Static | ZeroBOX

PE Compile Time

2023-11-26 21:14:22

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0003ac74 0x0003ae00 7.67423329946
.rsrc 0x0003e000 0x0000763f 0x00007800 1.36938071986
.reloc 0x00046000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00044500 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00044500 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00044500 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00044500 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00044500 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00044968 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000449b4 0x000003b8 LANG_NEUTRAL SUBLANG_NEUTRAL COM executable for DOS
RT_MANIFEST 0x00044d6c 0x000008d3 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
0Emju:
=mO.53
ch`r|C
m|w*ko
ny~*V3
c[^8${z
?LtTMnQ
-xVQ=i
D*WJM%
6D,/=l_
.mS$B;}
^!ojk-j
;U~%cx[
5N-X6
_bN1`|
5b,*%
ocTtJI
JMWTfs
G/{Gyy
F,mc Z
6F7^o$]av
0$zDmRM
B@VSzo:
|Z0S4\
.TEL&syL
VoEO#I
<crYTxW
(b/g-t7
x\G-(r
m=Cl2x
zucf43
d&RY?V
?%eb%Y
[-K%b*8
itK7#ld
7@g/kr#
b/0pf--
FF^(`*
`},8/tJ8
Wvr\hC
[>@eVU
%f:hXfH
IrtE5r"
;p*Oa^
Dx}R5q
g81f:@
2bp-,c
'A)[53p
jggRq(
P`udr
K>c)"3
&[ZHGw
'xz[E/
|i~Z*X
<N2FRZM
jC.N 9g
']Sr?u
lL~,Xp*
tv6;-~
(:j&J
LOhqLp
aNSTWJ
Fjr bL
$0Fi
m?.]oF
~M/lNOW
fSm!%'l
Re-Xiw
e/l"V}
QW)7pc
G%c0`tW
6Vkiv-
,dKaq|
0;*v]m.
5T>eJd
>fRb/$
jO~V<^R
\N/|&;
8VhV9C5d
9&b TE
PDvd_ +b
UNO `z
`m|uW(jb
opv20g
2Mk2'1
q<4HV
[d<=V
ntsa{!
`;k3 !
'*O|<#C^
$;7gicX
j6/_"`[
f1I&>5
*GZXG1
CJ21=0
.&LbT|6
nb<Bag`
}/=frSYs
`&pQP=
?r84beMO
i[|p(A
1SvjeQ
GQj>>3
W"BeZ:}i
^S~)p6O
YT^OeJ
g]:65i
jm8vyS
1+viQ@`t
k,KFnr
wyY1Nx
<H\H\%
D$Qc{_*
l>rJJ0
y@!_1\
lht1U
DHjV|U6(
t|zH&g
Q{j`U<R
Gt1];'t
%H_,^5
Zf/-K@
p+jLO|J
>zm_lR
HTaPcMB
[wmpn=(i
mNSTz-
|&-/"}
arAiDn
M/_Cwm
>{_3\S
s|8"r"
mJR3]]
fmFi|o
g`_KW8]zV#
^73k`1
7"@GF^;
l? 1_c
]RJ0/cHT
"&#J 5K
h#2$N%?z
fH1duV
-hL+3/=
z!%O;K
ujC$` V
GVx}tx
$+9]8x
tzcD-ACjR
<=tXE?
DLFH4/`]d
Xh:\k}
^y>uLc6
"ra)R)d
H^\e$}%
J,vP<b
>"CcoW
Ivt}v
\a/P&G
<s( |+
hx=4|'
O.xSC]w
'ttn8
E&"y=4
;HB$z2
?dycoc
kW, m'G
_6nW5`?b_7M[:yY
gu$BOw
_9na5G
rIh`=&
d,2H/V
8U1/2&
-qMa?@
K~^<6
r`#e7JI}b
Kfd&Dthr
';_._-
\:mO@x
"ZE$DZ
=$Dcj[
7!&+~J6
`LFdl53D
>G\B,%
lg?K\|
$!9d4:i
Tw1!y#
"g=g{Q
tx,s_LD
d2|4ndr
~TB.6YO
(tT`Na 
-4ig'{n
IA10B6L
HOKP#q`
;!%"K( gA!
%dW&eU
b)H^_l
AMXRKaQe
nBTa@K
YZ>@]ew
D!6F&%
.&%w2s
:3o<9{1F
o5RG(t%
nZjiu[UO
[ja"oj
l8'.ls
Wv*7U:72
JEAG='
JjQ1u5
P(OP'M
MUeFK#X
(_*89?
?j~Fz#
8laS/s
O~r%%q
(E%A,RxA
cLf4"=
~gk"Vo
nh4A`>
[p0z:EF
m!odz?
GVl+Ki
9o*D~l
OR6PW#
i30z`
5<KEiY=
-vS-^
RG3lp0_a&w
+*DW1dH
m^JJdi
^RlPxar
Q%N6}o
cUf <'
C_kjZ\
EYTI}6&0
4Z/?bP
\giSx}
^{@8j
'H9HH!
(B}egUW
ieILB
AetWn%
+5&(nU
MmX]V/
Hw[p'pc
MuS!'tl
PtKNX.
sb|TdE<
Vehk,u
s}5b5,
eHr1'[
Msv0{
DIX)s|
-2J(M@Ds
D="$|
GN`Dx,[q
eOSlIN
jEAyxd%
EUoG"^
t{oWbgM
iV>r)w,
z&;/*%k
9aA/=Ja
(:*_PH
cD|h,o
3eZwICq
8nEKZX
]:E@2H
&vHbT8
Lpr<Dh
]rCDg
$5))Qw
x"?Q%Q
"b.<yK
KF?#P*
xl9\mB
kvhSj
rv)2Cn
h9%oh<o
K::Ze1Y
%Zz9\X
r<M*:[_
("SiN|7
P"i^<>
jtdykb
=[[R/%
?FL{SAx
Lu^h4O
}D/Elmi
u:y`ec
8Cp>XkF
o:9jZ|
^eh"g"
Ky?H Y"I
a]les8
!G)u_Y
%'t,
Z W"d-Z
X W"d-Z
Z W"d-Z
Z W"d-Z
X cZTwa
X cZTwa
a cZTwa
K"Aa8g
Z W"d-Z
VMDj^m
a cZTwa
bZ r=r<a8
fT_w8
d+#0%&
Q%\BZ
F>W-%&
7S.Z G
D9Z x!c
LP\a8i
HPM6%+
gQ%{Za8R
nq4jZ
Z Hz%3a8
T5Z v9
L_`&Za8
#[|Z s
RF>}%+
)JkZ _
Z P~AEa8E
_bj2
_bY*
QbDFZ
hk &/sba%
ZSN6Z
;cDZ f3V
:[A"Z
#%%&8?
D0Y38(
Q.%&8'
%Z [2zVa8
[o4aZ
mKZa8z
bk;&Za8
7<"%+
Z_bX
E6Oa8<
2ehd%+
jjzZ 9vq
Y_cX*
qn4%&
_0&Z _
cm$a8w
*-%&8Y
Z lpX(a+
rC4fZa8
Z )8|`a8
BZ ^_rRa+
_bj/
#<Z A#/`a+
_bY*
,3Z 1N`xa+
!]tX%&
] (Z A
_t6F%+
_t6F%+
Bq%&8w
7UV!Z
Z_bX
$FNZ i
,%La8@
7d%&8{
e!Z >g-4a+
Y_cX*
._ 0z6
d*sZa8]
XT:%&+
v4.0.30319
#Strings
#Strings
#Schema
;d18lY
server1
UInt32
ToInt32
get_UTF8
<Module>
System.IO
mscorlib
get_CurrentThread
thread
get_IsAttached
set_IsBackground
ResolveMethod
GetMethod
distance
CreateInstance
Invoke
GCHandle
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
LoadModule
get_ManifestModule
get_Name
get_FullName
AssemblyName
GCHandleType
ValueType
GetElementType
ResolveSignature
MethodBase
Reverse
posState
STAThreadAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
SuppressIldasmAttribute
AssemblyFileVersionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ReadByte
matchByte
prevByte
get_IsAlive
add_AssemblyResolve
server1.exe
inSize
outSize
windowSize
dictionarySize
System.Threading
Encoding
IsLogging
System.Runtime.Versioning
ToBase64String
GetString
get_Length
GetManifestResourceStream
inStream
outStream
MemoryStream
stream
System
IsLittleEndian
AppDomain
get_CurrentDomain
System.Reflection
Intern
MethodInfo
ParameterInfo
sender
rangeDecoder
Buffer
Debugger
ResolveEventHandler
BitConverter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
zhBf\&ei|9_\\;OXW{u`a1X_?l%.resources
DebuggingModes
properties
GetTypes
numPosStates
GetBytes
ResolveEventArgs
Equals
Models
NumBitLevels
numBitLevels
RuntimeHelpers
GetParameters
numTotalBits
numPosBits
numPrevBits
Object
get_Target
ToUpperInvariant
Environment
ParameterizedThreadStart
Convert
FailFast
System.Text
startIndex
InitializeArray
GetCallingAssembly
GetExecutingAssembly
GetEntryAssembly
BlockCopy
op_Equality
WrapNonExceptionThrows
Vouive Qui Bhong
#Copyright
2023 Vouive Qui Bhong
$cc7fad03-816e-432c-9b92-001f2d358798
4.8.2.8
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel node will disable file and registry virtualization.
If you want to utilize File and Registry Virtualization for backward
compatibility then delete the requestedExecutionLevel node.
-->
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of all Windows versions that this application is designed to work with. Windows will automatically select the most compatible environment.-->
<!-- If your application is designed to work with Windows 7, uncomment the following supportedOS node-->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>-->
</application>
</compatibility>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!-- <dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>-->
</asmv1:assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Vouive Qui Bhong
CompanyName
Vouive Qui Bhong
FileDescription
Vouive Qui Bhong
FileVersion
4.8.2.8
InternalName
server1.exe
LegalCopyright
Copyright
2023 Vouive Qui Bhong
LegalTrademarks
Vouive Qui Bhong
OriginalFilename
server1.exe
ProductName
Vouive Qui Bhong
ProductVersion
4.8.2.8
Assembly Version
2.7.7.4
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealer.12!c
Elastic malicious (high confidence)
DrWeb Trojan.Siggen22.18357
MicroWorld-eScan Clean
ClamAV Clean
FireEye Generic.mg.2390cfec047769ff
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
McAfee Artemis!2390CFEC0477
Malwarebytes MachineLearning/Anomalous.100%
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Clean
BitDefenderTheta Gen:NN.ZemsilF.36608.qm0@au@fmB
VirIT Trojan.Win32.MSIL_Heur.A
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.AFFK
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealer.gen
Alibaba TrojanPSW:MSIL/Stealer.f5ce2515
NANO-Antivirus Clean
ViRobot Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:nm4p3JnfuqJap+qwfTP0GA)
TACHYON Clean
Sophos Generic ML PUA (PUA)
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Win32.Outbreak
Jiangmin Clean
Webroot W32.Trojan.Gen
Google Detected
Avira Clean
Antiy-AVL Clean
Kingsoft MSIL.Trojan-PSW.Stealer.gen
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Znyonm
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealer.gen
GData Win32.Trojan.Agent.E6GE2H
Varist Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 CIL.HeapOverride.Heur
ALYac Clean
MAX Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Msil.Trojan-QQPass.QQRob.Agow
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenKryptik.FEDY!tr
AVG Win32:TrojanX-gen [Trj]
Cybereason malicious.eb985c
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.