Static | ZeroBOX

PE Compile Time

2024-09-04 05:42:37

PDB Path

c:\9qehe\obj\Re\ease\gqa.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00026194 0x00026200 7.98934857018
.rsrc 0x0002a000 0x00000602 0x00000800 3.47344974167
.reloc 0x0002c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002a0a0 0x00000378 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0002a418 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
otqzjHZG
LK@)bKYV
6vt&+uq
1>'k*
b2F32/
OKcje@
Y@$`%U
!en61X5r2
O+(4;Ju
\4LNG^
fLb<[>
W"3p5'
1qX+j$
Ui?|lDg
=MuK~C
pmGcmm8
A@WSq`
NN\6=$
7TeKt$
70iHHi
O@ExBe
~yu>/d
g'IRhI=
hhm\W
UJRjn6ap
PWzQE7
bm*7K=
@rR~1K#&
5Iy@W+7
xfw7j~
YiXpc;
}|<Cn8,
p77T9hd
"1LBgN<
y~>CG
bjwZ{T
;*"{.n
6z'}d?
w].+`X
IYw_@H
/!VvPPT&k
kpJi<y
2:e+d:HH
)tav<^x
W.PWe )
Ox~+?b
3VB#h[x
(w.Ycg
,~seNC
PGKDvf>
:dwy.@
N<P8j?
Szqf|n
1Qjjn$
8MS+%Hk
J('6W*
7}h_,Qg
m<WAbS
(t}eV//
4O`;Rh
?L{]`x
y}Ob a
5#,sX
v!;Hr6>
!BY?Mn:
GSeec^
TW+C80V
x?lOz*
cVdO~2.`"p
$1b4O>R
psS}@g
NQ!2Sy
$A.j%R/%
bu~_T5-*
v6!k:Y
IdM?V_
wxB}HE
_x|NU#h
J<?u2/1h@
F-]pb?`
-H5lq[
BT\HF~
\[+EdI-&
d]T2#{
n0vN$R
~V`sN{9
l({P.m
/TBi?m
"J0yeK
9\OH;A
UHFfMHM
h"iR<p/
yG*^8-
P7A/07
iFZzF4
gyt~i?*
][7^$I
$L-'bIv
;Ltj94
lH_Gxg
PLjgB#e
lO)@HF\
,wHA5*3
w1$}T+
uYoEd"
:*8A)P7
[|eK>u
aN(k<h
7|}% j
^ fxh?
M?Fd<d
eWN7/s3 #
pRfJ!L
[e)WL\
R({|Ct#
#)%t1=S
`Tc*a z=9S#
/1m_p
ZCm]"#e
cFM)4B>
~p$Rzvy:
#(Mzyjq99%m
qBhNt5
aQ\j$v
Fr=u8t
ck.t*^
\9Py6v
H]v.:
{8 `JbW
SC.T.I1y
q@8`hz
IB]fr.CZ9
?2b:~>
-S=R1#
3r])"f
9/Q449z
2]'6`<
HlD<+H
.G)NPH
q`x|>(B:
po!6!5
/5"!0K
ic3mn)
xfi!*v
.h?bt7
c6OTu
"+R0H2
c8BD+lAqo
v0-V61C
v%b8|!
]GJUf%
ax{8!tw
>.q&IR
(?=FiI
A)aA!sy
zuiN+E
XF.uA9a
DNFS7O
(8?7m;~
:>wjB
L!\Qgq
y}^Ev:}
t*_o#R
!{F^N|en
QSi%!&
Fub/U$m
/T/Y0J
5` XJY
x{q2jet;
ae}+\h
+@mRSw
aq&F0x
xVn' 4
L~h<:K
[kT{y@GqF
2HHk8~S
rF\&_F
:3jC+q
Lbwj.4
(fU+:G
fP6B8x=:
b$_OGu}
T<L`bn
D*-LjPH
js=lU<7
SkTL%#
^<e5o
^^i{vr*[
vv^S*:<
5@JN&+
[/2rx7
ty{A7/[|
B$.PkZ,
6SKZEC
{F5,%|g
+5\=/~
-_f<db
YAbvXM
XzHD+{
7^K~TN
3/i:"z
*|}i[g
8y<n7X
7Am=qqh
niaza<
<1 |uJ
,h),tC
E %>gt
Ws^Y${t
t3UiL[
NCI"(3b
PLl`U
3gm1Nu
l;]GgJ
p>n`.K>
4?#!Bw
6uZ.eCq
fNj=n6d
0UY1TB
:qv{,$
CP!j}B
T.f'HC
TN)2k,
JZ.cF6}
*LxF1tK
~}0/6d
}f\9p2A
<w\ydc
9cW_Nt<
gr9u8>n
TFaB3>h
7/JSH(
Mgi2 3$E2^
V:Br+c$
f^5v5m
P]efIG
>OA3M$
~^d<md
$I-Cz8D
^jD"R^
86gXOm%s
6q!*N3~^
Gn7sIH
{Z\[ns
)3_|.SV
!x!.>!
\f.|y"G
mcKNm@y
]JMb(~
aFHFr$
%>$8wmj
xexbLv
QU-1Jp
95h~Sp
t'Woha
ojafEuf
aT8^_V
-Jk(Fk"
W`+CSM
%['5zt
HOo*,ER
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
AVP.exe
MoveAngles
ContentJoiner
Program
mscorlib
System
Object
userBuffer
MakeSign
FreeConsole
VirtualProtectEx
CallWindowProcW
LaunchInitProcedure
AIOsncoiuuA
AUIShsuia
IOAUshiuxA
SADthhjty
uiOAShiuxiA
ASrgrty
jtuygertdr
fwergtrh
verfrew
wedferhyu
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{58648647-E735-4D09-87FC-BC55480DA441}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x600000a-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=150294
$$method0x600000a-2
String
get_Chars
Console
get_Length
WriteLine
DllImportAttribute
kernel32.dll
user32.dll
Convert
ToByte
System.Collections.Generic
List`1
get_Item
Exception
get_Message
$$method0x600000b-1
__StaticArrayInitTypeSize=1196
$$method0x600000b-2
.NETFramework,Version=v4.7.2
FrameworkDisplayName
Sincerely
Bollix Vivisecting
Production unsolder
Beknights Recommittal Bashings
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\9qehe\obj\Re\ease\gqa.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Security Init
FileVersion
10.0.19041.1 (WinBuild.160101.0800)
InternalName
secinit
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
secinit
ProductName
Microsoft
Windows
Operating System
ProductVersion
10.0.19041.1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.MSILMamut.4!c
Elastic malicious (high confidence)
ClamAV Win.Packed.Zusy-10035770-0
CMC Clean
CAT-QuickHeal Trojan.MSIL
Skyhigh Artemis!Trojan
ALYac IL:Trojan.MSILMamut.13721
Cylance Unsafe
Zillya Trojan.Stelpak.Win32.715
Sangfor Trojan.Msil.Kryptik.Vtr6
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:MSIL/LummaStealer.26947df9
K7GW Trojan ( 005b9f261 )
K7AntiVirus Trojan ( 005b9f261 )
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.HBFX
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Stelpak.gen
BitDefender IL:Trojan.MSILMamut.13721
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILMamut.13721
Tencent Malware.Win32.Gencirc.14191cd8
Sophos Troj/MSILIn-BFQ
F-Secure Trojan.TR/Kryptik.eptzf
DrWeb Trojan.Packed2.47854
VIPRE IL:Trojan.MSILMamut.13721
TrendMicro TROJ_GEN.R053C0DIA24
McAfeeD ti!A8B4FB8E5E17
Trapmine Clean
CTX exe.trojan.msil
Emsisoft IL:Trojan.MSILMamut.13721 (B)
huorong Trojan/MSIL.Agent.li
FireEye IL:Trojan.MSILMamut.13721
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.IOI.gen!Eldorado
Avira TR/Kryptik.eptzf
Fortinet MSIL/Kryptik.AMFU!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Stelpak.gen
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit IL:Trojan.MSILMamut.D3599
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Stelpak.gen
Microsoft Trojan:MSIL/LummaStealer.KAP!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5665865
Acronis Clean
McAfee GenericRXWP-BQ!C3555FFA2618
TACHYON Clean
VBA32 Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R053C0DIA24
Rising Malware.Obfus/MSIL@AI.98 (RDM.MSIL2:NfcgCpRPYFzlrHLlrO8CFA)
Yandex Trojan.Stelpak!jeVGZIZe46g
Ikarus Trojan.MSIL.Krypt
MaxSecure Clean
GData IL:Trojan.MSILMamut.13721
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/LummaStealer.KMD2XJC
No IRMA results available.