Static | ZeroBOX

PE Compile Time

2024-09-24 22:23:51

PDB Path

c:\rje\tg\vaog2vj\obj\Release\Qrr.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005ab44 0x0005ac00 7.99589564984
.rsrc 0x0005e000 0x000005c8 0x00000600 4.12185767193
.reloc 0x00060000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005e0a0 0x00000338 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005e3d8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
uVoZIGn
<V<;a
?-"SCv
2^'sUO,
d+h<,k
$zXA"Y
^-cGS!
g*,1E~E
kw<3la
er*^)zTk
$h"Tn-
gwgGo_l
!p4&)U
@!]gGK
R%)N,<lI
b\k{|Z
,TRb(4s
|.%)u&
ZX#}ri
NvPcd_A
/U#WrU
1io/aw
mxlm3_
E3}y*^
dIA*Ix
|u'?QU
UfjCC6
!,`j4Y
EorI`~l
eORjg<-
1o]%-Zk
Q~%c!O
~qb51z
1%DT'i1*
CPgbt<
p}YK/O
d)JK6P
~BekCf
J8G~=0
xI#alXv
a%]L4,j
sOXE3O
XMu=ApN#%"
Q?(6,?x
t$Pkn*
W((&b_
8Hybro
Y5DH`B
B@+)Nvv
[Y`"|(f/Y
3q>yf1
at9,>T
7J8/ff
+ZuLj
UJA0%.
bBIb'dB
'x@_(/M
T\0\R]
>N:)`'
lGPeiW
:;?$.at
o@$K4Q.
K#(wxv
fdGItd
wcjYR8
nb>? Q
]vr+S
_djz!3?
-daP>`
Y@ 6pc
0rC9JL%
dlf$cj
Hhl0L6
zE>JUO
}gQEQT
,20Q+-
W^tif%l
u9FM@U8a
"8MG:Cr
XjcrOM
jhwwm
:&cWgA
VC'7`NB3
`"CH?hyk
G3~c+\
r|!7rw
8nAn,&y
?b5ZmK
kRkb
u6g$2)
yCa!M@
%9_-'+
w[B'X,-I
0OS24Vd
xkYD~*
-]}-fxA
'Wm S\#
^|}jY`
Q(1}O=
T'@cV3
5M7<>ck
n=%NVsxn$H
!dO$,%
a.%t6%
:0LF4Zn
ouW/v~
LLYt?v
nOqgIx
AL\&WZ
NS|1Qa
"?7b3)
Yi%lCl
D|9({K
[c#+[lG
&[B;AR
xR(q|x
?lf_/D
{|SgAT
anWl6|
Ter:hO
SNH0wd,
^l_L[&k
@dDl>^
o\&PNL
;i||RiT
2u+j9{b4
7H.xn##
4w,pF~
!3("ho
>o?5uH
,0{3%{
6t/$"N
Ur{{)R5
3: quM
CA3e%i^
L9|!;E
+BmpYg
G6^Z$\n
u^N:SVm
}_0|'N7
0~gWu(
Qf.{3/
02+Dt;
/ds>r\40
&WJ,IM
g&(kT~
B7"vlN9
n>9GfG
h=h&OTrp
mb>TdQ
n7S"SqH.
szgy|y|
v[_xW_q
4Vvj!q
iA~%ob
t",#Re1^
-H_D7v
vRrt}[/
p=69Bv
lw;nja
aJFufc
zY/oNC
f,xkKK
0=iOoE
-'.x-Ke`Y
0Ci_%(
PSj+0<
J?67(^
?Qm[j8
,Rw/Iq
pk>t%1f
p&Nz**&"
M])G8R
O6b/~#
I+MP:
y3cl}XS
p|F;j2q
0 *uf[
]qqvKC
kk17qb
}$.T'!]
lFp'4X
oe&2-n-
pu.6X?
~G0u1sCN
Y8I?zw
vs(|TX
0%:~Bd
m[=9~
Ip^j@M,3K
0. \[-s&;
a9b=<s
wAY38!
M 6;4Z
\S/1=!
X=6m{ihC4=
8f&JTA
|#)Ig,
iT/FJi5
e4{D$M
cE<<R9K
).-?sc
CsNI!}O
LQJ,Q"
lE/DkZ
{b<BC>
wk+0bc07
z(a@vr_
JXN9sh
u)UX<l.'
D4[E.x_*
pS||V2
;y 9O"2
r|\"fS
bf~{1:
[B{Zf"
V4?NzP
\jj&lV
>*Z;&3
DO_f<:;
6aS<5y
6C&O01
SNq0EG
ICFq"~
I@;&nf
BEaa<t
LI{ I`9>
@;eE|Yo
Jpf3Zj
Ti8O~]
e0tH,
lQd;}t
B;I814
dWhr2s9
~'7Oq{
YIV+cK
8cdeax
dE5a*!
k%X*=Ko
>@00M%`
/KGuoIc
n8A+L^k
_r](W8u
Zy_x4t*
=e_BLpx
&K +ZR
-NBb)RKU>HB
&^@L^M!U
Vez6h$
+A~k4I2
Q<uQTy
f\yk1*
lhdp
0CE{va
-.S-^~m
/`=h*3@y2
*?5f|?.
;N:B[.
+DhWrcGD
7~oZpC
-3Oem!Y
9czls<l"
>FE$k\
BjM9BQ
e_$OSu[
{J`HQCy
+0/J<M%
ee[r;Yy
TLW}mL"N>Y
Z H'kGJz
_UNm*u7: K
1?[ncX
L$e,8T
!vntD@
4;t<s]
L3~e14
:nuK=6
&tUrAf
Gzh(hX
>"h6Rb
iZUogp0
|`ASi-
y;N^_+
's2oT:b
&QKx?w
K+o(f\
1@[p"C]
RKot+
?'%AiY9
]yP&)d
HCpF+?c
3_bJQ>
2\h@~v
Q>gfWG
KCj-NU
1m x7'
}xhs7:
5]a-ea
SU+P~g
~;*hBs
Ff-j55M
Am\[@G
2Hh`<lw
>tadrt]
54$u{H!
O8nfYwVc
y:2X8Gh
a:f@4=
T6X#6\9
{sELY[/
0eC% ?
P~W3"
Og%Hx_"
Z2rjRgK:" 8
N94TvH;
uA,P|H
kCq!B7n
I"r~hI
K[X#-h
{"#H]#
6NRUV?
1>eDh3
[IIVZj
]&9^0S
~$G8gH
(!E?t&
&IJ<b-
4/;@JQ
a;^KkJ
SWKo@`
^CS)QR
E.cN?V
jt*AMN
h~\,TbE
$Np3<rY:F
IQOg=ndpJ
Eni$K
i}(^'p
Hv#jfj/
woKc;]
UF(sj#-
7g$9Ab;
=Mz|mp
dY/g4k
H?}}/wWA4c=
MO{59w
F7Xq&PEB
Aly^7^
LqZ3/Y(
#@,1.l
n1^zfpN
?MvS|-H
.%m>,`:_3
@iT(KD
Gm,eE\2v
~!v!]4)Ag
bXH+,i
,)d(F@
9bL5')#
aa_e9i
8e'.z\
t?CN=&wz
!A0D4IcY
=pNx{}
Ms*&M^
85Xc*l
ejre;Q
r_`];Y1,
>YNDuA
P,V)Y~^=S
xXnKH(/G.
ozZ|c/
"MnUwSn
'6xw{#
~d6Pe6
p>T:Gh
KsK{("C
~5vM!4
mY)u9Y
@wU.ab
Ay^4f-
.yCmX8CY
J*MLOw
& P*K~#E`
*<Ph` 1
JsU:v!
~JJmCh
g!JXLK0
NCF}>h
.DAim#
]u[1L%
fW9jsl
<67C`/
CL3:IAPF*
6R2g{`
%7vd_38
IR3+h/{
`uXu#P
R0w$a"
[&f o(=c
!'|GPC
(T\0pb
N3l%PU%[
st=i'/
f<^ol_
9t\}QN
jmD<^z
q%Bf7E
J"<e&gP
yXb58tpXN
}IlWrm
w)-mT7
(TqQ`%G
gqG#*/L
go7{"k
N#oDqH
!N.&3D
s';CP5
dggw((L3
<=l*7[
iKYLQ4
[2,# v
Wl@$"
k9cIi,
sLm&A
?O>N.
\Ck\6P
e^g,n2
K?IcGg
AleWI:
dexoCW
S<MurI
{_7FEV~
4H<SaL
F9[w[ ]V
=O}.,"
__8{l!
VYs;\s
s>X(3&
p(Oz*yC
&d__mX
$@d#Lh7
m0AF'XU8U
"t{J^y
@*SLTSMi
T9<aj~
OK3KG~
WU_}"u
\<-m#o
/tp)78R
>sQijv{
0",y.c
K\QTj&
,|QIou_)
'i$Y]F
"Y#f$hY
v6T!xs,
x=V[FT
V+HwGQ
h}IkDp
Oiu<W\
u0J"}4c"#
EHk*"Z
&WWr!,,Kg
f%BFw\
Eob:.Z
R3[6}}
klsGTt
u,])j|
/P|Ym+
Pg?>p.
3=otW;`
RtS0o0
xnDX]v
B90t$M
(xRVu=
YGs/]e
k?%S)|S
P(>/3UDq
f:g/64
B}-}htW
p?WPt.
'(6J=7V
/;~hV)
q*@#)M
6JBK{R$sd
ke}&Z"
1/!r_d
1|EU>#
(w^GM%
^DN$Gi+
>,fG6\d
Pp',`
Vhntis
(GrfF
K*>Dwx!
!|!Vas
Pnkvav
x*+DKH
A_FoPT
/79ywn80
D~v?|D?K
JW|.Bh
]aKWP"kEI
Q}znd
,mUJ!-
Cy0dw=&
_V>k/y
q5gD2j
q-&0D@
GbIq]U
pYX6#H
jY#i09,x
'`-"wb
a1W>DN:
8Cb%KC
yZJg7]
!zLpKi
vG."q$
A,XNUl
@{*M[jvv
/TOEV`vP
xCC4hz()
;ls667n
+ }hp#a
YVa(kfXsn#
VK;8LO
qW#BZqC
G:o9~s
!%7q-Y8
&io}wc
SW#Edu
6c^)q
~":p2@
8[e9,h
U&Ke9n
D2w:/c
@sS{u1%
4E/_f`
.p?@f0
$=>%Yy_*k
hXN;lk?
;@Ky.'
[1h/K-
J-qyO+Y
;:\}}G
F&RMPY
K!jo|Xe-P9
8YB/t'
$p4C|;W
UN]CaA
g0%Vmj
L<':xp
}r/=X2
MvV2*T3
d0b;Gg
,d|Y^cah
j;V&P+|
yQ+ @}-w
.OS}8HIE
89`P~\}
]_7@-G
hvdl9H
g#zFM;
\GYW2/!
$$lo{#s
+To9.^
(0M&n#1
j*4_29
@-mLql
cbVrZ&
mQ'RZb=
5z'.eLn
kFU-$R
sNbw@v
dDwCzB
D[<3ufW
j^oq=A|p
:(N)D0G
rdKcY&
GS6F?u%
k^ :z;gg"n
sZqFHm
_DV@s4e
w"3]ZA
%k8uR)
2>,PO?
-*(3D%`
`s7.k[
2`vFhh
hPd?m*
>O> j %
^sRsH,Ab
8KD>_)uS
:Wlj8O
z(Abu7
<vQ"?du1
X!e:Z.
<f!9D.
aVep{?
Xv9Pl9
Z_yQUC
4;"I@~
F>]RAF
@:t)x@
1T= 2Sp
A:6{@z
YMcP7h
SO?,2R~$
JTbo<P
^}&MBq
99sZ7+m
}rlAWA
*$Rm_a
fG:a1oj
R{aovY=
K4>JQ\
Ft%}|X
#|053(
d1iSX_
TDS>|i
01,0E<
~Zz)[+@
8rHl@fT}
kvg-|b
gu$}5Z
d!LF7GI
2yLhgGT
3BKEC1
~i?rpI
\$fW`!
{5M:wd
)ZzFX]
J7UNlz@
L}%\oy+
0rL`XyL
+ns1wh
!M;]X[
%7T*b`
t8$]g@o
j x&jV
;A:=;e
\thY`_3~
~K6h]`
sTk`HQ
Kq}Zu't+_
9LLub;p
Ud/S*E
{f^i=U
Ge4F`_D
yZ"*Ir
)3StoW
$ <1i;
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
GCM.exe
MoveAngles
ContextManager
Resolver
Program
VirtProt
mscorlib
System
Object
MulticastDelegate
userBuffer
InitNum
returnNumbers
CallWindowProcA
SetAccess
_founds
isAvailable
FreeConsole
VirtualProtectEx
GetProcAddress
GetModuleHandleA
System.Collections.Generic
List`1
PersonalActivation
AIOsncoiuuA
GetComponentList
Invoke
IAsyncResult
AsyncCallback
BeginInvoke
EndInvoke
dceafre
jyrgetr
DSfdwertgtr
ASxewqrw
SAWSadew
founds
access
ZAzsaruik
QAwtykuil
DSsdsAsssQ
ASxcgtjy
moduleName
funcName
uiOAshyuxgYUA
manager
object
method
callback
result
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{8A8083A6-5BA8-4FB3-8D6E-FA912D5D4CED}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x6000015-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=364032
$$method0x6000015-2
Console
DllImportAttribute
user32.dll
Convert
ToString
String
Concat
WriteLine
Exception
KERNEL32.dll
kernel32.dll
TryParse
System.Threading
Thread
System.Core
HashSet`1
Contains
Marshal
GetDelegateForFunctionPointer
$$method0x6000016-1
__StaticArrayInitTypeSize=1196
$$method0x6000016-2
UnmanagedFunctionPointerAttribute
CallingConvention
.NETFramework,Version=v4.7.2
FrameworkDisplayName
brumbies precooker
holland revivify
pozzolanas goosier
amauroses frier
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\rje\tg\vaog2vj\obj\Release\Qrr.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Available updated:
Consulter
kernel32.dll
VirtualProtectEx
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
holland revivify
CompanyName
pozzolanas goosier
FileDescription
brumbies precooker
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
amauroses frier
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.AdwareFiseria.fc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Msil.Agent.Vzs7
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.HAXT
APEX Malicious
Avast FileRepMalware [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Msil.Trojan.Genkryptik.Ckjl
Sophos Mal/MSIL-WA
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!92F54F1548F4
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Clean
huorong Trojan/MSIL.Agent.li
FireEye Generic.mg.79903fe5b1c05b12
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/AD.Nekark.tqphc
Fortinet Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Phonzy.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!79903FE5B1C0
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.91 (RDM.MSIL2:FcKBssGIvW2QHN+KBWZxIw)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
GData Clean
AVG FileRepMalware [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.