Static | ZeroBOX

PE Compile Time

2024-09-06 01:16:10

PDB Path

AVP.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000330e4 0x00033200 7.95485538894
.rsrc 0x00036000 0x00000614 0x00000800 3.4474380654
.reloc 0x00038000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000360a0 0x00000388 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00036428 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
(}aRP(
pD0o
p51o
v4.0.30319
#Strings
AssemblyCopyrightAttribute
System.Reflection
mscorlib
System
String
Boolean
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
DebuggableAttribute
System.Diagnostics
DebuggingModes
CompilationRelaxationsAttribute
SuppressIldasmAttribute
7fda164b-d5c1-4223-bcdc-06fae574098d
AVP.exe
<Module>
KyI58ff0bnapMugwbT
qhFVkm6RmCWrOuqYI1
Object
ContentJoiner
KPKKZEDogBnCswBQul
oeDMUWFIVOtoyw7W4I
rivateImplementationDetails>{1328D6BC-B8BE-4F26-B09F-27F159195DE7}
__StaticArrayInitTypeSize=16
ValueType
__StaticArrayInitTypeSize=192000
__StaticArrayInitTypeSize=1196
<Module>{E08FB119-19DF-4917-BC12-96D46646E04D}
Mc9tPhB2sBSwsm3qeB
xaAIbA3FGnY6OExLpd
kRGt7TJLqSMuYHl1qP
MulticastDelegate
FfhQYsuFjsWLI1eSpu
SIVnr7TbRk6v1YR8dJ
rivateImplementationDetails>{271057F6-8D7C-4F74-8E99-2E531C8C3625}
__StaticArrayInitTypeSize=18
__StaticArrayInitTypeSize=30
__StaticArrayInitTypeSize=32
__StaticArrayInitTypeSize=40
__StaticArrayInitTypeSize=64
__StaticArrayInitTypeSize=256
f8DCCDDF3DE8ED19
m8DCCDDF3DE8ED19
TimeSpan
DateTime
get_Now
op_Subtraction
get_Days
Exception
.cctor
Kvm77GoJA
pY50SJAZn
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
TJLcSZuWm
get_Chars
Console
get_Length
WriteLine
FKitBtuRL
Ns4mZ5d2w
QRuUPXnCu
FreeConsole
kernel32.dll
M23rGBk0D
Single
UInt32
VirtualProtectEx
XUvy1AgEG
FieldAccessException
IEnumerable`1
System.Collections.Generic
CallWindowProcA
user32.dll
w7taqR5Oe
List`1
Convert
ToByte
Replace
ToInt32
get_Item
eEy4ZCxNo
get_Message
$$method0x600000a-1
$$method0x600000a-2
$$method0x600000b-1
$$method0x600000b-2
w2pCSLHZy
Module
WH2IIfjfq5
typemdt
FieldInfo
MethodInfo
ResolveType
GetFields
MemberInfo
get_MetadataToken
ResolveMethod
MethodBase
Delegate
CreateDelegate
SetValue
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
get_ManifestModule
IntPtr
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
AktGuWRlD
NZLI2Sa374
0E448EF5E5E60630BDDB19388CB6378436E3C65D03DD66DA7C6EBFF563BD857A
4BED3ADC52D4904075F6BBF279EC4ACEDE079533B95E229A29809542EA324A7B
62E6F13B53D67FDD780E20D89A6E8EE503B197AC16AC3F1D2571C147FDD324C9
7F535673D836D3D77A97DB03EB3D71EA780F44372F5AEBECEBEDD696AAEB8378
97E613E5A3A47DEC76B7E50D47644B35EA4322F00D594D80D2F1C1F3644F8A4A
C356AFF1A01C2B0DA472E584C8E3C8F875B9A24280435D42836A77B19F5A8C18
C61B1941CF756EB7551F7C661743802362728B785ADC22E860D269713DFB01A6
D5B7247C497788CF0031CEB06E3DF77A45FEF59F1E49633DC7159816D64759B5
CompilerGeneratedAttribute
AVP.g.resources
aR3nbf8dQp2feLmk31.lSfgApatkdxsVcGcrktoFd.resources
Copyright 2024
WrapNonExceptionThrows
calypsonian overturning sworn
weatherized sociocultural
dolloped pipiness beringed
Production garishness parted
.NETFramework,Version=v4.7.2
FrameworkDisplayName
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ajSystem.CodeDom.MemberAttributes, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089mSystem.Globalization.CultureInfo, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089fSystem.Drawing.Size, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
ISystem, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
System.CodeDom.MemberAttributes
value__
System.Globalization.CultureInfo
m_isReadOnly
compareInfo
textInfo
numInfo
dateTimeInfo
calendar
m_dataItem
cultureID
m_name
m_useUserOverride
System.Globalization.CompareInfo
System.Globalization.TextInfo%System.Globalization.NumberFormatInfo'System.Globalization.DateTimeFormatInfo&System.Globalization.GregorianCalendar
System.Globalization.CompareInfo
m_name
win32LCID
culture
m_SortVersion
System.Globalization.SortVersion
System.Globalization.TextInfo
m_listSeparator
m_isReadOnly
m_cultureName
customCultureName
m_nDataItem
m_useUserOverride
m_win32LangID
%System.Globalization.NumberFormatInfo"
numberGroupSizes
currencyGroupSizes
percentGroupSizes
positiveSign
negativeSign
numberDecimalSeparator
numberGroupSeparator
currencyGroupSeparator
currencyDecimalSeparator
currencySymbol
ansiCurrencySymbol
nanSymbol
positiveInfinitySymbol
negativeInfinitySymbol
percentDecimalSeparator
percentGroupSeparator
percentSymbol
perMilleSymbol
nativeDigits
m_dataItem
numberDecimalDigits
currencyDecimalDigits
currencyPositivePattern
currencyNegativePattern
numberNegativePattern
percentPositivePattern
percentNegativePattern
percentDecimalDigits
digitSubstitution
isReadOnly
m_useUserOverride
m_isInvariant
validForParseAsNumber
validForParseAsCurrency
Infinity
-Infinity
'System.Globalization.DateTimeFormatInfo+
m_name
amDesignator
pmDesignator
dateSeparator
generalShortTimePattern
generalLongTimePattern
timeSeparator
monthDayPattern
dateTimeOffsetPattern
calendar
firstDayOfWeek
calendarWeekRule
fullDateTimePattern
abbreviatedDayNames
m_superShortDayNames
dayNames
abbreviatedMonthNames
monthNames
genitiveMonthNamesm_genitiveAbbreviatedMonthNames
leapYearMonthNames
longDatePattern
shortDatePattern
yearMonthPattern
longTimePattern
shortTimePattern
allYearMonthPatterns
allShortDatePatterns
allLongDatePatterns
allShortTimePatterns
allLongTimePatterns
m_eraNames
m_abbrevEraNames
m_abbrevEnglishEraNames
optionalCalendars
m_isReadOnly
formatFlags
CultureID
m_useUserOverride
bUseCalendarInfo
nDataItem
m_isDefaultCalendar
m_dateWords
&System.Globalization.GregorianCalendar
(System.Globalization.DateTimeFormatFlags
dddd, dd MMMM yyyy
MM/dd/yyyy
yyyy MMMM
HH:mm:ss
(System.Globalization.DateTimeFormatFlags
value__
&System.Globalization.GregorianCalendar
m_type
m_currentEraValue
twoDigitYearMax
Calendar+m_currentEraValue
Calendar+m_isReadOnly
Calendar+twoDigitYearMax
+System.Globalization.GregorianCalendarTypes
+System.Globalization.GregorianCalendarTypes
value__
yyyy-MM-dd
hh:mm tt
h:mm tt
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Size
height
LwKW)9p
H#(JzUr#
0`*-Gy
yz5{fW
fq*,W/
0M%YWgrm
LRNtCjG
*BaM#r@jN
$l`6u
m.Pc=A
lT[Yff
[+[O10
@o <a<
2,!<b(
G$:/'"
acJy+*
-%2j9;
lC9$9Z
H$>X}aZ
ZQw=o4c
<~y$o?
Z>}>]{
dZ,b/W
0Lzm@+-
\.Tf$:b%
RsnvKpS
TQ*gE0
LGxBfQ.Am=
ppWG6!`
`pWRnZ]5
Y?Z&1G
6L/e/
Pr[y)5
61B)Au
.Gn{~w
h)P-V2
Zb>ad[Yl
3^^:;:r
5[lu^
zn2'T5
HR/Kgg
>G)4_|
g*{77#
HJDL9-
]!-t(o1>b
zTK.7375?
d0-Xsz
p!$K~@
b*FYMs
}4TnQ7{D
a6[0"n
3W|Ds_
*/IlQd
E+5' b
jfCSL7
|>XD%/
{t4y!o
z?87[Tz
VYw^N-
]fY{EX\
0h&t<W
e~D,m
{9!\agq
^aA.OY3*o
T-*UiySx!
sP9Q?C
I!A0mLymF
#[S-3h4
{YBu6"
(ERU5#PD
Jif6QfD
xzc.!I
oLBT0)'}u
Ul7azY
\Li`_R
3?DBh_
1s=$LQ!
}<Gdj,
rO0:&4
>0Yv+>Z
Br(EPt
@}aX-w
7/>8[Y
%}i-fg
VT=W]
.FY5,B
RV5:ZO
XRuWOG
58IsDC
UwWB/u
Q~]3e?
%3ut7I
8Lcgmbl
Y^?d)k
+6wfBP
4)uSw][
,505"D
dR*0IA
sX1Ewc
BA=+'!_
&CNPj-c
u@7:#L
e7Hy[E
;pnJHy
;U;*H*
~,$~,8<
r*U02C)[
$T2M|(
vQ.cKq
INO}`
9.jEd;<)
'3{ktS
x~,Z)E
4:gZ1<
$<}/X,
r IC:VZ
yK2ZM'B
CO.UQQ
=BAa?e
z>?ICJp
"g<=>Y
.D95s6aE^
ZT2;m
6Yi&!QtO
Kx|pdxr
mYmb*lh%v
DCI(lU
nos'rB7
KanZR}
I7/'[`
8/-Tx#_X
b_7~{rr
E:bA$?a
j>Tw~F|
wSsrDc
^yFPRR5
KyT2x1
KGW]"H
2+TM,>
>(?y~{
C[},rnmo!'
&9DBU2
($ BRa
kSH ;DhG
C*q;t}
YtN7GA
v5Ygt5
Jh(!Lw
T)<1;(
@,B;M3
Xayw-DXBWPl
s%'[&Q
,w*<9\
kVS6{p
0Gu#q)
FaM;Vkk
<+-|n
ZbIlB2
J:qqx^
H@Wd06
][h2;B
/aC+J{
t!)`bu
as\g7Q
{ZujG=
T@!.:.
yt#gM8<
!#6(.wG
c%'{SR`#
w:&rf/U
HSb%af
SFET9O
FBY{m\
`F\Yw<
],"?BJpM^.T
{avl5l
dOgNUc
O4-V+6
K;+?=B
f9Dan-
'{l2Mm
CMiau{%
byEs5z
J;M#!#
<+<b|%
Y1],8>
Z{v .+j
c>Ws #%M
7Ab4QQ
R`_/j>r
{p\N7}
E#*QlXm
i~*~r>
&JP0F2
@N0y;/
ce~D30
)[}H9j
gN+eaI
ZP)c0)*emp`
\)u]O?
{mvXt~
y!E]Dp
Y<Q[}6
I{}F:w
?]KbnX
*mR{0MG
=Yac6
Z$YnyVZ
NV0/n!d,
\1jm$88
[w|gn-
/y]~eW
Cp?r:_m
ihq`T-A
Z>T(YN
)GYS"tG
'jRwuuBo
a^}o!)
t6Q=&I
$5,UbE:
MOR`Q3
Q>pQvrM
cc!O%|
e[dz\Z
agsmlU*
SS.yqY
.Gi}?/
zI.\K_
>tIGN_S
r%vL(q
_dPmMe
D[)~!Fw
E$$<c$
PPm"&^
YulqAP7B
.p3\+c
GTcLAWr
AoSj2T
:=H#|5
;,G*`c
?Z@d3R
mk1N1|
*w'[t[
Ii>[',k
A,!ez/
lYc`Tu
e5FrV
%&3J(DN
-o9}]7
UjMX)m
xDJtYa
`?] LpT;&
eBna=Q
/S7z9]
QH:+yXhtm1
W9_`.V9
~!gYiu
V1#jwQ
+`Cg`@
FZ:^7V
s3zww-
oY*e)n
|J01Ma]D
`<:WSKl
*$ON&<6
Hi6y.mq
)65_{[?x6i
hD+4j2
Z4l ?hd
Q,I)dM
<UcN KZ
V0m g/_&`
"B2B!=Z
5RR|8"
UE|H0Fl
7JwzP+T!
f_8ZCX&
{C}&qD
A!{p`F
y5aW\z
-,:)7Z+B
iH'YvT
m8XaUOPh
seYB5N.T
Rv?Wd
$JtAaM
*?U*Yzr4
{5yrTe
^L=(N6
'RLlvP
)]9jZh
ADogm
5x*2I#
A/O.A9
5WBY(n
{4E|o3
gCGlL7
nthw9E/
Z:M$eB
39J=8/z
c|*7<u
e"cB3vg
sw@)AV?
5vm%eHXV
B%!_vP#
q pXoqVVw\|Z4(
1l^?]k
JB?A*f
$3_q_*
'w>K}R
?:z~*w
8(R-If
kP>V5D
6](Z
|]h#WG3
vOby7q
j5+@R)
Mq[MGD
RO[+N_e
hYHGb:
Bva=IJ
#7UMT}
^(Qi%v
#\W/Dw
6wbd5k
)4s3\P
G#{HTR
vM_5g|
n.gTG,
[}`aC!`~
>qkC?K+
i8Tza@
ELbRec
1SC#F)
7h_l~
rD>Dg?o
n795`eB
19-vsO
]+Il)Z4
}Sx*YD
kau)H;
{3)ASj8
D{Yt~,
-quhRC
?,5U_ki7Z
_Q%VSl
DBRfhn M
AVP.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
230113000000Z
260116235959Z0
California1
Santa Clara1
NVIDIA Corporation1
NVIDIA Corporation0
Aoi0Ka
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
joS&;J
20231102033749Z0
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA1
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
991224175051Z
290724141512Z0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
Entrust.net1@0>
7www.entrust.net/CPS_2048 incorp. by ref. (limits liab.)1%0#
(c) 1999 Entrust.net Limited1301
*Entrust.net Certification Authority (2048)0
150722190254Z
290622193254Z0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
T=A^C_(F
http://www.entrust.net/rpa03
http://ocsp.entrust.net02
!http://crl.entrust.net/2048ca.crl0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS10
221004172103Z
290101000000Z0u1
Ontario1
Ottawa1
Entrust, Inc.1+0)
"Entrust Timestamp Authority - TSA10
_Xg>gX
http://ocsp.entrust.net03
'http://aia.entrust.net/ts1-chain256.cer01
http://crl.entrust.net/ts1ca.crl0
https://www.entrust.net/rpa0
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
231102033749Z0)
Entrust, Inc.1(0&
See www.entrust.net/legal-terms1907
0(c) 2015 Entrust, Inc. - for authorized use only1&0$
Entrust Timestamping CA - TS1
evN`zrPCjCFhsBTKPqsovb[drSZhQVO@XoC_[NsBpyl[pLmc]wD`LmVB[eigWcmTnFPDzpjBypywp@oeaqJTRjneY@Dq`LfLLXgjwidhLBbVoZL[qCE
$this.SnapToGrid
$this.TrayLargeIcon
$this.Icon
$this.Locked
$this.DrawGrid
progressBar1.Modifiers
$this.Localizable
$this.Language
$this.GridSize
$this.TrayHeight
progressBar1.Locked
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
weatherized sociocultural
CompanyName
dolloped pipiness beringed
FileDescription
calypsonian overturning sworn
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
Production garishness parted
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Stealerc.1m!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Gen:Variant.Tedy.629705
Cylance Unsafe
Zillya Clean
Sangfor Infostealer.Msil.Agent.Vjpb
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/GenKryptik.HBHR
APEX Malicious
Avast MalwareX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Stealerc.gen
BitDefender Gen:Variant.Tedy.629705
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Tedy.629705
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PWS.StealC.4
VIPRE Gen:Variant.Tedy.629705
TrendMicro TrojanSpy.Win32.VIDAR.YXEIFZ
McAfeeD ti!FFB0CA6890B9
Trapmine Clean
FireEye Gen:Variant.Tedy.629705
Emsisoft Gen:Variant.Tedy.629705 (B)
Ikarus Trojan.MSIL.Krypt
GData Gen:Variant.Tedy.629705
Jiangmin Clean
Webroot Clean
Varist W32/ABTrojan.ELEX-2790
Avira Clean
Antiy-AVL Trojan/Win32.Agent
Kingsoft MSIL.Trojan-PSW.Stealerc.gen
Gridinsoft Malware.Win32.Stealc.tr
Xcitium Clean
Arcabit Trojan.Tedy.D99BC9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.MSIL.Stealerc.gen
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!785A37D8D627
MAX malware (ai score=83)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.VIDAR.YXEIFZ
Rising Malware.Obfus/MSIL@AI.90 (RDM.MSIL2:Z9rxBDT6CcS9M9gD371S1w)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet PossibleThreat
BitDefenderTheta Gen:NN.ZemsilF.36812.nm2@au7Z8cl
AVG MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Clean
No IRMA results available.