Static | ZeroBOX

PE Compile Time

2023-11-09 16:57:27

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
R\x174k},I\x0c 0x00002000 0x0004d05c 0x0004d200 7.99946257258
.text 0x00050000 0x0000c08c 0x0000c200 5.17893280196
.rsrc 0x0005e000 0x000032c3 0x00003400 5.44276288282
0x00062000 0x00000010 0x00000200 0.142635768149
.reloc 0x00064000 0x0000000c 0x00000200 0.0980041756627

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00060158 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000605c0 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00060638 0x000003b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS
RT_MANIFEST 0x000609f0 0x000008d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x462000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
`.reloc
~#Og1N
l*0IL
6!}[bW
RzJ^B-T/Y
\(:8%[
];0bXiYP
m03kAY
pp"tG0
z&jBm|
ncVb@k1
^dRszN
bO)8whD
8c6LUL
K#3G(`Q
4prbY\
eU~@-c *{
>%DQn5sX
ywJOII
^@0ztq
Id>U9)
tg*WE?,3
>l,fgG
4:Gmpkt
s>5Ljq
{0wSwX>@
"XT`[H
T!5:n23v-
=2}>*;
|J@P$.
\;/\5(
HO_,_{lGe*
h?f$_#<8
dXg]o.
&JyW;}V
ixtAswM
2O2@qR
0nR")I:
Apmc|`_d
li1EyzR
zum- 5
;r%8gj
bsD>.3
:1HUbW
6jPED Gp^v
*c7`NR
r'%O*;
g&jcAx
:v@Wus
h-i>yC
VV}L$i
NpD})
o}G3NiL
(WOm!\D
qM0ige
~NHCS`
N%*Yhi
vGu`"T
I8J:xj
'+L'q5
gc$a:xE
+)pS%z
uDWK^
sgIATLM
z#*EQ+oGv
j6:$?C
U$wt|@I
q[P_2x.
\%5;dt
.r(0 >|
&QLof-
c0oGNZ
R(G|k6
"-$3s8Xn\
d IsO5@;.u<Sp
6zG)E]H
W>hObb
r@K7Q~
27G!4]
|un8W'
W)Rz&)
fHw+GU
bH?XRJ
)G4/a4
^OHwQ+
-P<j~bZ
(SGc=u
Ah\Zfi<
zx<J"_
1}A{Qv
M/+}oSB
'P`_?~
{um66c
H%`4H}
T&xp?[
f{4%!1D
;U/^Y9?
0?Wc>3n
>M[`Gl
-6]zA
9{U_Lm
|]h-=.1
w*<MK
'$V1`@Qy
.Tn!ts
Ss!&L&cGA
\5ZJX3
N5ekea
G@a`(R
ym>>FNdRr
"Ak8]
q}3JFf
!%Y:G^
s;;\UF
CuHVu#n
T#fO>Z
1?JT}>
TlNcJ&
&p?0)$
Q]t9c&
.q<fg5
|Z"$fjbE
Rk_6 %
Az?*O9
A&!2~H
Ie[&nK
q^maL|
CfV%,os
o=kB*0
+PzauM\
dav[3~#
]r@y?qD
%Xeb`A0{
%rkG-2
vXF. DC
>-_"'r
B$$uC-
4>q*\G;
K>5EG[
v),j# tA4b
;KzVn>
*/.>uD
J7gdNm6=#K
?'2x%-
Jxm-wy
-W@iNw
hr/-kG
a(WPSO
fn8jL!
GS7@n%w>
<j*^4o
fkT H4
&5H\W2
6[Q YZ%
%IF9T[MD
C005je
.vVsa[
}y0["v#
$K ,aS
~#^@t|
p8_oL\-f
C),I*tx
iF^dOp
BQ*J5/
'_5{.W
_$2730
4ou5a(
j9}iIHb
*>Ta^*~
3!pH(!:
mrVZ)L
defDK[
jYBe=
%ZT1Uk
CiT~KB
tMTJ"A-NS
ok"5?*T
d=BO^^
Z{n,>3J[
qca}vF
lF:y.9/
ck2]~7
mm,#j\=7f(@
Z7r3@O
',]gld
>Ly>e;b
%TGh%k
yP|Hy>*
vLK9wT
EIhnLf
@GZK(8
(h9~k!
.m;X_2
uw-)*\JP
jC^.vM
s6]D[F'S
_DCo'J
5nx@[.
#_\POI
a]UvYB
<9"Pu-
w:GbgBn
T{&g%F
H[5,Ey
a43U]I
|FR]djV
)}9qQd
>zQ7Bj
2 %-v,
F,&bA"
O,WMNS
]n3S5+g
<*yA`0
oM^?U2
^hz'c/
qx~uM9$8QA
#O+BVMAO
oi#>wc""E
86REXp
CD7|hh'
.ndv]&C7(
BjJ3_R
g\PHTTJqJ
qj1wxt
@`?GiA
+yNx8D
'"O)v'
78A?TM
.y#\&^
_+5 r_2
8#-/HD,*
@6tw4LU1
p^F)3M
=S:LD@
f$7,zZ
3f3I;'zD
5D-;nx
<hw('W
jL%~4}z
i7s_oTc
FL2:4D(
m>=S6CQ
]5t,S 9
*:GKn%
B$]tKv
(o+q@~
k}Q,e9
8@x%g|{
OL3r d
2{<~J@A
P'Xc{ "
KaO:%+h
z!Un
`H%;1E
8/MM0ed
;D&TE)
210#'M
?#{IY>
c`3xvM?
2KHr)W
XuG&{J
,vGiOzvC
f_MmA=0
4(i%V1]6
rl+-T;
_]:fg*
5ktuoC
x1Oi3*V
g.TaLw
!4P`T(
P,bBk#hgr
/?Q73}
1/,s/g
{;_WfnW
'rJ6oo?N
&eF>ycP
!<f X!
<E}ui
V(f,hm
8vkp+J
^%d.0w
%c.H@ol
9v%rGP;
QHJ!,zc
EYyQ\
9En/i%
HQ]}(C
0JRLJ)r7
")'9$~W
B>UXx)bU
Mtv>{%
3BCp&g
*vx~0`
^7a:[w
=`xA(>n
mRiB-i;
}zbD!Y
|^E9~S
oFT~e;
Xhg S_\C
m%3UU"q
T?J0P(G
;J^M5%{k
MB)g~g
4R]2B`
aNg^n3
+a54Op
unh,(!
/9S@NT
heZ+B5+
\Y3H7h
U.qbN,
pnY30#x&j6+
],uZm
0egbdb
E;L934
T5pk64(
AYr:c/BV
C9YsH/{1Z
!)(5Y>?
1`Z<I(9L
(:@n0X
\"%w,UU
Yj\My~4Z
wqFCj]
l?qLaNY#c
V>Tx8s
GFmPj\D
VqyS2{
YJ^[lI
Z2[A"1
d*[%M:
ut:j,0
+F}W~4=/JQ
B.@*B1
(DxB/4
xk."Qf
ZU}}71t
i;49"/
#x6qsB2
?&?</(
x}}b3$S>o
-kym|.
#SwZy\
aGTI<F
z<]r.u
n9z9<y
jbuZZFm
rv/d[.
6<{bsV
|RwTWw
L#.uH6Q
_,HNe4
^_\Y0x
{j$BiF
\ZKO9p7
Uzd8t{
N4_QnX
TMyFn
`o4[\'N8
Vh8i#<R
4PW8Aj
`|r"$U
I$RdW.6
jyKeD_
jF}E*v
,aJ.D{
m]8up5
@P j@4WM8
g~@OZ$
q2zM1!
?9Y</eN3QQ
U#3{@V6D:
BHOCf,
5+VT74
)r<jDw"=J
/O]a66
nae*IkW
k'^IT"
)9>gSg
m~{nAZ
W.y{+.
EPIwYA
ccnvd5{
8\C -A
't66QBbx
qY(?W)
<^\I=X
@fcs"n
Hrf@EI
D$6W_f
t"+&<<5
Qv^tY=
-N0d=
i9.W6eAx
\qB@Oz
npr4C@
@9"WH-
8n_4oO
_8y2eJ
-[;}pa
/SQRtsY
C$y6tSm
nS%0 :kQ
0izJrf
+#@uC9m#
@1i;&E
N^35b?^P
g@y~'
yD)stP
%.qg+&
7R_Js{}
Hny)\Y\
u/~Hmn-
xxtW.c
1uw{+C
MifLsJ'
*beHy6g
w|Zi[;
&(n;9@
Q`T-Z
mYnOu~
W{Eeh7
/,\;:n
biA+|^#`
V2 `#(
y.wK/;^2x2
D&x6zU
`nlVY*
MT_*%qX
D $|kb
2x".?7OA
hvoh,O
k.v'rq@
T=MQ#{~nN
w Om`<
j|jTUT
*H"3A$D
R& x]v
_zG)q /TV7i
X3pGK{
2[Pl>f
x9Ku2v
5;n@q\
#2yH:E
"N3r;A
(X9(i^
%3'xri
3{S05a
FLz4E(
WQZ>T
n-2;+>
8`t*7~
l3<U]g
3p^@r%
dYp>DyVLn
a!H<=?]
Xv'?2K
@b}6bBD"
tc]fy&oz
B`nciIes.
WwsI;A;
K*<kzqII
(b[..`p
79:h1T
'%}BZ5
/%cnNY`
k#R+5|$
`n?CS
G!b^+|
)#:O9s
BtD6(
kLL!<I
0Yqxw[
,_Ay;9}
Qi,x@+
Qu<j~(
;4,q5
WW MVd
-IEU,-,
=wxrh$
r&">NZ
ys[IRHa
vHE^% @
#Oj}zdd
#uvB%/
w"Xem_7q
0Y*u#fi
![J"4Ih
8b~yi/
s~>RHc
T5#;c|IRmE}
_e&$Ss
T^T<351\4
VoCfB[z
o)h vy
qcSL[3
Z7jn#A*hE
T`U|[@$
AkAzYT
<&yYG
q/dJ~S
76lyV5
0><:n
cRMO:
yv0;A
y-LpEy
2iD?W2
(+Nn|4
lclI[3S
FA/8m;
+.57jH
K:">%&;
e4>VrH?7
FGeYc+
`)-gLV
OMS\[]
uJ,pB@
<x`1*
sYQ3}`UK#
A7%S^$
N}N|(X
}3aQHS
<8%C)#d
CkPYaA
6(2Kj4
H-<INL
8.\*vTg^
*d6+N=\
B.}Hrk
*=Ae.v
QBO{u,
NjJ*mg
q/)M%p
x{3EJ(:L
[rz{7%
,;ENq!
<eI9'nx
VOlb Wk,
[}w2vS
]Y wL.
y]AKn\n
'@)u5T
={&=jKy]
2JDj Y
^'BuFlO.
\/+Bie?J
YAxt1/?u<
hR${q~
^at~Qn
PPxYny~Z
D6On|L
{xep],[
60"WBb
lW{t\e
Kt+c]*
78[c.'l`
`/CB'w
P-f:9o
=0W^2n
)ym<"\
C7FwdU
1ztU_J
)lkwj!_Z
.~y64~
Q>I7"9,V
=-9sh3
m.x0eD
;BN_]k%
/wr\@W
STpo`.d,
WDLoi@oW
vqn)*6
2qSW i
>swP*Z"
TvE!vWl
@+Dq0T
/7gS0s
AhCxlIR*
Lo"NJx
@^@{<kEI
Iq'^{2
B!Ll26
|<5`Xv
h`"Zcq
Z)U1li
A.Da8(
9 w;<kZ
9 SjCfZa8
ntdlT
NtCoT
X ntinT
9 >'[hZ
X l.dlT
{>NZ%+
NtCoT
X ntinT
iZ !|5
X l.dlT
(XGR ;
id Z o
9 ILI^Z ^f
UBKZ U
ntdlT
Z bI8=a8
4d1%&8
JZ -Q!8a8L
atG%&8
Z 9LH%a8
AUYLZ
/]%&8t
Ib%&8{
_CorExeMain
mscoree.dll
v4.0.30319
#Strings
#Strings
#Schema
server1
UInt32
ToInt32
get_UTF8
<Module>
GetHINSTANCE
System.IO
mscorlib
get_CurrentThread
thread
get_IsAttached
set_IsBackground
ResolveMethod
GetMethod
distance
CreateInstance
Invoke
GCHandle
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
get_Module
LoadModule
get_ManifestModule
get_Name
get_FullyQualifiedName
get_FullName
AssemblyName
GCHandleType
ValueType
GetElementType
ResolveSignature
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
server1.exe
inSize
outSize
dwSize
windowSize
dictionarySize
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
ToBase64String
GetString
get_Length
Marshal
kernel32.dll
GetManifestResourceStream
inStream
outStream
MemoryStream
stream
System
IsLittleEndian
AppDomain
get_CurrentDomain
System.Reflection
Intern
MethodInfo
ParameterInfo
sender
rangeDecoder
Buffer
Debugger
ResolveEventHandler
BitConverter
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
peL7pc9PGg1o@_?1c'6_^BT2(.resources
DebuggingModes
properties
GetTypes
numPosStates
GetBytes
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
get_Chars
RuntimeHelpers
GetParameters
lpAddress
numTotalBits
numPosBits
numPrevBits
Object
lpflOldProtect
VirtualProtect
flNewProtect
get_Target
op_Explicit
ToUpperInvariant
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
startIndex
InitializeArray
GetCallingAssembly
GetExecutingAssembly
GetEntryAssembly
BlockCopy
op_Equality
WrapNonExceptionThrows
Fuol Nlly Gobal Inc
Recover
&Copyright
2023 Fuol Nlly Gobal Inc
$cc7fad03-816e-432c-9b92-001f2d358388
4.8.8.8
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
oiiJrc=
{R-#sG.
dWYMdXP
pUWMeBD
vwI#tsD
cP:AcL2
aXMD}lT
iV@0jS;
gQ81SIA
jT:0J.
WC0D]PC
qQ+M_7
~_=(^ca
iVA(hU?
f]Q0sbO
qRMvn`
tfXJdO8
q[D#nX@
h\PMdYM
c<MV<
w^BMmV=
ndS#obO
|v>}o]
NMF'oxt
_F(Y\SD
QPI-inj
70&<cT?
fM-\aVF
MMG+luq
</";dR;
bH,[]UD
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Recover
CompanyName
Fuol Nlly Gobal Inc
FileDescription
Fuol Nlly Gobal Inc
FileVersion
4.8.8.8
InternalName
server1.exe
LegalCopyright
Copyright
2023 Fuol Nlly Gobal Inc
LegalTrademarks
Fuol Nlly Gobal Inc
OriginalFilename
server1.exe
ProductName
Fuol Nlly Gobal Inc
ProductVersion
4.8.8.8
Assembly Version
5.7.8.8
No antivirus signatures available.
No IRMA results available.