Static | ZeroBOX

PE Compile Time

1986-02-13 08:04:54

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00051db4 0x00051e00 7.6899312315
.rsrc 0x00054000 0x000003d8 0x00000400 3.34630286961
.reloc 0x00056000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00054058 0x00000380 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
O-?T)g
952\}=
HI\[I-w
Nu@uHu
?t,t/t
BLSL]L
O=Y=c=
LLKLvL
#B.BaB
\5Ome5
9*3*v*U
5181b1I
xgrgzg$g@o
*+.+-+
f*{UoCo
fk{QoJo
fY{SoGo
fi{DoHo
(B-B=B
[`FnRuR{RnR
ct]~]k]
nDs$gbg
nNsjgug
n_sqghg
~_q_F_"_FW
HqU\A]A
HdUWA_A
XJKJdJ
UfAfkf#n
ycdupdp
9s=s`sRW
w)p)*)
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
2Q*K`u
9K6psw24
tXf='m
E,zQO@~
KvLy(-
D1<N;q
# -5/b
_?i;}4}
zw/$U@[
cxrwtM
VsLpT*^
<tnSO"Iw(IHP
KEV%pM
\K:6V_
q.vYEB/
mb-ueO/>QY
Na#(n_
X\]ozJ
$,Z#H_&
%mZ#z
`$~{u
^n0}H?
S}CNH4
i(~hz
1Hm[MCB
x:g9I.
?xk*O;{r
?im.,<h
C%^l#e
GEGvjh
KM aW<
QSl(yU./
m+EXXx
y7czfU
P> sVg
(qh}>Rq
nIm8~4I
*/$'Q|'
Kou|\?
b2WjZ5
v0P&iW
&j]u+#
9p$I"$
`rH/S!p
`FSo#Xe
Df0sFg
^PMp8%
JU][kz%I
aYH%P{uG
y.ADLg
1^D>Jv
e?.cEi
dWasxx
IX(N6h
VaDgDS
%,>AE!
^@76
B(~n3T
ji~(_'
RZj.C-
|V5qb/
UY\1"'
Xt~ooQ
>Jl5|G
"Z`bX=
P&>(c>P
/Q,hf
%`uc7u&
D5A[,Z
pnyD4g
hL&.`w
kd:1-zY
q9c#BNf
:A{Vc9~
\">:jG
~Of;\Zr{
!TaWd9JK|
cYdWXpr
BxgiP}(
savioQ
yUI1V/
SjQ+dU$
J=r=,0
4]aAu7
.b3OJ_Qw
_VRe?i
M+4Wub
~?LTgaq
[{0.FG
kg3s]"
9+QP&y
C?N,zp
VB>-%}
.'~__e~
0Hrw"Q,
E@R8d,f
He{Bf7
Q0,$rq
Ag?*4g
a*4wt5
7k`"\e
eX*K~<I$f
!?Up&\n
.<AE&7
8g{Y"&
|i}8!rB
%JE#s1-O
T',%L}
9Q6?O^
Z@($hf
Ck\T|La@
G_k~?^~
8D])<(M{
-M2M:+
] _sym
F9Eb-[
fHPxCB
1TGa70(
zR<:.{W
VK"/ld
HAudhL
73gQ]2u]
ECttc>
uB0g8/."W
S[`^}V
CI6-XG#7x
=2o|=
^cN}=
C&]P8
BMp4p
3v@?IE
,yGyKO
O;%wh[
1a;!8I[
N|y9hq
a<[t{i
<mLn;'
5X$V3s:# :
Iv:].A5sA
^]<zHz
$-$WNd>
xfx&Q[
8@!,fNXY
[3_GJ!
+he-WB
ktXRJER
p[7"sZ
k#.8ES
`bNr4+
:b3Pg:3
o6Y%Yu
e!KV~8k-C/^
F$\]<18!I
&O%d\X*6
r+/hv
b3}f-U
:M>0OWh
15l0o,
Mp)^lHgoC
E?EQG*cb
mt[(s_
~T`XTu
\En>Le
I<6u\|
q;]sC!g
UD(B)}p
5TdG+<b$c
n1PNT5
#~?GaU
U-(H8h
F>-gr(
=4QNUjC
s' .JX#
W2`R'.
u2nyD~YdC
tS2MXJ
7E'47o
@>v0}#+
6 fExJn
$4w>kO5
h@Vp/l#Ql
&%|?X)
vPkWyf
4zn)L4
c=|F<M
ZC_]Z.
*uO^l`
d4NLnJQ
V7V< ^
5Fz>=uc
.G&l-P
vV=$y=
MQ^c~\)
A,g(+*
Q'?b.b
-9r&8c
=c%k*z
Z&y+sG
h}P{DT_
8VogD*
Fd?3@[e
~oS%_n
t8f%
|WX&'D
!ki%px
Bk2UPG
nu-LCf)`
.i1p9b
BG,jZK
^UjC/A
cq3ll]
@kmX"]q
YL+da~
^{G!ii$
^&^%c`
k=g2r
5:g&N-
)V9E,!
5P^qS?
;QS.7<
Wv>q4V
S{G{~"=
<d5;;}q
=]Wl+p
ql=YCy
Z_&JM:
r*`se
xM6(L(
^9s2uC
z-J73~
jU]& 9
U5@Xs
NvJ@2:p,
.r.2(w'r
As#/y
^fwuR=7RuA
e};"3D
>r+O5r
pHQa;P
C6^)dO
-1'~G_W62
2G6J![
l:2'$7&u
3rD7+lo
#x9BSO
l4#gf42"3#}vv
vvf3._Q
r%Ro{9
D91{p
qm{3s9N
nN^NtjB\B]
QQBr]p
nEYlOA
\t^c>mlbio
OUi5Vp?Sw
kSkfM'
8Gxk%A?|3
8Gxk%A?|3
I}V"wX
uI\PZ.H
?i]Wiq
! ;>ir
@4Bryo
7N;L:!
u=99hb
=O,V8^
*5jWha
B{$vUN
i@`R2<
wMObo%
%goLKd}
yPb$x*2"
#@P8X,
4hTS?x
kG`e*hB.c4W
s/R\IG%t
LxT\429
\^L!<\
}3X"Fu4
,8{ZP>
?"*VR}
Vli\ ]*L
"pD,kB
["@R&[a
{a9^ELw
+sAb F{
D8^Q<N
`TN/EyF
T,_/m:DY%x
AM0=C1C9
^JL/(b6
o<sM?n
#tKj5W
G|lCvm\
IY()vl?
s|kG|)
1uWYcW
l1q%c9
s+f2sdPvF0@2
<3<]{$su
sbip)_P
b'4&n0X~<
3rs@&*
x>~#4xa1}d
aXa-@v
v-)RLMN
NkJa2mz
XjQ>hL
.8:/#54
(Q,O-0
]/hk%$
'!^TGK
T]&20|e5"
V#deT}re
GuD=E~
V"x=x`
lZN"fA
Lvuf9
^p\el?!
K@:4.]ua)
4Q]lZf
gT.~qO
S<Tpx"
Q%}E^`
JaGn1"Z
4@1$1th6
WdmAE_1
&1mB20
z*>C;I
@~*!XI
G{p$TW%
2&lGmu=ETdP
c=n),4
Tygh:9
dDY]!Pf!
yY:BC$
$'UxnB
i`pL'?
Q*|zY*
Rweuz5
j}o-K&
&&qHr}
iIMTt4
SW!a4v<JQ
R;C}2"
i-.aX;
iJ2p"(3V
P"YGx!
LGH,g
^C*HJ,aDl
b{bCqL`
>H)LXr
xfFX{~Bj']
*bly+B
~2d\n$
O#j]G)
<=Fool.
^;p-l6W
{Gb&tw
)1J@"Q
<SR~^3
wC`TV-
*Ws{Tj
fOb8oz
y,khGhx
^N$lY
{J^77w
jwd$ &_
v4WW?,
UoyKeh
wC#9N2vw
2jsf^4R:
m;'-^g
87e8q
f4Z_OV\
$5vC+d
?>X@<H`[(EJ.w
0rtCg3
%X+E,9
c?,'{v
.Wmm?Q;
IW*RId
s~}Z.\
C(IYq
YyD/5}3-
Ky&'O3WV
R~R.pr
9`wU$B>T
f04A@|ya
[7Bx2/1
tWut,#
<-Ox6@Q
VuPE5C
U4[hwMH
bL8; ~
{Kg}M-
pD*d(zw
/I{<!~
R?)1,GM~
W1\B1[
fq^B 0
B7O/%-
ZWw:C+
l,/5NoQ3
zYe96k+
pX1i-A&
iN:;9@;J
`e]+Ae
-dLHBi-j`c7
:,L(>|*'>y
?&]J(Z
\t;1,$f
T#wmAVgL
k@S1`-
l L \u
$m'z^-
zLz\uF
hUn:4<
Vk+'L%
uZ%b&+e\
A.v$$h
7377777?
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
"$,0wT
M(+"*
{jlN*-
'vT3<_"
c=wb'a
5a~#$6
;-1%u-
#0C<V:y
2ce}Qf-1
q,9lhs
M*1`xj+
9eZRG
X&^Kt[B
fG2JZI
K'>ddQ
csg9w_n
Z:}{X'[fT
B_oN)*
E78.VX_
v4.0.30319
#Strings
Nullable`1
IEnumerable`1
IEquatable`1
IEnumerator`1
List`1
IDictionary`2
get_ASCII
System.IO
value__
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentManagedThreadId
get_IsDisposed
Synchronized
Append
Replace
CreateInstance
GetHashCode
CompressionMode
get_Message
AddRange
EndInvoke
BeginInvoke
ICloneable
IComparable
IEnumerable
IDisposable
Hashtable
ISerializable
IConvertible
Double
RuntimeFieldHandle
get_TypeHandle
RuntimeTypeHandle
GetTypeFromHandle
Single
get_Name
get_FullName
GetName
AssemblyName
GetDirectoryName
WriteLine
ChangeType
ValueType
GetType
System.Core
ConsoleApplicationBase
ApplicationSettingsBase
Dispose
Reverse
MulticastDelegate
InternetGetConnectedState
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
IteratorStateMachineAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
GetObjectValue
Remove
NewLateBinding
Encoding
System.Runtime.Versioning
GetResourceString
ToString
GetString
ToLong
get_ExecutablePath
get_Length
AsyncCallback
ConditionalCompareObjectEqual
System.ComponentModel
LateCall
wininet.dll
Control
BufferedStream
FileStream
GZipStream
MemoryStream
get_Item
set_Item
System
Random
ToBoolean
System.ComponentModel.Design
System.IO.Compression
Application
System.Configuration
System.Globalization
System.Runtime.Serialization
System.Reflection
IOException
NotImplementedException
NotSupportedException
InvalidProgramException
TargetInvocationException
InvalidOperationException
get_InnerException
CultureInfo
MemberInfo
System.Linq
StringBuilder
ResourceManager
ToInteger
System.CodeDom.Compiler
TextWriter
Computer
ToLower
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
Activator
.cctor
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
ade8c9ae73987b.Resources.resources
Be.Resources.resources
System.Runtime.InteropServices.ComTypes
GetBytes
ReferenceEquals
System.Windows.Forms
Contains
Conversions
System.Collections
RuntimeHelpers
Operators
Concat
Format
IDataObject
SubtractObject
NotObject
IReflect
LateGet
LateIndexGet
LateSet
Default
IAsyncResult
Environment
Component
get_Current
get_Count
MoveNext
System.Text
LateSetComplex
InitializeArray
ToArray
ContainsKey
get_Assembly
GetExecutingAssembly
GetCurrentDirectory
A5A5695CD;AJ5<G
464@7?D>JEF9H?73DD<IDF2G
5JF;JC32E=D;675
WrapNonExceptionThrows
$ae28117a-4ba0-4093-a283-682e1b2dc5b4
1.1.1.1
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
!Copyright
1990 5JF;JC32E=D;675
"Ny4x7YCk26Kts1EJr59Gog8S3AdMz00Dna
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.7.0.0
My.Settings
IP.W+W, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
GetObject
_CorExeMain
mscoree.dll
HHkdskjldfskjjerAasdfsge
003b02765f
83bfacca0
VZ ]!d"r#s&w'}(~
)(/.0/1/21314151617/8/9/:9;9</=/>.?.@.A.B.C.EDFDGD
9ACDEFGH
IJKLMN
OPQRSTUVWY
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
A5A5695CD;AJ5<G
CompanyName
5JF;JC32E=D;675
FileDescription
464@7?D>JEF9H?73DD<IDF2G
FileVersion
1.1.1.1
InternalName
skx111.exe
LegalCopyright
Copyright
1990 5JF;JC32E=D;675
OriginalFilename
skx111.exe
ProductName
464@7?D>JEF9H?73DD<IDF2G
ProductVersion
1.1.1.1
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.aa97e84ddfed87f9
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fc
McAfee Artemis!AA97E84DDFED
Cylance unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36738.um0@aiDnbPn
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AJXI
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.MSIL.Crypt.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.89 (RDM.MSIL2:Mvya73ovJTsepqxNyqoWBA)
Sophos ML/PE-A
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan.MSIL.Crypt
GData Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan.MSIL.Crypt.gen
Microsoft Program:Win32/Wacapew.C!ml
Varist W32/MSIL_Kryptik.DSR.gen!Eldorado
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Malware.AI.991493986
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Kryptik.AJMF!tr
AVG Win32:TrojanX-gen [Trj]
Cybereason malicious.ee0183
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.