Static | ZeroBOX

PE Compile Time

2024-08-11 05:27:43

PDB Path

c:\uw22uphtu\obj\Release\MSG.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000195f4 0x00019600 7.97856505836
.rsrc 0x0001c000 0x000005e0 0x00000600 4.16484266247
.reloc 0x0001e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001c0a0 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001c3f0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
Q"HBS0
Z[RcGtyKr;
<t<K!)
P5a]! H
W$:.cD~
Dp}`U\
W00@10
D@zBG#
mS+78!4
OdOgr,K
uuV[>S
]05?1kM
jD_OJzooEl'*
:7D}'e
*G2D9m
f#w'bZ
u2BOK{
FFBj$5
Spk(aK
d!4G"L
8jVbr
UWh^x@
>YpX;9
qFbB&FC
7K|-onIUF
Nz^_G5
YA{c+$
F\!"Sj5AZ
q)u<!Ur
jBHkbp
$E3>I"
jfz]Yp
m[dd:f
;TR4dmFlKe
&Wl!e
cb4^.cvKY
sE%6{
TwXs^z
QrnpR3oE4
Y1bo#-tF
Lk@D('}wt
dkD4>o
3d2D<;LJ
W02h:v
Y[!|yN
4JG$uq
}[Xr$p
E^3bVu
J${yGIk
^|_"
r~yL]n
*q\UeL!
[;bM9*
0,hWqU
:@o4t!
({Z1a\XAc
Wi^dFGg
RK-((b
:h&^p:um
8tu#7<(
m6f;$~
]Jk*g
r`plmA
uhPZBr<
;GH{)x
j9?}i
BzHL7m
P~{h3'
Z%&a }
#Rws;z
;h&J1K
/F0G\2
,,Cj%Z
UH)?{r
Mp?]Eeq
!l_Kk
N1X="LQA%
h]=z C
DS[W_#R
d!S=yD
~Qs0_e
';v_3XT
0,?9kS
.dT0')
;n-zhRd
zk"CId,
Nc7*a$
0SYW[3
Wmm c}
6.?ajFR
,DY]2S
|,Ce"T
[\c{]h
._|x#rgr.
yB~$}\
9#qa,|*
^Y=Dz7
A:[R`{
TC,@{&
5W#lH)
h~_.JE
v]/fW;
4G+mV%
0vzVO>
=Ky4_7
~j[u=DB
+yBD>w
jiScJa
%S-pTa&
iPv,U]
e%8NOY
oFj wo
B@Gc4eE
fRf7)C#7R
lMkZJ>E
|ad>iFV
$nYuHS
ndYNb=2
qm4o(a
Rc,Swi
ZA-c2z
p9FbH_
spW#a
RY>Mv0_
:Wp%V7
}Kt|CU
E{.%RU'^
Wb7~RK
k}pqc2,
|)XH.h
vNe2=2p
"96y5T
bgYW%5b:
t~R8>~
j{GoY2p
paN UTC|Gq
_zeC_m|
.V6+xR
!E$LOK?
V3k. ^
]wdtUpNa
j|b?GI
E4j7an|
v/%\73
;3y:%p
E-so4p?Ly
l?OBlY
FexB$X
w ii:\
<%Ajw_
}V#RV`
*4%^)N
IydE2vN
NXAG4&
sPLiB}#
HIZdbdS
?r,_C{
Xwxnf#-
!~1^6ie
6fW1rX
Uo-2S|
-x{CQQ
7MXYE
\[{KHf
+/!v|1)
7|iClN~
"Aqux8
o-^t%!
H)|S4
cl$n:(
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
MSG.exe
MoveAngles
SplitSettings
Program
mscorlib
System
Object
userBuffer
Status
DoSplit
WaitForSingleObjectEx
VirtualProtect
CreateRemoteThread
EnableHTTP
shellKey
splitType
uzBAyuisuyi
ZAdhhytjuy
listenning
AZsadffde
Valeoz
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{D886FFEC-5D88-4580-820B-A3489A592B77}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x600000b-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=97792
$$method0x600000b-2
String
Concat
Console
WriteLine
Convert
ToBoolean
get_Chars
get_Length
DllImportAttribute
kernel32.dll
ToByte
System.Collections.Generic
List`1
Exception
get_Message
OperationCanceledException
Random
$$method0x600000c-1
__StaticArrayInitTypeSize=1196
$$method0x600000c-2
.NETFramework,Version=v4.7.1
FrameworkDisplayName
.NET Framework 4.7.1
Interruptible marbleised
Photoreceptor
Volatilization Swellings
Good resorters
Copyright
2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\uw22uphtu\obj\Release\MSG.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Splitter:
Exception:
Custom definitions
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Photoreceptor
CompanyName
Volatilization Swellings
FileDescription
Interruptible marbleised
FileVersion
1.0.0.0
InternalName
MSG.exe
LegalCopyright
Copyright
2024
OriginalFilename
MSG.exe
ProductName
Good resorters
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AMCP
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealerc.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Mal/MSIL-KC
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!4F1B08B2DE97
Trapmine Clean
FireEye Generic.mg.4f1b08b2de97134e
Emsisoft Clean
huorong Trojan/MSIL.Agent.li
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.36810.gm0@aCuxrTb
MAX Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.86 (RDM.MSIL2:smHKEOwesksadjOND9HMAw)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet MSIL/Kryptik.AMBW!tr
AVG Win32:PWSX-gen [Trj]
DeepInstinct Clean
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Clean
No IRMA results available.