5s
3]w| b
+pvzP
#"(Govp
$ryloh
'{$gy*
RF&?pJ
'{$gy+(
'{$gy4
p'`?bL%C
KCMlG1
k aVY0^
]a0[%2
@bW28
ZaG:AE
E=my`P}!
E(m``^}
m3*STS
e9d- `
(&evq/V
-OP?e'
Zd:,lq
3wNH3e
#O%EXnX
x~5o%I
kpg}TwA+
` V&Ak
{h)rYk.
*8AuCv|)/
Le)2fl
iF.jE5
Ix:j,(Ia
jr_~H@fE
#Vi\k`
k44IHR
XVY|xM
rR\Q#_
h^0fLx
p(v%qa
1(gkY^"
efl`S]?>
-`e%w;@8cK]\
aO;0<`*
Ot6K_.
<cFYI+
#3l.=a
x8_h6>
re(/(v
yC'mcc}O
!g{|g$
jDm*G'
VHg0GaH
OT=]tt+c*
]^dtD6#T%
iG}:5q
|Faj9~S
K)Bor@
-6/mq'
tCZ.-"
1}}9f1
6=]mCE
KRA)CwFO#y
F_IB4grh
o8<[<?
W7U%[ec
it^liK
JLysEh
48u?0
fSO?nvZck{
$*Nj`$
~;$'jnv)
aVee0`
WiSX]Q
*&\:V|E
MMenSY=
2}uk?~
~<U$r?
M'.[@s>z
-Z!{.`
<'<X%j
.x&`^0
&+]'"4
0aLj2L
fz:]!o
z!>w"
2jD[KKM
6K5i}&
T&LPQ^
\"x$Sg
76aY"ip~^t`
)p6"7I
52ev9'H
BftD6+87Ba
;G(VkVg
'jPj^w?[DDd
t@DO?5Z
}WtOl#
a]/9z|
#W|fNH;
2dXL*6
0>D,G}
t?QdNu
XW`2!,^
.<2H&\2
DqLfZ8d
~Ky,K(
Guw,X"T`*
2R2:/kl3
He4Gs h
lH2H}b~
6.:?Q}
h*4EVH
<NIqC#$
lA<?<%
h}=_c1
s&eC7y
Nli0K2
rwvyWU
:rAxs
B-msC%
%CVE+m
|5z:Sq
x}P=RR=#
v}%]?%
R*#wrE:k
sSfsz&
^nPrp>
W~,TU\
r*LS!@'R
5'asV
#*1tez
YLG"\$
WuIxg@
r%u{uP
tDt)Re2
3x-Y c
EA`@bU[
*15J\(`k
T8't20
zy*m1|
iD7rbG
9J?y"4@5M
8Y@B5wG
-ej>'
#;)#ZO$5iK
X(;Sb
r!<hta
|+rX4L
-$oTt*
HTWFP-O
b1HLQy
~"jce2
_^;(G%
=\ef}L\
#H6xsTS
Y-G%F-
=*)3"WL0u
94JC-<
J9.5X)
]F.DWc
x^H$\^
Qzi0rR-<O
[RI52s
2s?d$rf
=Gs5vV
xT9M2
jK#c&6
B:ugKY
6>>[q(
nK17a0
1WulYe
{iy`OWAy
oGy*tH
F)k8Znq
FNk'`Q6
v4.0.30319
#Strings
<seatsLeft>5__10
<>c__DisplayClass13_0
<>9__3_0
<All>b__3_0
<>9__4_0
<GetTimeTable>b__4_0
<PortModels>b__4_0
<>c__DisplayClass4_0
<>9__5_0
<CanBook>b__5_0
<GetAvailableCrossings>b__5_0
<>c__DisplayClass5_0
<>9__6_0
<NextFerryAvailableFrom>b__6_0
<>c__DisplayClass6_0
<>c__DisplayClass9_0
<GetNextAvailable>b__0
<DisplayTimetable>b__0
<>9__3_1
<All>b__3_1
<>9__4_1
<GetTimeTable>b__4_1
<>9__5_1
<CanBook>b__5_1
<GetAvailableCrossings>b__5_1
<>9__6_1
<NextFerryAvailableFrom>b__6_1
<>9__9_1
<DisplayTimetable>b__9_1
<ports>5__1
<GetNextAvailable>b__1
<PortModels>b__1
IEnumerable`1
IOrderedEnumerable`1
IEnumerator`1
List`1
<>m__Finally1
ToInt32
<>9__3_2
<All>b__3_2
<timetables>5__2
<>9__2
<GetTimeTable>b__2
<CanBook>b__2
<NextFerryAvailableFrom>b__2
<GetAvailableCrossings>b__2
Func`2
KeyValuePair`2
Dictionary`2
<>9__5_3
<CanBook>b__5_3
<allEntries>5__3
<GetTimeTable>b__3
<NextFerryAvailableFrom>b__3
<GetAvailableCrossings>b__3
<GetAvailableCrossings>b__4
<>s__4
<>9__5_5
<GetAvailableCrossings>b__5_5
<>8__5
<GetAvailableCrossings>d__5
<>9__5_6
<GetAvailableCrossings>b__5_6
<origin>5__6
<destination>5__7
<ferry>5__8
<bookings>5__9
<Module>
System.IO
MainWithTestData
mscorlib
System.Collections.Generic
get_Id
set_Id
get_CurrentManagedThreadId
<>l__initialThreadId
get_TimeTableId
set_TimeTableId
get_OriginId
set_OriginId
get_DestinationId
set_DestinationId
get_HomePortId
set_HomePortId
portId
get_JourneyId
set_JourneyId
journeyId
<Id>k__BackingField
<TimeTableId>k__BackingField
<OriginId>k__BackingField
<DestinationId>k__BackingField
<HomePortId>k__BackingField
<JourneyId>k__BackingField
<Name>k__BackingField
<FerryName>k__BackingField
<Time>k__BackingField
<ArrivalTime>k__BackingField
<StartTime>k__BackingField
<JourneyTime>k__BackingField
<Arrive>k__BackingField
<SetOff>k__BackingField
<JourneyLength>k__BackingField
<Origin>k__BackingField
<Destination>k__BackingField
<Entries>k__BackingField
<Vehicles>k__BackingField
<Passengers>k__BackingField
<SeatsLeft>k__BackingField
<Weight>k__BackingField
<OriginPort>k__BackingField
<DestinationPort>k__BackingField
<Ferry>k__BackingField
DoCommand
command
TimeTableService
_timeTableService
JourneyBookingService
_bookingService
_ferryService
FerryAvailabilityService
CreateInstance
get_BigEndianUnicode
GetTimeTable
GetNextAvailable
available
IEnumerable
IDisposable
DisplayTimetable
timetable
RuntimeTypeHandle
GetTypeFromHandle
Single
Console
FerryModule
get_Name
set_Name
portName
get_FerryName
set_FerryName
get_Time
set_Time
GetFerryTurnaroundTime
get_ArrivalTime
set_ArrivalTime
get_StartTime
set_StartTime
get_JourneyTime
set_JourneyTime
<>3__time
ReadLine
WriteLine
System.Core
get_Culture
set_Culture
resourceCulture
System.IDisposable.Dispose
DebuggerBrowsableState
EditorBrowsableState
<>1__state
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
IteratorStateMachineAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Value
get_Arrive
set_Arrive
Remove
FerryLegacy.exe
Resize
get_SetOff
set_SetOff
Encoding
Booking
booking
System.Runtime.Versioning
ToString
AvailableCrossing
Search
get_Length
get_JourneyLength
set_JourneyLength
StartsWith
CanBook
tootlOl
Decimal
op_GreaterThanOrEqual
System.ComponentModel
PortModel
Program
System
NextFerryAvailableFrom
resourceMan
TimeSpan
AppDomain
get_CurrentDomain
get_Origin
set_Origin
AddOrigin
origin
get_Destination
set_Destination
destination
System.Globalization
System.Reflection
NotSupportedException
ArgumentNullException
CantFindFerryException
HolaZXo
CultureInfo
WireUp
CommandLoop
System.Linq
PrintPortHeader
StreamReader
get_ResourceManager
PortManager
_portManager
FerryManager
System.CodeDom.Compiler
ToLower
IEnumerator
System.Collections.Generic.IEnumerable<FerryLegacy.AvailableCrossing>.GetEnumerator
System.Collections.IEnumerable.GetEnumerator
Activator
.cctor
System.Diagnostics
TestCommands
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
DebuggingModes
Ferries
_ferries
get_Entries
set_Entries
_entries
FerryLegacy.Properties
TimeTables
_timeTables
get_Vehicles
set_Vehicles
GetExportedTypes
FromMinutes
GetBytes
GetAllBookings
_bookings
GetAvailableCrossings
<>4__this
PortModels
System.Collections
get_Passengers
set_Passengers
passengers
_boats
_ports
Concat
Format
AddBoat
GetObject
get_Main_Project
Select
System.Collections.IEnumerator.Reset
get_SeatsLeft
set_SeatsLeft
PadRight
get_Weight
set_Weight
FirstOrDefault
Environment
System.Collections.Generic.IEnumerator<FerryLegacy.AvailableCrossing>.Current
System.Collections.IEnumerator.Current
System.Collections.Generic.IEnumerator<FerryLegacy.AvailableCrossing>.get_Current
System.Collections.IEnumerator.get_Current
<>2__current
Convert
<>3__fromPort
get_OriginPort
set_OriginPort
get_DestinationPort
set_DestinationPort
<>3__toPort
ToList
MoveNext
System.Text
TimeTableViewModelRow
OrderBy
FerryLegacy
TimeReady
get_Key
FerryJourney
get_Assembly
PowerSupply
SelectMany
get_BaseDirectory
get_Ferry
set_Ferry
TimeTableEntry
op_Equality
op_Inequality
_boatAvailability
FerryLegacy.Properties.Resources.resources
WrapNonExceptionThrows
FerryLegacy
Copyright
2014
$9caf382e-7952-47a9-84da-7453c569aeaf
1.0.0.0
.NETFramework,Version=v4.6.2
FrameworkDisplayName
.NET Framework 4.6.2
8FerryLegacy.TimeTableService+<GetAvailableCrossings>d__5
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
Main_Project
#-#5#9i
#$!%(
!"#Q
\data\ferries.txt
Hang on, why can't I find a ferry journey from port Id {0} at {1}
destination
awdfawhtnfgjgjhjgheea
\data\ports.txt
Welcome to the Ferry Finding System
=======
Ferry Time Table
list ports
search 2 3 00:00
book 10 2
book 10 10
book 10 1
search 1 2 01:00
book 4 2
book 6 8
search 1 3 01:00
search 1 3 01:30
book 5 16
book 16 16
search 1 3 00:00
list bookings
| {0} | {1} | {2} | {3} | {4} |
search
Ports:
------
{0} - {1}
Bookings:
---------
journey {0} - passengers {1}
Commands are: [search x y hh:mm] book, or list bookings
search x y hh:mm
book x y
list bookings
list ports
Book is [book x y]
where x - journey id
where y - number of passenger
Search is [search x y hh:mm]
where: x - origin port id
where: y - destinationg port id
where: hh:mm - time to search after
Booked
Cannot book that journey
[{2}] {0} to {5} - {1} (JourneyId : {3}, spaces left {4})
hh':'mm
Departures from
--------------------------------------------------------------------------
Destination
Journey Time
Arrives
\data\timetable.txt
FerryLegacy.Properties.Resources
Main_Project
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FerryLegacy
FileVersion
1.0.0.0
InternalName
FerryLegacy.exe
LegalCopyright
Copyright
2014
LegalTrademarks
OriginalFilename
FerryLegacy.exe
ProductName
FerryLegacy
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.Common.4B9CC7B8
Lionic Trojan.Win32.Crypt.4!c
tehtris Clean
DrWeb Trojan.Inject4.60249
MicroWorld-eScan Trojan.GenericKD.68755300
ClamAV Clean
FireEye Generic.mg.88c3f4ed7f993535
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.68755300
Malwarebytes Trojan.Crypt.MSIL
VIPRE Trojan.GenericKD.68755300
Sangfor Trojan.Msil.Kryptik.Vybn
K7AntiVirus Trojan ( 005aa0861 )
BitDefender Trojan.GenericKD.68755300
K7GW Trojan ( 005aa0861 )
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36662.Gm0@aqnRDij
VirIT Trojan.Win32.MSIL_Heur.A
Cyren W32/MSIL_Agent.GFX.gen!Eldorado
Symantec Scr.Malcode!gdn33
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.GMVY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
Alibaba Trojan:MSIL/GenKryptik.01ae3316
NANO-Antivirus Trojan.Win32.Crypt.jynhyg
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:Iz+FLet7efv/HU3rORfPLg)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.sbivm
Baidu Clean
Zillya Clean
TrendMicro HackTool.MSIL.GENKRYPTIK.USPAXHG23
McAfee-GW-Edition BehavesLike.Win32.Generic.hh
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68755300 (B)
Ikarus Trojan.MSIL.Krypt
GData Trojan.GenericKD.68755300
Jiangmin TrojanSpy.MSIL.cak
Webroot W32.Malware.Gen
Avira TR/Kryptik.sbivm
MAX malware (ai score=81)
Antiy-AVL Trojan/MSIL.GenKryptik
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D4191F64
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Crypt.gen
Microsoft Trojan:MSIL/NanoBot.KA!MTB
Google Detected
AhnLab-V3 Trojan/Win.Injection.C5471767
Acronis Clean
McAfee Artemis!88C3F4ED7F99
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall HackTool.MSIL.GENKRYPTIK.USPAXHG23
Tencent Malware.Win32.Gencirc.13ecafc9
Yandex Trojan.GenKryptik!swXbHcbYNXg
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/Agent.8DF3!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.372660
Avast Win32:PWSX-gen [Trj]
No IRMA results available.