Static | ZeroBOX

PE Compile Time

2047-11-26 11:57:47

PDB Path

}TL'ƒR¨uöܨ‡³ÏŠ†¸¥ëc&GúçÌÓ²"æ.‹f™Å‰0¸‚Þ´h§ÍÓ~2Þôd«µ˜ÔÕh¬y]nàò!²IÔ¡$í0ÂÒÚ39Ÿð‰

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000308bc 0x00030a00 7.50649403728
.rsrc 0x00034000 0x00000934 0x00000a00 4.37776371654
.reloc 0x00036000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00034400 0x00000348 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00034400 0x00000348 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00034748 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Microsoft.VisualStudio.Shell.15.0
ThreadSafeObjectProvider`1
List`1
mscorlib
System.Collections.Generic
get_Electric
Microsoft.VisualBasic
Versioned
Synchronized
CreateInstance
get_GetInstance
GetHashCode
set_Mode
set_AutoScaleMode
PaddingMode
CipherMode
Package
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
CallByName
CallType
get_Culture
set_Culture
ConsoleApplicationBase
ApplicationSettingsBase
Dispose
Create
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
CompilerGeneratedAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
StandardModuleAttribute
HideModuleNameAttribute
DebuggerStepThroughAttribute
GetCustomAttribute
DebuggerHiddenAttribute
AssemblyInformationalVersionAttribute
PackageRegistrationAttribute
MyGroupCollectionAttribute
m_ThreadStaticValue
GetObjectValue
SetValue
set_ClientSize
Randomize
set_Padding
NewLateBinding
FromBase64String
ToString
System.Drawing
VBMath
TransformFinalBlock
Microsoft.VisualStudio.Shell.Framework
System.ComponentModel
Microsoft.VisualStudio.Shell
ContainerControl
System
SymmetricAlgorithm
ICryptoTransform
Boolean
System.ComponentModel.Design
get_InformationalVersion
get_Application
System.Configuration
System.Globalization
System.Reflection
MatchCollection
CultureInfo
get_ResourceManager
System.CodeDom.Compiler
IContainer
get_User
Register
Unregister
get_Computer
IEnumerator
GetEnumerator
Activator
.cctor
CreateDecryptor
System.Diagnostics
Microsoft.VisualBasic.Devices
get_WebServices
MyWebServices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
JesusIsTheLord.Resources.resources
Matches
get_Settings
ReferenceEquals
System.Windows.Forms
CustomAttributeExtensions
Conversions
System.Text.RegularExpressions
System.Collections
RuntimeHelpers
Operators
DoEvents
Concat
AddObject
GetObject
LateGet
get_Default
get_Current
Convert
MoveNext
set_Text
RegistrationContext
set_Key
CreateKey
RemoveKey
System.Security.Cryptography
get_Assembly
#6'O$])
h)-!U)
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.WebServices
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.7.0.0
My.Settings
UseManagedResourcesOnly
$f1c2d7f7-0c68-41f8-9c76-37235de9ff13
Razor Live Share Services
$f1c2d7f7-0c68-41f8-9c76-37235de9ff13
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADPF8
r^M"
|U*NJk
({oAbax_[
K 8YEy
R=DpcW
6[5Py0o
}wEo{
u0ad-Pv9J
jWRQFE
h,,al
5AO$uc
eb>yuzUM
P,>nwS
o!nVZ=
R,vfHbq&
x9m]Z&
g>fKba(
*q8C+(L
Kw[\7)
rb:9OY
jXSI*Y
g\WD7e
70/6+Wr
G)$9xE#
=nMVpl
DwJBd@
w}%7<F
Gb7GAF
GiZ^C(
Vq|FcBt
zV*6^Ho
oP7Iy4
3:5 fF1
yl@jZr
XCfO9a
*_^g83
#M`+.._
W`MK1|O
26&,ZD
NkX$dB
ko>:|T
|!Jku1
T'SId-/B
e_3_^x
15=-V^*P
WVs[$d
Sg7VN6
-HIy{U!
?&R~py
}6k+.Nl
-gBOF=
M*epLI
l6R_po
fI=F)f
Sf]B%8m#
'wfGsQ
-~#^hDy
X|2Ew.D
Kiw,;tyy
R\P8D
n7=cG}
),n:a8
-U7~#o
F+eGhK
zuD%:
G6q$Q6[
a)-v8!"B
EJQaUK
+:p=a
T!mm^t+
Nx3(2+a
0$4zeAi
LSf-fY
C:KpZC
U=h)GA
lEsM"_w7
,onf!+
:Tqp'_
$!>-=s fUq
<m~3~1
',hbP_
7<[Yw|M-5
rW,[ZXjh
'/*}%g
<iQ<qHGl
{h;D3
wu9gKB
LY=toK
HFROQ`
lFX,igc?
aup|GHPO
&a( mJ
r$*59J
@hps,F
A5KF!;%
%@2|385
AB?jwq
A4O_}i
[(yi{3
@2Kc{=
I9|:id
\Rls/[
^PU&b)
RImA"6
5gn{(T
s<>< ,'3
aWEje`&q
xB56[F
qNOHcA\'5.{
$R"`Y#
BJAm/?
FU/~1u.
J]LLC0g~7
%!qlbL
\2O+4^
h4uE4;_q
t/Yu1O
ZU%"L
Y_kTb~=
"gEe9?
_x&,.=
yCHgm$~ug-
hSE0`u
ie 2@{
| tn-+
c/l0zE
'<vx`R
RKF[M]
! Aki#1
b,}77{
(tO}/7
9hBP|F
u$*Gb1ocn
,eAAJRP
OCoiHc
6"-'jV
*L>q+c
m#iIE-
>N,o"t
&A@ S&
pihMQmg
Or3B!=
N:^pw8
/+13Q5
B.@,t&PH
`j*D,s
!A;WTYy
H{?HA<
{Kc_@-
fs=(J`
q)|M*bJDl
oz}BN|
J3EcWD
Q.\aKm
'9O[h(w
J<TQr'
Wu/r<J
O%5ah>
M@AALQ
Y`4~4s
8(z0c>
i*hAeQ
-vvz17I
MPE.qT
1$~%zQ
P6Dxpb
G&!Jqa
f%Dby`
"' x 4
OZ,HmF
kv=tD4W
S2JbXi
RBW-0b
m`l}MB
%r%"*wE
#*Wm!RB77
N|`DG6
\wf38)
n;K /F
Umvs^q
YOP3GD(V~
g~]LJ/
q11rm$UUfq
-I*/"m
YRV?}bSD|
@FN(_r
JZ"IB8
b&I\zy
"9|:C.
XwYU=o
d[]bxf
!)7uM
P1=?_)v
Wo3\_u
qsZu?#(E
&*.'>F+
=ea8d:
3t[l@a
8Q}f~#
M!#8N:U
<#7fNQ
=GQ{~x!
U Neyw
='q=w/
peI\&1
S2b>mM
>%O87k
]K<dHnH
vBuUSn
5\{?~\
9y ;OF<q
l$-Ugh
uReL}\
Di:R_Ndg
*cPFNAa
O[>j
hIM<+3
B^}9NI
--ZF1.
asYG,8
QLp3H|fbw|E
Wt^ngj
L(pe45
R$o#xvQ
T>Aj[k
-D-4jm
~YWesZ
[Jt'IBgd
Z7LM3&
G%.4HIF
.U%mwB
4P$.U$)
'.{UGe}&
zro,:\]i
Hq;)k9^_
9QpZYB
c8/6#u
%o5xIC
qJR n94
f/Hl(,nz
+<I)|$h
}5[?W4
o~9uW<iK
Xug6G@
gyU]cJ
k; }jQ
,JPe|8
Qg#/N
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
capital Inc 1
230930004133Z
240930004133Z0$1
capital Inc 1
capital Inc 1
20230930004133Z
Manchester1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #4
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
230503000000Z
340802235959Z0j1
Manchester1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #40
r dAl
https://sectigo.com/CPS0
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
OYDeKCd
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
230930004133Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
JesusIsTheLord.Resources
Electric
[a-zA-Z]*
`!@#$%^^^^^^G`!@#$%^^^^^^et`!@#$%^^^^^^Ty`!@#$%^^^^^^pe`!@#$%^^^^^^
`!@#$%^^^^^^A`!@#$%^^^^^^ss`!@#$%^^^^^^em`!@#$%^^^^^^bl`!@#$%^^^^^^y`!@#$%^^^^^^
E+VPNTdKEe4QeRGwtVWGw0YJ3nq/1OTnysSIde9f/Do=
`!@#$%^^^^^^L`!@#$%^^^^^^o`!@#$%^^^^^^a`!@#$%^^^^^^d`!@#$%^^^^^^
`!@#$%^^^^^^En`!@#$%^^^^^^tr`!@#$%^^^^^^yP`!@#$%^^^^^^oi`!@#$%^^^^^^nt`!@#$%^^^^^^
`!@#$%^^^^^^In`!@#$%^^^^^^vo`!@#$%^^^^^^ke`!@#$%^^^^^^
InstalledProducts\
Package
ProductDetails
UseInterface
UseVSProductID
f1c2d7f7-0c68-41f8-9c76-37235de9ff13
Electric
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
eMExEraWU
FileDescription
EPeROsOdAz aGocA oTEVieAfUOU oqoYEQaP.
FileVersion
9.81.48.60
InternalName
EDEUeoOw
LegalCopyright
2023 eMExEraWU.
OriginalFilename
ProductName
UGUxIXE
ProductVersion
9.81.48.60
Comments
ABOeOio UDObeL esApIqIW ayajIvu IRIBoIuP.
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
040904b0
CompanyName
eMExEraWU
FileDescription
EPeROsOdAz aGocA oTEVieAfUOU oqoYEQaP.
FileVersion
9.81.48.60
InternalName
EDEUeoOw
LegalCopyright
2023 eMExEraWU.
OriginalFilename
ProductName
UGUxIXE
ProductVersion
9.81.48.60
Comments
ABOeOio UDObeL esApIqIW ayajIvu IRIBoIuP.
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.f81a2a
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.GOHJ
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Generic.mg.16e1b0fb578bc6d4
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Trojan/Win.Generic.C5498466
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36738.mm1@auT0uxji
ALYac Clean
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet MSIL/GenKryptik.GOHP!tr
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_90% (D)
No IRMA results available.