Static | ZeroBOX

PE Compile Time

2024-08-25 19:57:53

PDB Path

c:\u96ccordue\obj\Release\doX.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004cf34 0x0004d000 7.9949973075
.rsrc 0x00050000 0x0000062e 0x00000800 3.58426436269
.reloc 0x00052000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000500a0 0x000003a4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00050444 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
?ph[]^
`Yf~(-
f`mw]k
i28d%jK
Qj1f{jHG0
9q8yZ~
GZ=A(}a
,$^Uv98m
`1>iGz
0+$/{9
E$p4-oz!
d(KL#`
S0Zm D
tDf0#.[
$u~A3l
.?--4?#
Ts+}sgav
bPtUT
C}3Yh{uB
3}3?!H
"#V!9U86
|xj3.!
D?Rr<x
yk 'q5
}0.$Cz`
";].",[
fy~Pl]}
}ZD2HA
=f'C_@BC"
@C>Xu6
)%N**
q+<a*?
l{l+>6
Rc/\C:
S'4Y9@
f/{&W'
MU@l{3
[C.>g~
K&P,S@
-LI,7
@=XD3Y\KS
?+dB#_
xsxNNb
m4~~qS
aWE,.c]
Us{ywUmgC
CbmT[p
XBI~|;
!vf:GY
Wnb(9Q|
{GYF 8
mAFFPs
$}}<;M
?K6iX9
+tJ\,oC
)]k^Ai
#%t5T?w
R?LOuNY
(Bpe0#
c-Y=1_
1vTOA_
k_~WMg
-?vBvi
{nQ^Z=VJU
M[,/-H(S4
lRl[}m
8+NIk<
zv"-7hE
hf4 HD:
(0,q:h
l+:>O
y"qG;e
#9nwLl
`bpfM}]
~;DE]"
#(&gqU
2aLt#dnB.
+ZF-$
~JLS&K
l;\XVK
db&5lx
z)W^Qf~0
4e]fE/
g.0{Ze
LT=<Nq
_/y iq
#DCi89
98;Cs)
PD2$\"KG
:5e4i6l
j80C*8
j.QKtVfJ
>n;N-:
268c`:~
'>*")a
CQ!6}o
o*5m)?
[Y=pP]
<("F`
0=KS3R
"wT3U8
rM)"T1
&->:,$
W J04T
J~QG/m
PeQ`!H{
iz|u(<
4rb3z
@lfqX,
"6AaHm
yB88TRY
kiS0 I'
2s%:!O\F
=Xj_kJ
)oRS`i
ka6pX?
q:-Jw$
!JP#;D
3?EY*K
nQ>]4:
]7R\x#iV
ReC{d}-w
W(m@mf
yV)]Z]
WT{ft=$f
BZJE]/
n>j>ow
S12h"l3D8$
eDR}@?:
;P!Hc~GU
Q5B9CU
?akUn+t
1[4#j;
$Y5uta
<6q[BG
^U4B"O
TlysW+
cWfCrp
IS'SyY
"G<'Ln
sKSu9a
an;>G
jHVCg*
J5sB"QL
d$FA|
X\a j'
9?GdW]&
::4Z(V
0iA6Tn
t_Oyq{y6
@q&4[u
ePS}I}
?|F5mXv
@z1.0.o
Ryw~b
Oa[2G%;(
WtND&^G
.2q`yw8'
lbmt]1
;EXy{yD
GIP<y~v
^c|6dx
''0>T-*
DABQv|
>wIA~6M+
i]a/c\
F7;BOz
!txehT
<4x>1oP
O6L\u`os"&'
)i]Y<
Ce"<n>
d8xD"Ozb
oYG(gE
sLAXDE
.'aW%d,
[#]`b?J
~H'*8O
hl#34>
J~Jy]m
T43+_.
:VzY@[
xH9sx
.h/WlnC
:)_B(P
1OiP+=
Ei_IFS
e6\l))
Daj_FC
E$dP-%
PbBo.TP/
3?5T~k
-YJ]QEt?i]U
KVD6yu
<y%6iJh
c@4"V2
xws1?P
*h>f^j
-"R6u;
>fO"g!
EyIzzT
m"vEh7O
yggZw.
B[tLBP
CzigL.
T*fHCj
]R!A<C
3dWF-gV
K|/HF2
q_Jxr;r
>@{_Bl.|
)0=QW:
,S3+c+
3y=bh'
CwiV(D
{S.!iwTA
dWndX
U_Z.j
N%?G_b
v@+z%<<
Ea?V@s
}!X.PU
"jfge
+$h4-A
WV/]`
en'**b
B27#*}
iaj>=Tb
#g\c>-
X|_Eu2
EF1\yx
G,#C|p
Rdz8?E
#1*,8,
,up+oX
%WG?x!
hJJh!7t
djlF9az9
\mUA=I
^,vx3S
xxYXgD
l,&q\G
\`-,by
;|2yl?
50@P=q
[\^%A~lD
u 2^5}
W(rhy;O
e4S$IB
98\8-
h*e&MJ
HeYM>
N%5AR%
nzTeBmS
?&u-*|
,\ruOO
5KY^dB
Y z^LJ
~FU3V
=4=Br|"
@w~dx`
3X>GPG
L/'h^T
`[3/-A
-z,<{o=
X%`H!/C
<N<\Aw
WUEkED
VgY\B.
'/:pWcaM
],bbu}
z5)8{}=
.zPCMd
{p6.\`
EM^fSO
J+HI|@
nJ _'"3q
4OBMak
hkhPMW
HxqoOB
14P#c|
G!mD]S
1@PK4y
`~a%F%K
B*3w*7
?|b&/`
uA0[%h=
G>V<P?
) 2UZE
kFT2]&
*H:B]T
"<L&T(
V!==0%
=MIwK#
Sk:04o
?;ag=I$z
]d[ZEJ
^I,N!IJ
k4Zf+#
"e7H=fs
bk4SV\
O ||OI
8PgH1W2
,pjvb
gbz"Gm
Pp1tcQ
rp[=y{
{[{;-5)H
-& /Ql3
`]RThO
\N29OK
63~r6#
wASJib]
Ayp2b{s
+a$3&N
c'YW$ph=R
_9I0 6|
ynS1u8
_2Hg2x
JI_+22
dUsZ#Lb
k2n_Kl
s"aY^Z
Q0]-cn
syp':r
>nZjWM
(PLjr$5
6FLB#Y
+T0(qmj
VM)&vw
dL!+[p
*m[o@|
VE4b-.
v^y_xy
#AFl@G
>wHZ7>
Za+J,8
y6w.Q{+
<%/@/:
I{ei 0
;2,u[E
zF*T6>
0(3Ie0
6h9!n)
|bw(_{ou
qH?p{=
*(/6aXC
Onr!$6
~~KIIa
9PRf(I9>HL
NS~x/x,#
raeAw3
}R3l?5
S[1<94D
#"[+<{
G/749x
(h)i=u
01jBY`\'
80sQXP
"|eTN.
}L;`='
~&*-m&U{
@z O6a
Rr7f:Z
0A32sO
/3Lt8;T$
c+>)lI
RPf*M/p
UeHVqQj
| (y'M
nRQe*4)8
^OSv-9
,BLUR`f
t~cdz_q
Y&QP5_
"k7S.md1s
;+%wPL
stkI@{
leIIIC*p
PIw=b&
&o1!}kK
LwH_sw
Qbh'fq
d|8_#H
yeojgyw
^l`uw4
:I\+}k
tW<DUbvz;
RbuqtV3
CP?@Xiir
ki*XSy
=CS=#d^4
gLUn_.%
|QLS]2J
%Rj5ppV"f
~ _nz>e
bU>4[v!){'
w|PQ<
?-V|RO
%OLfB~
=):gS~BV`
5#_qjjw
Oy:[.<
wlnL.Mj
yr.Gh
{?_$r,
I&wOP
vUm"K:
cv0P^Gy
8TE;Lx(
]il\_
2IckIB
Q6Nj%'(
PXG`3
WM0&.)
Y_3ZyN .
&'g9Uo
<\$eOk
)B=\1y
Sx~+{F/T
F3AQUF4
5iIFGt
}!Z8[RF5
yV=q}@D
nj4=JK
k]?cxHnP,%
_kJ]uH
T4)3/R
BB<.u
QWe;)/
IU{1N-
ztnR[?j
"??LX'
bh.42
%[JQ(E&
f[+23(
Nw`-Iz
dCna%ET
Jwm&"
a^H~1@
l>tC_p
fq.?nDX
y/W9Xj/*
=#H{#m
s3z~+/
&a9r7c
X8\?n;B9
shB/<$
K@W8@Y
=SonFg=2
_,,E@x
Ion0%3
tiIYjkb@b
A]P$7fT.1
=Yg,Wo^
fLvAE}
wD2#YU*U
<OvUNz
4%^<dt>N-j
)soH>1
!Y)cF+RJg
P$j1h?Z
Dz-dgq
@Fp>v$
:*sC7_H
o3ETNIp?'
Sd_A)o
$'O>!?
+T<.}XS!
qtZK{>
QG}gxR|
7[i<2
yj,cg0|
`"H:i
_-,}oL
^,"na1}w>(
dB;#$j
w>H{&K
Zz^W=T
riWWon
P`btq4
gj`S\8>
W0.B+]v
\(xwNpJ3
.mVo}jX,
0S%D|'
gH~P_M
8pyh=.
Q~#G+JW
slSWZee.
ekBL:N
59?Z2i
#O!!-*t_;
T*1&YbO
diM Xh
PoDd:5
h4Ev=1=R
F6&$CI
j$}1n
!-.@KZr
bCwrpX9
9q{n_T
hDe9jt
GvGwrA
$3x^@(
oaC;k-
C?ONEf&
Y"ENix
Eh,II&g.
?AG!6h
5d-=sX
"pXET<
Q%bhDjP]s/e
N)>vju
>Rr(mZ
Pm/x>'
^lOW&
K>iirIITt.
X0$tx#
=+^}0&
PCxA'*
\=k68H
/H~r*d
[I6F[{~
C~Nh/)nW
~,(@Li^
Ycl}jo
q3wP$
L{fI4[U
h/Z% D
M$4@xz
LeK@eZ
OD1URz
h%^ 4u.
QQ`|o:
/I4FWc
,uTZ_G9
RV$c+4
6S]L[o
Zk*zXB{W
<Jo<G!,
8vT\Z"
;|YiFC
7EE11C
4`Dnd&
]<Qgl;d=N
h:a``;
AC%)bc
A22(_I
/=@_9Xre
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
AVP.exe
MoveAngles
SplitSettings
ExtremeClass
InterfaceLoader
Program
CallProc
mscorlib
System
Object
MulticastDelegate
userBuffer
Status
DoSplit
System.Collections.Generic
List`1
ParseString
VirtualProtectEx
GetProcAddress
LoadLibraryA
FreeConsole
EnableDataValidation
AIOsncoiuuA
Invoke
IAsyncResult
AsyncCallback
BeginInvoke
EndInvoke
splitType
strings
DisosNXoa
IOAUshiuxA
SADthhjty
uiOAShiuxiA
jikoxzaoiu
zkANsniuw
moduleName
object
method
UOIAshuixciua
ASwerthy
ujizahuiiio
cxjaugsuyqa
callback
result
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{005C9F8E-5FC9-4E16-AB8D-CCD434DDCD78}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x6000013-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=307712
$$method0x6000013-2
String
Concat
Console
WriteLine
Convert
ToBoolean
get_Chars
get_Length
Enumerator
GetEnumerator
get_Current
MoveNext
IDisposable
Dispose
DllImportAttribute
kernel32.dll
ToByte
Marshal
GetDelegateForFunctionPointer
Exception
get_Message
$$method0x6000014-1
__StaticArrayInitTypeSize=1196
$$method0x6000014-2
UnmanagedFunctionPointerAttribute
CallingConvention
.NETFramework,Version=v4.7.2
FrameworkDisplayName
Tricker
Dauntless Lanthorn Sittings
LovingDev
Lilly Hyperextended
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\u96ccordue\obj\Release\doX.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Splitter:
user32.dll
CallWindowProcA
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Auto File System Format Utility
FileVersion
10.0.19041.3636 (WinBuild.160101.0800)
InternalName
autofmt
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
AUTOFMT.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.3636
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.fc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.HAXT
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Generic.mg.7541f9ac48cc0926
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Infostealer/Win.ApplicationInfo.C5661876
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36812.tm0@a4REpVji
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Clean
No IRMA results available.