Static | ZeroBOX

PE Compile Time

2024-09-06 07:26:35

PDB Path

AVP.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000330e4 0x00033200 7.95666761555
.rsrc 0x00036000 0x00000614 0x00000800 3.4474380654
.reloc 0x00038000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000360a0 0x00000388 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00036428 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
pD0o
p51o
(U8<6~
v4.0.30319
#Strings
AssemblyCopyrightAttribute
System.Reflection
mscorlib
System
String
Boolean
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
CompilationRelaxationsAttribute
SuppressIldasmAttribute
91194bac-fe21-4980-a6c4-bf7a3e43efd2
AVP.exe
<Module>
rqtP6Q6HCyJgP3p6i7
vceASfqjp5F8G4X4nv
Object
ContentJoiner
GQAm65Vp0VwUELFfKE
X0fPYcI1b8nWtVKyZj
rivateImplementationDetails>{6342DDF8-F79D-49F1-A7A0-451AF9914385}
__StaticArrayInitTypeSize=16
ValueType
__StaticArrayInitTypeSize=192000
__StaticArrayInitTypeSize=1196
<Module>{A5610079-4891-4C31-8676-8DC0486EC964}
H6bClLfDCmstVjPTY1
QZC8ymkMdfclT0k7h8
ge3JPjCo2S59M1glBO
MulticastDelegate
GUa2R6jfyTpYVlNw6u
ecF25fd26RaXhw3fOf
rivateImplementationDetails>{F006A7D7-5E02-41B6-A5C5-819C21EE9A2E}
__StaticArrayInitTypeSize=18
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=256
f8DCCE12FAD13615
m8DCCE12FAD13615
TimeSpan
DateTime
get_Now
op_Subtraction
get_Days
Exception
.cctor
L6PeVk9g4
pCrTORSA3
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
PYMw80ELh
get_Chars
Console
get_Length
WriteLine
ChslRa3TD
ejFLdeZCM
pBPnsGkyF
FreeConsole
kernel32.dll
tcM1hc60M
Single
UInt32
VirtualProtectEx
UVuMUvElM
FieldAccessException
IEnumerable`1
System.Collections.Generic
CallWindowProcA
user32.dll
Q3xr1OoBe
List`1
Convert
ToByte
Replace
ToInt32
get_Item
BnWGL31dv
get_Message
$$method0x600000a-1
$$method0x600000a-2
$$method0x600000b-1
$$method0x600000b-2
NuKKv0hbE
Module
QmOaa6ftQD
typemdt
FieldInfo
MethodInfo
ResolveType
GetFields
MemberInfo
get_MetadataToken
ResolveMethod
MethodBase
Delegate
CreateDelegate
SetValue
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
get_ManifestModule
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
Syfb7S4bs
kSZamV8JHM
0E448EF5E5E60630BDDB19388CB6378436E3C65D03DD66DA7C6EBFF563BD857A
4BED3ADC52D4904075F6BBF279EC4ACEDE079533B95E229A29809542EA324A7B
62E6F13B53D67FDD780E20D89A6E8EE503B197AC16AC3F1D2571C147FDD324C9
7F535673D836D3D77A97DB03EB3D71EA780F44372F5AEBECEBEDD696AAEB8378
97E613E5A3A47DEC76B7E50D47644B35EA4322F00D594D80D2F1C1F3644F8A4A
C356AFF1A01C2B0DA472E584C8E3C8F875B9A24280435D42836A77B19F5A8C18
C61B1941CF756EB7551F7C661743802362728B785ADC22E860D269713DFB01A6
D5B7247C497788CF0031CEB06E3DF77A45FEF59F1E49633DC7159816D64759B5
CompilerGeneratedAttribute
AVP.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
Copyright 2024
WrapNonExceptionThrows
calypsonian overturning sworn
weatherized sociocultural
dolloped pipiness beringed
Production garishness parted
.NETFramework,Version=v4.7.2
FrameworkDisplayName
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.CodeDom.MemberAttributes
value__
System.Globalization.CultureInfo
m_isReadOnly
compareInfo
textInfo
numInfo
dateTimeInfo
calendar
m_dataItem
cultureID
m_name
m_useUserOverride
System.Globalization.CompareInfo
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo&System.Globalization.GregorianCalendar
System.Globalization.CompareInfo
m_name
win32LCID
culture
m_SortVersion
System.Globalization.SortVersion
System.Globalization.TextInfo
m_listSeparator
m_isReadOnly
m_cultureName
customCultureName
m_nDataItem
m_useUserOverride
m_win32LangID
%System.Globalization.NumberFormatInfo"
numberGroupSizes
currencyGroupSizes
percentGroupSizes
positiveSign
negativeSign
numberDecimalSeparator
numberGroupSeparator
currencyGroupSeparator
currencyDecimalSeparator
currencySymbol
ansiCurrencySymbol
nanSymbol
positiveInfinitySymbol
negativeInfinitySymbol
percentDecimalSeparator
percentGroupSeparator
percentSymbol
perMilleSymbol
nativeDigits
m_dataItem
numberDecimalDigits
currencyDecimalDigits
currencyPositivePattern
currencyNegativePattern
numberNegativePattern
percentPositivePattern
percentNegativePattern
percentDecimalDigits
digitSubstitution
isReadOnly
m_useUserOverride
m_isInvariant
validForParseAsNumber
validForParseAsCurrency
Infinity
-Infinity
'System.Globalization.DateTimeFormatInfo+
m_name
amDesignator
pmDesignator
dateSeparator
generalShortTimePattern
generalLongTimePattern
timeSeparator
monthDayPattern
dateTimeOffsetPattern
calendar
firstDayOfWeek
calendarWeekRule
fullDateTimePattern
abbreviatedDayNames
m_superShortDayNames
dayNames
abbreviatedMonthNames
monthNames
genitiveMonthNamesm_genitiveAbbreviatedMonthNames
leapYearMonthNames
longDatePattern
shortDatePattern
yearMonthPattern
longTimePattern
shortTimePattern
allYearMonthPatterns
allShortDatePatterns
allLongDatePatterns
allShortTimePatterns
allLongTimePatterns
m_eraNames
m_abbrevEraNames
m_abbrevEnglishEraNames
optionalCalendars
m_isReadOnly
formatFlags
CultureID
m_useUserOverride
bUseCalendarInfo
nDataItem
m_isDefaultCalendar
m_dateWords
&System.Globalization.GregorianCalendar
(System.Globalization.DateTimeFormatFlags
dddd, dd MMMM yyyy
MM/dd/yyyy
yyyy MMMM
HH:mm:ss
(System.Globalization.DateTimeFormatFlags
value__
&System.Globalization.GregorianCalendar
m_type
m_currentEraValue
twoDigitYearMax
Calendar+m_currentEraValue
Calendar+m_isReadOnly
Calendar+twoDigitYearMax
+System.Globalization.GregorianCalendarTypes
+System.Globalization.GregorianCalendarTypes
value__
yyyy-MM-dd
hh:mm tt
h:mm tt
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Size
height
~/(p9-
<1?8/^'
)sd~=~
^^,#vX
^^<H7
q%+nXC
3Oy#;
aZ:}+gh
moP[1c
[yG`]4
;J($ e
MqJC-l
(b#s6P+5
9|O?Iiz
yJO)u~ !9
!sOR1)
6G6kV]zp4
Qm$9H
11m#t
/X$i47
pcLab`
Pk5NJ%
Q`10H$z
X3[?w>
)>GxXFY
ljf {
o/9y9
<,%8B<
N<G\ >
:TQ<c
kol~8U
h\9KrP;@O
n*rJ/Y
A,:P~_
CkqQp1
,$vjq5W
|Tkco?
v)yzu#
hy{k&Be
`}PxFK
WM}w"|-
/JP|mPx
f1ueiw
de~$&hlV
i%#q?8
Fn\"\H
`z/,Va
V3(<-r
Q<+k\#
>%61c1
"8z|XB.&
E-ST.c
]b:aJ~)
Qxh]MX
Ac62Q9R
l7MJHi
/v[-Xz(
aE>*j=
MnUbi]Z
QJ%[ETy
yTZ+ho
v?D/":'s[j
Go.HbO
cGcX7)
n61>\F
*Kj.,&7QP
Dot,J&
ul'I[gg
PGm*`O
~~IP3]
Jr$/^T
cWo,>]
ndJZC
;jS{6.
?~n-C2
)cneXT%~S%
8EcsUGu
,p2}R!
azLX'T
j=uz6>
lCrr=:N
?RrD5{
N:ED~V
P@F{pcnG
aiYsX^@s
%#j&)j
D=L fv
FXSt\H
ONHq6Z]
*M9Wq\
yS'sQA
> 3>t
rA;X/Z
rRE=ys
+et1I6
j3(5Jf
G{}PUc
8L %)u
XN].1
i@/H.^m
O)KA)P
Lkp@Y7
y\ha%I
th4_W
Tlc5gA
i@>k>N
~63-R&
?[.7;C
:w@A=@
'j?<70
.oyD^^
?D53E24}
qK@LIS
x'U.hKg
qkfB!'
Sd|C,k]gP8
SRp[ed
PETvF>3
0R*(8P
:ghdjo
5b5U#h^}
8j[h=#
w\`&xZo
1tC*nS
r 7W4q
)3.mo#
cfbG .K
J\cC;L
4x?j&#
~Jn,+jf
[)L4B
OJ[$^C
x?Su3v
)M+9a-PH
yyXsUG
2L*gPT
)Vy;Sf{
>}}3e+Ng
S==ocQ
*-'ISeg
KX=0bTl
N@4y}E@
w2V2Ek
w8W%M!uq
Xec5O8l
,zsLt"
{y]ap]
e1DeYv
H"C9N<
|V%=5PE
@S4WsC
Uk`Q|\
/l9]*I
3<|/l9
s|lqG4n[(P,
png'*{
Cj6LJZ
V!4-]
FUJduhG/
-sXTk_
gP$)CRLs
3k!;q>
~~]%`*F
j8VnE\
m&cY1E
PF*G.
H{4^ja
|W-h|zn
-4>5I;=
iI*'=)
=PSDPm
*<S^ {B
kf2#:b:
O;iLNA\
+UuRR1X
]r&&&[M
p"0/l#6
GsGg_5
`q}G(f\
ciRzdA,h
Z>;*/~
&tc;9Y
Sgbi@g
hD(:^J
fn%k~4
1yKrQh
O$A3X3
r SuJcG
7*O]V1
_4>9}@
mU%W?,
J'XX'}
S9>51R
STsr;!
Lx3-h`IX
]ZSU\Mt
R:c9Nt
d9}jQCL
uVYSow
=~k5JC
-$=:F
Y/*g*V
V.{MW+
#ZO21{,
S6s:_
}=6]Pk
ApiLr-
=%#;\o
&Nw\o1#C
(j@>zl|
\hL2)[
sffI(AZ
6DJ=y/&Q:
FTDhU
yFvh/
B_XXd@
/t5Cd_ @zwJn
^'%E[~B|
zzQkAjkW
JRZ>+u
VYbKE
?CORP1
7j8aIph
G H"qib+
9'0^+(xYt
HsUkjF
%">[$D"
Q>Z`n}
_B`xuFt`
*P"a`'
k+dFqw
ICqqx.
PLdX?
"A"2Wh|%1
nXE(m7
|8f1D0
GFl8W8
h5T(9R>
Jj(-'~_
^/8Yb@
F.7R?I
Pe(AQj
*\CZ'+
xRw&@A@
) /P&A
]x.QT*7
D=&[K8
x*b,E'd
kVt.kN
P1Kl{U
[(J<JhE
!>skDg
>?fc`
uAhrov
L\,^n
+=3vQW
6kV7h[-75
'&53n`
oS/TS{
l+# D|
`l6`.4
l0'o&Z
.x&~Bm
u_F>qC
I};n%[
0lGv^HO
{U*f6o
u1_iL?
i#U\Iu
:'j9MPO
PArRE
jf-}-%
MKS)XCtf
pA5J21
16Hr^2
Vt,sHzV
U"lqDB
di"y:#
:/ 0ir
rspgs^
V-nMw
<GM/VI
vdJ+wtN5
m{)N)2
B 3J+@>d
EO"m[Z~
ql]mC(c
L7K:]sW
i4ckf-lq+P
,IMkn&
1BNr'|
%PhSyR
U{Kd,p3
PkEovs
p<xz!q*-
*QbP!N
k#j;7e
}mLpx{
,_! zz
qoELCW
8$Hkaxz_
4?Biew_
!Rrk-K
6=++vM'$
!_/+<v
?,5U_ki7Z
_Q%VSl
DBRfhn M
AVP.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
230113000000Z
260116235959Z0
California1
Santa Clara1
NVIDIA Corporation1
NVIDIA Corporation0
Aoi0Ka
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
joS&;J
20231102033749Z0
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA1
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
991224175051Z
290724141512Z0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
150722190254Z
290622193254Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
T=A^C_(F
http://www.entrust.net/rpa03
http://ocsp.entrust.net02
!http://crl.entrust.net/2048ca.crl0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
221004172103Z
290101000000Z0u1
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA10
_Xg>gX
http://ocsp.entrust.net03
'http://aia.entrust.net/ts1-chain256.cer01
http://crl.entrust.net/ts1ca.crl0
https://www.entrust.net/rpa0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
231102033749Z0)
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
CrIjw_XLNdmkALO]lxWhkGil\SpEkvXZwy_IgnHyjYeH]s_UzuHXjNWvIXMdjR[SKSoBhFpxoXyQ]`NdnZEpm@jhbd@O`_OWxRwJD\htDJcRPEXdJdp
$this.SnapToGrid
$this.TrayLargeIcon
$this.Icon
$this.Locked
$this.DrawGrid
progressBar1.Modifiers
$this.Localizable
$this.Language
$this.GridSize
$this.TrayHeight
progressBar1.Locked
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
weatherized sociocultural
CompanyName
dolloped pipiness beringed
FileDescription
calypsonian overturning sworn
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
Production garishness parted
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Tedy.629705
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast MalwareX-gen [Trj]
Cynet Clean
Kaspersky VHO:Trojan-PSW.MSIL.Stealerc.gen
BitDefender Gen:Variant.Tedy.629705
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Tedy.629705
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Tedy.629705
TrendMicro Clean
McAfeeD Clean
Trapmine Clean
FireEye Generic.mg.b81ac0bd6737adc5
Emsisoft Gen:Variant.Tedy.629705 (B)
Ikarus Trojan.MSIL.Krypt
GData Gen:Variant.Tedy.629705
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit Trojan.Tedy.D99BC9
SUPERAntiSpyware Clean
ZoneAlarm VHO:Trojan-PSW.MSIL.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=84)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL2:5CGJbQ29Uccqb5qNmmItCA)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36812.nm2@a8mnvDo
AVG MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Clean
No IRMA results available.