Static | ZeroBOX

PE Compile Time

2024-09-25 01:54:34

PDB Path

c:\rje\tg\\obj\Release\Qrr.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0004e944 0x0004ea00 7.99482910332
.rsrc 0x00052000 0x000005c8 0x00000600 4.11719821962
.reloc 0x00054000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000520a0 0x00000338 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000523d8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
BL#fD2
bk34Fs
e#Y'lv
Y.Ey'X
<c$]o}
~J$6.mPe
t[P{\O;c4
&\13/H{
X?Rcw_f
;7pJ4!;s
s(0,(;
~F|s%v
euMrkh
e0<^pdr)
b9@h\G3
*@q7M3!
yc:Z=n
"LUJ{5
k[OCv?
31qthd
Wu="3P
:^AAf=
1[ujC=e
79w4WVK
2)nbm0
E,sNlq
+EL>i#
#YfsRb
jH|MI/
@!:V63
rgj>U
(<Ny/iv
jB&kz=Z
n[r!ac,5Zp
aVD=by
"=%M.8
_8a*Lz
uFN#6j
iNt{]g
v,6*NZ
2gJ1UE;
G\tSs_(
d~62[V
6]g^xOJT
bS7tGEn
+]k`>h
26|s4s
H.4@a\
vYC3%,
xX?(bO
L0/^ e
-EdeE]A
GOSv6`U
6`wOuI"m>
ejF!;j
A3`;}(
VF.],n
gdJ2}p
%,RuQ>
(jYCQ\_:f
VKp(k&
?/fy*
/sFjyjP$
o2{-Fc
B9>hjK<
P1lTU#?
u[[(|~o
)Um:$u
w2f.uL
<0yvmN
2Qq3.y
e;oRmy
I}dKO
Pr\{i>
4 QoTK
:4o8fS-h=
EgMA Q}T
$JBo4Q#_v
;}2Eju3
~,0)-
}[2?1J`
k%kMUntu
(`>;E*
~y`B.PX
8I!>oF
q8i/S#
&GJx=mv
R{1m\]
--??j@~
D^#u{m
W~a+-I%
g-|*J\
b$5YL]
+35f$~
u&o@X
Y\.[TF
U;FXl`0
zmDM`|
]UW^{L
^l..T3Q
R'o"[^
}!Y3&vT
*:xP5B}Y
qkNE?@
fDhP7A
C BBtd
6^:TXh
xMV3{Hh
kgq)$/
+If#CY?#
3d<)dT4
jT_Z#h
^UzcC|
v^vN6a
oowsX
%vtG!S=_
Dh;z~Au
{PJzB6
_r[-`e
mvtl2i
Iz.|Aw
w_ht2X[
m;NT,p
x0u1!vs
IG@$]Rd
&^x&LB
("Uf:A
Pq{xLJ
5}&cmn
S5ko]4C
=S,Q`.b
<\?0J\
5/sQM^
<l6dSO$
^5cE2
Yqb/$2
R1B~/xr
icMV6n2R
96)AUb
qK-',2
71:"8BtH
kW'~J9
|)e@B-
r~CZB>
&zj%?C
xn2jx`
ZZe#'~b
NR#~@K
pC"KdI
BRQK<S
);_Fi/(
^=8l\WC
,c4?]u
D\8&Bw
*g(,qr
.5.nNT1
KCroM)
Tq9V I\
@y}a!B
fIc#5wo
d_]]G&
_m%QM[8
f^o2JD
saH/dwF
oU65p"
_X5d_
d%{x!y
-{/Q*p
%fAK[[
7t_oG
VdKITK
lkP'0P
x9%{c"!#
%5V&cAs
DhR;3Ld
Ia}Ayk
FgYpGg
U:$@|/
0A/]A
Rg9}Sa
^bJ0=.a
G:{fO0
a:*6>q
{*nl`#
~:}?sQ%
hIwT>z-
-$lTL!]cX
Qa8G-U
AMMFi9
;uz|.@
.78bu4
RG~j}$(
d_Q=9R
LO3?/8
typCaw
l$S%w0
8ijdGH
cY3=RO^
dlELKY
ArlN?x
*Iv +PT
,CNf'I
z4`6{[
2V*bp#8d
#9?LBQVQn
?@"C(z
v{eP"I^
`?~(Y_
GgTP2$
6%L.\c
O].:M2e
>j1{cX
`g_BQ"hb-
(-V3u\
`B34pH
P u3QC
p\ #)J
R>r3>'
heE,$n
EjNd+*
_S ^\y
aG!c:Vi
ol'sxT
5r^''8Ul2
vj[T}X7,k
RNs29I
@gcTNXu
j?Qk![
h$\K^b>
%}lB<ZJ
ir^8uS
jHlx9l
O+)AEjY,
_;]VPr
X({kLj
uNc@z.
j9i/ |
g-O{(s\
r{=l#rYM
#*?0sf.b
VJYN@Ka
m:Cp@)
hu}~`O
3gO{0L,+X
u[K8m?
uKlKe;
s/+08s{
chjqAHC
UCp\zd
okQ}Jz
$Wj9:V
p7@v``;
<D|09k
Y`1a[^a
|h#nP*5p
zb)ih5>
Yb}3kB
\Q=,{l
.=_mv|
~j'X*Z
x{T/8
%.jO;_
EYV\Y1
a'f)8?
9U_6#K'w
-4{d,>
m){,}\
W^|<t:
r|F%P3
gL0Qm+@
@hB^Un
!Ex(ao>
A]'zA*
VtM9s0
L!??PAT
73igA?
nTfj!?4B
:RH9j9
a7(Vf;
//j7o"
/=tm^i
6o9gZS
2: .&f
7i1.f:
;w,S-V
BUAj0cx
y?=iGGR
[:g:7E
y4tb+@
pwO\}~dX
yTVwW}|
Z53zDz
PyD_GX
d"7yZNv
Q+y(ze
tb`>Kj
";zU7j
]#=!%bk6z[
AM/pr-
}%H(Zb'.
x"m \S
,c`K%6
/cCKLR
R8\Ecu
8zrL5U
MGo7*sgA
p_e(0a
+<z&NI
f=[{\z
;p I=<}
-xkE&M
,sL)F9
D=EB6A
gdTan5
_"{7>y
aW'jw
>yp[&
j.@ayET
)3DsS,5+k
Amf Kb
\znMw[
8`H2Zm6
T_Fi%
:5idQX
=gIET!
f7-xKa
puV&T +F
[Nm?pC*
LsT$K!
Yds_zv
wrh51D
O,!(Fq
cl/'$/
}|R,K"Wp
p54C}.
b2uo>=
-/#9Xc
UyrqO
1X!dVe
j!{*B.5
r6l?sy
OcH(6k
HWUyZhc-{U
>rLB7:Z
oSxN^C
%hXN0Z
sA)NN:b
O09d<*
lyXF$2
=}8wi
- E5#{
d!Ms_K
L~#_'ocP
$3pRSG}
O:ZAoi
mFlKRX}
w%$+Q>
V\u65d
K7$,e2
J36t2J?Nq
2HhG9[
A#cw"
RpzbC?
] X3:wdu
zu[N?'Uh
#!p|K#
&vpL!1
"<*vb9
9!RI.E
ldd~Bf&pMLKx7
RC/+3k
$po.r]
9q18B
__DrCg
55m8V?ZNfF
O<hnY|T0z
);H`9C({
8>j2[8
i$mOoB
;`!>j$
D\agm/w
ZZ~IOR
D%Y<.[
%oDb]G
vkNe4d
+UFdG*5
*r<P`~
BG^G7R
XLxy?uI
5D4,.a
YF[3'h
CbU?n
@j"Nq1|
Bd8+^H
mYxn/W
bPy/EN
a:Ac)0*
Kj["j<n
g*3OPf/
Zn<A2U
pDG%=W
4&U_Sr
v4tu^.
^ ROG,
cq7;Tbv%
A4I_)[D
UKk.IG
ap#<r%
~%c}bY-auE
!=brdm#
BJGQ<#
"+/EK)&
HEa[i/
5xV7=L0
_&<%rV#
MR\;u)?!
^4H8n`
l$khd4Y
:HtH2K
.S~m`G
0i(:P3
:`:BsZT
:iJbE~
VH8s/^f5
{j,+m-lY-1
I8)Y"u
:zeuT4
289@c@\
h7nQkNKA
FuHFKJ."{
=`<mF_
4Rf(Y@
~K>^gb
*r>M+V
zy<?>$
=7LRj38^
9z+PrW?1
D6v9u
&pnZbC
MPP_sT
.@m(Lp
8%T2Oj(
EkfV] (
|jWmxct
7~Q4%?
%/j g}
>2B}5*
$\|a[],
[K~Y'K|(
#zbD-B
bD*h9q
cL)dH]{X
EK !ir$^G
gJ+e'ed
:N1/bmuu
f?3MBO@
KcaS+Jt
3<iSJ~lt
!R)t:ZZ
*;re*B
i/":h#3
-M.WpB
$kQ!R{r
9&:Y(
l6Rs_U
!/ty0L
L,W8iu2
'!t~Gw|
\V5"2[
HBl_&o
tyBtq"
svy.Br
w=G"
UoNfoga
?oS"<8
5`w"[&
OSt*AL
Poipsa
1o_8hm
5gRuU:{
J]UY&v
3cvtPPw?
S:rPkE
{o_["/
#.r<BO^
W$L65)
q(ifdS
he;vP
pp[*K.
,.XO[J#
YzX2]!
1x'Gnj
G1CNqf
z@$=#$F
NR8U^[
lz=~aH.
Ng G6!
3$%`v\J*
Ev0vE3
[q O$P
VIeq;E
Y,zh1a\V
-02m2",<
x}@x!\
v<G6+9$=n
|MqqPn
fBvv-V?
88:;X2
"C:X"{
w$d&ihW
<w8CT2
d<x X}
X#7#~I
(/bCpg
fI(=>^
n.S?rC%
iK_Azj
9Z\*m|
0m:40a{^:.
8RS%U}
Hjj:|Q
wfP-I0
Nf"*_z
#4Ph5y
Bgs0H"
T|OFI k
d{BaP?
[yX(yz
ur!8)K
"b&{j%
N<IcC]/.Gx"N
M0UG+H2}bX
PtuX$^
#'!/9~
5]c;SV
[1X^dA
iBQ 4g
$ <1i;
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
GCM.exe
MoveAngles
ContextManager
Resolver
Program
VirtProt
mscorlib
System
Object
MulticastDelegate
userBuffer
InitNum
returnNumbers
CallWindowProcA
SetAccess
_founds
isAvailable
FreeConsole
VirtualProtectEx
GetProcAddress
GetModuleHandleA
System.Collections.Generic
List`1
PersonalActivation
AIOsncoiuuA
GetComponentList
Invoke
IAsyncResult
AsyncCallback
BeginInvoke
EndInvoke
dceafre
jyrgetr
DSfdwertgtr
ASxewqrw
SAWSadew
founds
access
ZAzsaruik
QAwtykuil
DSsdsAsssQ
ASxcgtjy
moduleName
funcName
uiOAshyuxgYUA
manager
object
method
callback
result
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{A2F10016-F43F-47D6-82E7-501D573B8804}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x6000015-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=314368
$$method0x6000015-2
Console
DllImportAttribute
user32.dll
Convert
ToString
String
Concat
WriteLine
Exception
KERNEL32.dll
kernel32.dll
TryParse
System.Threading
Thread
System.Core
HashSet`1
Contains
Marshal
GetDelegateForFunctionPointer
$$method0x6000016-1
__StaticArrayInitTypeSize=1196
$$method0x6000016-2
UnmanagedFunctionPointerAttribute
CallingConvention
.NETFramework,Version=v4.7.2
FrameworkDisplayName
brumbies precooker
holland revivify
pozzolanas goosier
amauroses frier
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\rje\tg\\obj\Release\Qrr.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Available updated:
Consulter
kernel32.dll
VirtualProtectEx
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
holland revivify
CompanyName
pozzolanas goosier
FileDescription
brumbies precooker
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
amauroses frier
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.HAXT
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Mal/MSIL-WA
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!0AD3BCA28149
Trapmine Clean
CTX Clean
Emsisoft Clean
Ikarus Trojan-Spy.LummaStealer
FireEye Generic.mg.a1c72950a28756d4
Jiangmin Clean
Webroot W32.Rogue.Gen
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Stelpak.gen
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A1C72950A287
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.91 (RDM.MSIL2:s5MhKUovJ1YOn96fppzeJw)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
GData Clean
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.