Static | ZeroBOX

PE Compile Time

2017-09-28 01:15:23

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005d334 0x0005d400 7.55295731711
.rsrc 0x00060000 0x000003e0 0x00000400 3.41461557532
.reloc 0x00062000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00060058 0x00000388 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
y/k#$g
5Ta=3"-s10f
\|@|\|Tpk
(I'I/IMS
,3'3?3
--o(o0o
x0{0o0
x^^Z^~^
zUyUYU
W,cB@Kp&Q
m$YQzlJ
Yn^nZnfu
'!-&---
7<xX/
-30i4i)i
zBN6m5]M|
znN0m(][|
c/ )UU
3>G)a
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
9aOnR#?]
HcP\2
vE;*L[
!BJ**f
o5[6GQ
beG+Tl
a&iFw`f@
z 4+Q.
r7?DBf~
j{uK7m
]<]/#A
IvsQ\W
Ie1f_<j
[1D'@$
:8ws>x
VY5M&r
:~Rn'5.
Yfv[`Hp
e clz+
:qb9JM
]qJ="L
g s:S0!
8j<yW3
]xf]qR
;nVi-1
B@~$4e
-K!P7>
5T4Y0g
#,BvVX
$|uE<:P
U>Bg}L
P<)^qa
0'h^3Y
l>O*7IKJ
h,+}];C
D.%a'0&}
)'.2RO
EPI*cl
BZQr JJ
^D4BBt
/|J"cH
0yWiO|
k?@+E&i
Tc~ZUIW
E]\L{&<
s$@g*C-
CjnY9'
-1ch^P?
EEP0yA
R]y%wm
\sS]3
w><uj*f
VgaJ>V
{"rb_|
j+kyp>
34`06'
7RDk~Gp
>@J(-!
+!+N##
,c[-g
%t2+W#
u,~AHmR
l6JLy)
|krg^N/
jh<+}@
@E@|)3
wE8_=O
;>'0B51
En,XI0J!
&/%G't
*t$gSx
DqrGyy
p;z+..'J* dx
lWcpFZ
dmNnNF
xhQ%II
~Ls'!7<
$9]T:o
VZUaz-
( SZDRh{
i;J5?:
8&U)YZ
1d^n%q
x,$gr
Y3j(k;
SiuJK;m
5}ngJz~i
(0;A5G
P~0UE&yqg
\vXDHRa
>_dW>uP
#\sM3>
XgEPir
&d@'?(*=b
&<~X1Z#
tEkqN"
TUcGH9
d}{b2!
V<b-V#
q*L[2Q
%i`1<B
scN%uV
Jj_S?Z
nyHe^Z
TQy|b`
Hp5Szz
b77X%q
h2l09n
7 O]Ua
zK#OlAv
'bu(u
$jVW)5R
csDw406
4}_X34
zcey8:
h:*"CM
mkj1kX
unVh1$cS;
U@N'"|
.8\~Xx
bt\(dF
u1.zoDj>1V
:D:}b7YY
~7M5Rc|;
Ay`bE0
ga15Wv]
R,5uR|
a}m5dh
l)WXVxOx
P~%U+($0
m=s.e-
V\> {
]f&y)YF}
;"SEOnm
]x|WM8&OM
k\;c0
$XIEI$o"Z
G/=7+"
V+Fms*m8
{bs}k5
_2Uk&>>_,[5=I
bH>lY+
'$a%EaVA
%H/0,H
_Q*UH@
Efm6Q&0
CXGyA
Q6,k|6
uf76(=
OM*Rch
U\)vO
I(rpVkK
S;g1-A
HYBzS"A^
l'Ht6<
:5P,K6
[9X3.
Y^l|q~
-dia*%]
aVx,2Y
2_PfL6
7"0|Fp
x]B'{%
Zs1qRD
ao{bt:
8 J}^[z
ynnduFA
=o2GbQ
74px+
Su=>9!
2!F$"u
B|9Kn~
nHGW\85
?77b|O
A4ssdX
8h7kJR
-3B6Hm
m?Owo,U
#<xtx~
j$Ds*r
!!7$ND
CGoU>,
2o8RN.
}jZ39`
DT=Lc=
M6yc*/
.G0dR}
yp")8{ae
wtmv@e
j$6Z\n@
^i!oXY
?HXP K
z/>p5B
i#bbTIh
oR$"D8+v
pGER/'1
E #A%o-
`GjC'F!"
4rkua
S)g\@B
W~rl|K9
S]`j;-
u%#S/+\)
c\:S=j
o|fZVbvU
n_|E}vT
K.ipR+
3>F8Xa
dN\i%T@$<\
G*sPNz
8X.-XzN
s?DW,35/r/
5e >\G
~{21Vm
?C_/0k
sF3#G#
BF4RlQ
>.f,do
t&y9<H
/R52g#
-{,D{T
N;xAU:
LQnl|HX
=tthD=_
4P >d?
*Cv%.v>-8O
vD;5~/`
<$v6tou-
e}Xef
d|k<+mZ
]<XH>zB
y.Ydp2
zfp8x2E
ZZIyV{
eNRgDJ
Uh5fgibd
`X`mF,
3Ls`.J4w8
3Ls`.J4w8
Q7IR5
Bv])|S
~BW[Q%C
4bV\bz
*+05by
K?Iyrd
<E0G1*
6D']3U
!>a\cj
Ip/}^E
DsE%t&
bKkY97
|FDid.
.ldG@ov
r[i/s!9)
(K[3S'
?c_X4s
`Lkn!cI%h?\
x$YWBL.
Gs_W?92
WUG*7W
v8S)M~?
'3pQ[5
4)!]Yv
]gbW+V!G
){O'`I
P)KY-Pj
pj2UNG|
xJi+Mp
O3UZ7E
k_E$NrM
_'T$f1OR.s
JF;6H:H2
UAG$#i=
d7xF4e
LwgH}fW
Y<%^%t
BR#"}g4
-Fg*,
xw`Lw"
:~\Rh\
g:z.h2
x m9xo[}M;K9
787Vp/x~
xib{"T[
i,?-e;Su7
8yxK-!
s5u(?sj:vo
jSj&K}
}&"YGFE
E`Aj9fq
SaZ5cG
%31$(>?
#Z'D&;
V$c`./
,*U_L@
_V-9;wn>)
](on_vyn
])s6sk
gQE)mJ
UqZO[
U{Wng4*
@K1?%V~j"
iR\@[t
?ZVgQm
tl_%uzD
X7_{s)
Z.vNUk
AjLe:)Q
\ofJNT:
-:fI9;
q!5H0B
~ f8tP
Ku!*SB
Lp{/_\.
9-gLf~6N_o[
!oLta|
h6e"'?
_rlc12
oORV*[m*
rR1IH/
/,^seI
bk{G,4
Z!wqR!
Y|n~q>
avd&@-
--zCyv
X\*j?}7AZ
Y0Hv9)
b&%jS0
bA9{)#8]
[)RLs*
UH!CA'jOg
ipiHzGk
5C"GSy
smMSpuIa,V
!igr I
u9oWe/
D(aVL"
O=g(R
76Mddg%
U0{&g=\
":AK)Z
SZ".w
7XYuU8
|Hk_]&
!\xp_a
ZtDoY
mDi3dq
pW8tS)!
r'`cLcs
tw#w6
UE/gR+
pAU<<|
a|o/+-T
^S12x
}?\\4'
^dr@nc
|H(2E9}|
9axmU?Y1
Cf0,&Ul
E~~QgtK
m?QTD]W
?\ L;t0
/>}H o
45SK7CkP#NA%|
.S N'2
h4',p}
%\ff4Z0
B\!YBo
xuvQ%W
RrO$>v8&
nz<Ul
th`*%+
(s?'yCf
@r-,D8\]
YuY%{y
2k|^/I5_
m;?JKwrj
P<Is9$:
7&Ds=KZ
#L[t*#
]~[N>H
^?Pc|FC
iG30+u
p@lvF&
{O!o#q|
.qqM[
$Bp7*u
pBS&g
Y4":'LFu
\:WI:P
mzUI+;
I<D$.&
Q\|1H
g'$>EdZ8
qRn2=`
{S:b&J-
bE102K0A
knV Jn
&oGCIb&akh<
TJt(WQo
1'G#5w!,5r
4-VA#Q
_(|fJ]lG
`KX:k&
g+G+W~
/f,qU&
qGqW~M
c^e1?7
]` ,G.
~Q.i- nW
J%}//c
'<&/s
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADS
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
"$,0wT
M(+"*
{jlN*-
'vT3<_"
c=wb'a
5a~#$6
;-1%u-
#0C<V:y
2ce}Qf-1
q,9lhs
M*1`xj+
9eZRG
X&^Kt[B
fG2JZI
K'>ddQ
csg9w_n
Z:}{X'[fT
B_oN)*
E78.VX_
v4.0.30319
#Strings
1 D I }
!!)!1!K!\!c!
"#"("F"R"k"
#6#<#L#W#\#h#
%1%S%m%z%
j!s!z!
%"%)%I%
$I51-0
$I12-0
$I22-0
$I62-0
$I23-0
$I43-0
_Lambda$__4-0
$I25-0
_Lambda$__25-0
$I35-0
_Lambda$__35-0
$I26-0
$I17-0
$I79-0
$I53-10
_Lambda$__0
$I11-1
$I51-1
$I62-1
$I23-1
$I53-1
$IR75-1
04ABC8821A06E5A30937967D11AD10221CB5AC3B5273E434F1284EE87129A061
IComparable`1
IEnumerable`1
IOrderedEnumerable`1
IEquatable`1
Action`1
ICollection`1
IEnumerator`1
IList`1
ParallelQuery`1
$I12-2
$I23-2
$I53-2
$I38-2
Func`2
KeyValuePair`2
Dictionary`2
$I53-3
Func`3
$I53-4
$I53-5
$I53-6
$I53-7
$I53-8
DFEA2964B5DEEDEA7B1EF077DE529C3959E6788BDBB3441E70C77A1AE875BB48
$I53-9
75C8FD04AD916AEC3E3D5CB76A452B116B3D4D0912A0A485E9FB8E3D240E210C
1788A91BBE39157D78FB94B362038FE863E3403F8CE700C1F294E390B350B9FD
get_ASCII
System.IO
Microsoft.VisualBasic.FileIO
System.Data
ProjectData
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_CurrentManagedThreadId
get_IsDisposed
Synchronized
Append
CompareMethod
Replace
CreateInstance
GetHashCode
set_AutoScaleMode
FileMode
CompressionMode
Average
get_Message
AddRange
EndInvoke
BeginInvoke
ICloneable
IComparable
IEnumerable
ParallelEnumerable
AsEnumerable
IDisposable
Hashtable
ISerializable
IConvertible
ToDouble
RuntimeFieldHandle
get_TypeHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Name
get_FullName
GetName
AssemblyName
GetDirectoryName
AppendLine
WriteLine
ChangeType
ValueType
GetType
System.Core
get_CurrentCulture
set_CurrentCulture
ConsoleApplicationBase
ApplicationSettingsBase
Dispose
Reverse
MulticastDelegate
InternetGetConnectedState
EditorBrowsableState
ThreadStaticAttribute
STAThreadAttribute
DesignerGeneratedAttribute
GuidAttribute
HelpKeywordAttribute
GeneratedCodeAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
StandardModuleAttribute
HideModuleNameAttribute
IteratorStateMachineAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
MyGroupCollectionAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Value
GetObjectValue
Remove
get_IsFixedSize
set_ClientSize
IndexOf
OrderByDescending
NewLateBinding
Encoding
System.Runtime.Versioning
GetResourceString
ToString
System.Drawing
Stopwatch
get_ExecutablePath
get_Length
AsyncCallback
ConditionalCompareObjectLessEqual
ConditionalCompareObjectEqual
CompareObjectNotEqual
System.ComponentModel
AsParallel
LateCall
wininet.dll
ContainerControl
BufferedStream
DeflateStream
MemoryStream
get_Item
set_Item
FileSystem
Random
ToBoolean
System.ComponentModel.Design
System.IO.Compression
Application
System.Configuration
System.Globalization
System.Runtime.Serialization
System.Reflection
NotImplementedException
NotSupportedException
KeyNotFoundException
NullReferenceException
ApplicationException
TargetInvocationException
InvalidOperationException
get_InnerException
ArgumentException
StringComparison
CopyTo
GetFileInfo
CultureInfo
FileSystemInfo
System.Linq
ToChar
StreamReader
IFormatProvider
StringBuilder
ResourceManager
ToInteger
System.CodeDom.Compiler
IContainer
ConditionalCompareObjectGreater
ToGenericParameter
StreamWriter
TextWriter
Computer
ToLower
ClearProjectError
SetProjectError
IEnumerator
GetEnumerator
IDictionaryEnumerator
Activator
.cctor
System.Diagnostics
get_ElapsedMilliseconds
Microsoft.VisualBasic.Devices
Microsoft.VisualBasic.ApplicationServices
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
Lp7.g.resources
Lp7.Resources.resources
50b28e17cf29e8.Resources.resources
Strings
ReferenceEquals
System.Windows.Forms
Contains
Conversions
System.Text.RegularExpressions
System.Collections
get_Chars
RuntimeHelpers
Operators
RemoveAt
Concat
Format
AddObject
MarshalByRefObject
PlusObject
SubtractObject
NotObject
MultiplyObject
Select
IReflect
Distinct
LateGet
LateIndexGet
DataSet
ResourceSet
LateSet
get_Default
FirstOrDefault
IAsyncResult
Environment
Component
get_Current
get_Count
Insert
MoveNext
System.Text
set_Text
ReadAllText
StartNew
LateSetComplex
GroupBy
OrderBy
InitializeArray
ToArray
get_Key
ContainsKey
get_Assembly
GetExecutingAssembly
get_IsReadOnly
ToDictionary
GetCurrentDirectory
DictionaryEntry
IsNullOrEmpty
$Copyright
1999 CH?I@BF<GG@DI@3G4A
CH?I@BF<GG@DI@3G4A
JE2@DI22<H=:5@D49AGJ3?
7IJ;BH<638E3CC;:6
WrapNonExceptionThrows
y4GPp69XoEm57YtDg31
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
3.5.7.8
$1121ad7e-5c4d-4588-b7de-fb168b7803bb
MyTemplate
11.0.0.0
My.Computer
My.Application
My.User
My.Forms
My.WebServices
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.7.0.0
My.Settings
JG.aH+X, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
LG.aH+s`1, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.as+aP, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.as+ae, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.as+am, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.aj+aH, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
Column
KG.aX+as, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.aX+aI, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
KG.az+aV, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
MG.oC+aZ`1, WindowsApp1, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null
_CorExeMain
mscoree.dll
resources/uiodjmnklkjhjsf
1735effbc2
62d1fc8e0
Y'2'6'Q'U'Y(:(>(Q(U(Y)2)6)Q)U)Y*B*F*Q*U*Y+F+U+Y,&,U,Y7B7F7Q7U7Y929J:6:U:Y;&;U;Y>2>6>Q>U>YF*F.FQFUFY
2#6%9&?-H.L/
&%'%(%)%*%+%,%-%.%/%0%1%3242527686:9;9<9>=@?DCFEGEJILKMKONPNZY[Z\Z]Z^Z_Z`_aYbYcY
{0}](?=(?:[^"]|"[^"]*")*$)
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
7IJ;BH<638E3CC;:6
CompanyName
CH?I@BF<GG@DI@3G4A
FileDescription
JE2@DI22<H=:5@D49AGJ3?
FileVersion
3.5.7.8
InternalName
skx111.exe
LegalCopyright
Copyright
1999 CH?I@BF<GG@DI@3G4A
OriginalFilename
skx111.exe
ProductName
JE2@DI22<H=:5@D49AGJ3?
ProductVersion
3.5.7.8
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.622018aa5fdba418
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fc
McAfee Artemis!622018AA5FDB
Malwarebytes Malware.AI.4017048245
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
BitDefenderTheta Gen:NN.ZemsilF.36792.xm0@aGofcxh
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AJYX
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Win32:PWSX-gen [Trj]
Tencent Msil.Trojan.Crypt.Ngil
Emsisoft Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
Trapmine malicious.high.ml.score
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan.MSIL.Crypt.gen
GData Clean
Varist W32/MSIL_Kryptik.DSR.gen!Eldorado
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:DbHkKYuohCd8o8y/pp6hYg)
Yandex Clean
Ikarus Trojan.MSIL.Crypt
MaxSecure Clean
Fortinet MSIL/Kryptik.AJYN!tr
AVG Win32:PWSX-gen [Trj]
Cybereason malicious.a15749
DeepInstinct MALICIOUS
No IRMA results available.