Static | ZeroBOX

PE Compile Time

2024-09-26 03:42:10

PDB Path

c:\rje\tg\\obj\Release\e.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000680f4 0x00068200 7.99665957977
.rsrc 0x0006c000 0x000005b8 0x00000600 4.11796767253
.reloc 0x0006e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0006c0a0 0x00000324 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006c3c8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
NWp|H_
i["kAJOH
p!<'Jh"
31ptty
@9VT$L
<$!=$:
>Vx\%(
II12R6
jAN/>J
<?%<rZ
AHZX1!C#
Rwq|V@
L;:8x,
\{P-PE-
)-@gXf
R~(q&-
]YY{so
/EeYOl
nkL{(m,
D7lc&*
2A3I?0h1
4jgH%64
+[~,Zs8
T!V:|&a
dieO-b
V(g&&`
o\E*QH
zO %@,
H("y#j
.U61:W
e&2CkJ
Tw0_U3
E?a"aCj
Bq9v<C
y@YZ+$
iP85j;N@
vFx{"T>
R,IRVpI
}6:w8]
$`+O~I
SkJuz<
L%dZ(
3'q;Zw"
u_r'uu6
EeE3jU$
7Yn'JM
5F^kk@
*)@+ER
(wIQv9
E03fgY
A#drt:
&.1(E5A
l'$G L
V]GJHH"Ht
/>M0mr
qls`gJo
fkzVj$
]oj5I\@
e/$=gp
J+ Rt%]
lRNr9$
mAPu?5J6Y
FoE&-B
L[+vy.I
~vL!OD
(gCJCyh
RS~YGm
46E9yj
,P]/P&
dKr?<+
ROn-Td
v1I@.[
'@]|D
dOvPG&
aZB4q#
?)hB9c
o@3Bj~X
({/=3x
3^yCeD
%{$]:5q!:
&Z8xw)
H{|_V*
-FL-f!
I"E[l{
-$*9R+m
W\P>%;
QZ9Jqg
~\m aI
J1`@<L
m"]")
xGC. n
Zs+Crc
{5!sRg
y_:A)"
z(vnT9[
IO1!gtvCp
%G_Ka{
m7{=g|
*.Is=P
k$%-Ol
-~iJV^
6`o^/2O
D,iK2%
r6msm@X
TYU8_}
ZfVH5>
vb6p8|
\VnC?9
TVR&w:6s
}^UN-d
^](+F$M
Odt52,
( 4R|q
IqK{LV
_|*W'
<jOu=k
m9#:`>I
k{+Z!c
%u<GwF'
nv=YT)j
h_C93R`
blr4IT
+ &W!F
CbZ}P,
=oRweg
tEHAtV
6;";W%{yQ
;R_*hL
_/eN"J
)BceZ"V
QcQ20URH
d0$i7Xs
aJ}AT4\
~\f\G@U
$k+Bk
_?mW$32
)0X5s0m?
T7F1iS
t L)zt
uq~nIT
%ZgBsd
qX+lxL
;OgEgT
T\OX/2
u}Za*0T
qS$car
~+e&>q
bohyr6
*h>VaB
H_Y>jy$
<0\v(n
UKp"=fKyA
UbE!;T^
\t57f8)
ukYE;8
v1!tC,DA
Kf(qPQn
#<gX5t
Km0q[hN
Gvm.Ej
,b~#4Z
)_C6K]{
(H&JtK
p'wqf>m4:
x+cMI#w)Z
!*x0sa
NE?eue
O|w))8
u^h>)l
`-"|9j
\(cy#Vy5_Bx
){aJFlA
T$Znr>
E\Oab{
^:@*k1
bVG|;'\
K!C]r
60fL_ !
Dj\YuZ3
KhvDEc
|,w)(O
n\Oq1X
!~Cz$|T
#ydVHK
i4-3HW22
`0#('mE
jjTZPO
J/QE%$)PT
P'5R$O~
V.XNnT
re+C\L
O*H~db
U=It.R
8zryT>
1`*fw^m8
(]v(|CN
]`B<#p
atinnw3
=UE.==
rCFunSo
WsV%`)
y3d_t7[
rx-0YA
-G<G/]C1
CM$c[-
9*bxLz
_s68?V{
I9{gh_
h|GK`Ch
R?+W|3
eM`*O>o
'?O+XYA
P=/6]C^S
z]Oa?<.[
wZD8+:
(4uJ"8
*XG`rTpM:
~b`+&R
7GX$n_
L|'T^e%-
aq_LGg
fl3(+A
zDnlT`f
c]KZ]h
yD<vUB
15^87.B
MbkFav
_Fv[B#60G
xC=VCK
[0DEc\
5B4D \
Mq(6`6r{
|~6@4c
^}x4P&u
]R>bQ:
A5|>W&
q{Y>]2
TYhLkB&
u@qZEAFX
5Gzn@][c
;!hPc^(
$~[7,[V
?;llliJd
/\U?9KM
)<0qx4
s_7h\i;
VIolN#
/,WuCM
uId\gpB`&
iRxOG"
7ipeU@>a
TSNZ{"
)+wFv2
1A:VG0
-MN1\Mw
tZv,:R
RjB3Eh
us$4)0id
U=`$Do
%gEV=2
aMwFNnu
cI(AZx
DX]BfQvP
:O2FpR
q;=]@|
cs>)^
;bY5L*
,|#tT3#
r0>KgaZV
RFFjPh
6;?<0Ud
WAMV,{
e@Qs9v
>d/m%M
.UhBvL
XiBNg+
9a|ysXFW
6vH,F_O
}xZ|5&
{Srj_?
W{r%"vcVw
2zZD!
FkqcOk
eI"4up
6cT{qX
`*N\67h
>xX&1
aXPEb<r
I2]>f9
+7V]uX
#7%g3K`
N$jg qKd
%=-}\.PK
BndkpR
wOM T,
/VoRc
nY6Vfe4
Z[pwztG
W&@(?P
|}j9Zj%
nPN+'z
VSfUWH{Z_i
,VeQD!
Lxrv&a
n)LK4%
fLNy!p
)pjp5,
Avmw+mr
lulAg]
Wq#QKQ
{)Zq_Y
(F.utlC
Rz:vj1
dp06/rG
CyK.`a
<~w'Y5
PSb4wI
.X^^/qXs
qZ}[9^l
/=9(/32
xq"~N8X
JbuL{
q6OY1
^54uD.N
\/P<~#
i;]Y^L
N+U].Ax
2$_&kN
:^c@.r7Zo
e2oFLV/Ak
9:t3C-
T32>~@.
/P9-P;]
$Cr5%,
ZM:&o=
.q7KR(
YaA_CS
m$ok8/"D
]:@1oo
#*K3&C
;R{fC]
OLv|tH
E3^Drt
8K2=z)p
s+-9Uz7*e
'.,8&#
X;rxf`
>m2 0*
H1KP$ B
R!8pQ[A
qu(TC+
V/*$"s
"M{n{t
ji|/%g
NQ<-_rsW
P4TY<=
E LtqeTE
KL4n(|
CH<^BB
OkM$)V
kJ638`
^4b0i7Z
#VOhzRp.[
+.j/3r
d&[z$0
*|cn#Ml
YM?_f5
yQ:Kh`
+[tWbD
sfkvi#
Eip?c ij
b,kD(
";/2U!]]
2c>x3+'G
9UoOg
A8l2gG
t/O0kW~
x`>dYq
}sj.[t
XL}#5B
J6, 9n
6D0mLh
ba\W_5
RQC<A)
tQ;}z
UY%i-A
)(&`K.
[aa(G%sR
0TW9|;
lvc{IN
ZR=.Jaw
#9|(6v
cK.|RJ
--y9rW%
e;3v1<
JiCzk^.
#brnPaA
FxD\~i
f=O$[?D
b)l[7.:
#gF#te
81TA}Q
Nf9%Kl
7wJOUN
["{%y0
YVl*4
y|<u,p
6iHm=
P?-cx^
SCSG1|
o1WH0k
Q&)Kg-p4
_wr}f\
dTFIw_
b)'cX3
3vrW f/
",n5Vz
%r_*i^
$yd~T|
O--n>l
ag~#l=
g~pj"J
m! /KXP
<6]kUh
tMM0vt
%1S+tU
xSi(>p|d8
I|,rbA1%D
|Diy9d
Eqvguo)aJ
/}W\eTP
8If_jD
>2VYw*
-n,h%t
_,jrfc+
B@Hpw"
&e)iO#}
c*</$=
(bO2FIB
UE^"Av
h[%x?Q
E1jKv&
J3^HTq
X6{{bI
BN#"eZv
99Kr&6
iTmK[:
ta7Ro\j
j8BTwQ0
@"u:jF
sX4(X"ifAtc
pJ3KaN
Z<GHK8
{[DPql
.WrsMA
gV1(6yn
DSN)sD
C6)@*
5aSbvpz4
/9}L\/
mksuR)
}$r Yg
oX74\~
NAQ8Ye
}bK+7F
w/J"xQb
EZ;m],V
A05k[n
AQi{U5
a|*$eyE
fK~(&3
:__1L
] {~\R
5q0n%qE&Z
_eRt*_
Cr*@&c
?=uCP
m_6Sl
0lZ@q9
znH$/#
6luHS
K ./^#
:O5FGR
N5pX,3
e9e@'x?
Mmhw$-K
[N5x;%4OJ
Xnc/_f
\YJ*<b
2A[5 a
Pz_0G
`?&Cg7
R~s<z$
0nRXtlh
F_{.%Je
(NK1@OQ
ZJ`GA&
*1-IoY
N"E2"#
D97~AsZ
GvY!"9
t|{l$Q
.@r!_5+
W]K@Rk
O2@.wa
.t:w-J
%(&zR#
DhI>D=
1)}Fi@
p3$=Xh
T"UHl1
bfLd>
KG]]5,
y2B/3s
rc,:drs
tR#m~:
Q<,:Ac
!4,F;K
kwoOL9
@/i@rq]
3)"eM
G;P-R:
;ZrPzd
ihb7h9
LG>Uy<
pKbS^a
yBkT]~MF
*vmxId
n!H.!Wq[E
B,3f{H-
jcZsFh
';N2.;h
&V{FCI
+5umsHd
1DW#L.
Tu2\?]
o'*PYD
Wj,lHo
+ERrwK
E_O!05
v%|+I+^iWy
{sD:IE
v_5jk#
)5tn7>:
|w4W)t
C0xHh/
Hr)U?q
1-`?`\z
^H3L:K
qfL.~U
$S*T@t
}v<ohn
bo<2NBu
ghMq29
cA ?cO
6KS5T5
>'_tb)
#{@Q3{
v X]WA
<Z$_z.
}`.?h^
8+f i+
4h_gy*
1pkq)h
Fgu<z/
WJWPT|J<
Tv~<8N
B}}>3a[gIF(
G0'Oa~
O5Ck2tMsS
8Q~gIU4
fh$fhMe
&WvE5I
jgP~MsS#
:..{bE
vrXRc0`
R'|+3\
N}j[+5SC
G]{cc_5
2Qt@*d(
k>RG8'
4,{h!6
*]80E2
Tu<m/_
#{y\'h
NKi!*E
VY`'Qma
V$=G"j=
oc1-dn
UvqhMg
}Xg@*:q
%W/lC#
`$plO?F#
#rA'/{}S_
Xtnin=
1{_)6(u
J*gJ%4
m<V6UOS-*u
J:p^KM
}?!8k])>[c
.-tYgz
6zL^$R
cl0Zm
%H3e5W
Qmi\: R
Bf{o%Q
,f*Htx
EYu1{{
?>u-q5>
_DD|yK
K|<_HEQ
1.QKP*Z$&
XISREQr!A
T-e+BR
,n^c!d
xJ,N/
Ua`m"
q.$sk6
VGZ&?mA
hLEf4B
K:d)%"EB
Tb'$ux
p+GUY
/>Rmb>"
<9BbX^W
I&4AM;
*KlMkEp
_@.IiE
"gOmWr
sY";ucM
p@xQa
5MzMsuip
GoIgW'#
J0y'e)0
S/Pg+/
FA Jmd
dN(9V3
X9(fk
pd@wPj}
K'N]d9
Qy!t%P
m]Dt>f
LDmJ6
4w[(5C%
qcCLT5e
[sHSxJ]
LgM4X}
>*O_f%
:$k$/k&
ER=:RB
r<l 1r
+D3},)
Lg'Gy%F
IZUekP
('I Cl
b_Y347
b<xJi]
yd(r}&
BDuh)T
s,p\Z
#,%hY^{
LK>Yw6Z@C
x{GJ
TqL^d=10
BRdJ~v^
-m(:<G
Bkj23
s c8SFk%+l
QVvk5XL6c
6^jY=w
]6@}>w
ubYvJ7faZ
TH~#fK
i'z=vBo
cMwj T
3kaW[l[
2%#>lR
)$u=`+F
;@14nx
'5NVSCN
DL`^2UWI
>ephOo[
/ch@}-
V_bI?q
Mi<IjnjY]
zhx)qX
0/S<Cvc
|T+@r'
tY&m]zM
MYu&Lw
w4@#{K
laFC5_
+$#IX
A^lzG<
H@m&,g
g1?fW:Ty
6VK1o:
Yi*H%,
cx:6~wvn%
0J?aD!oVy
g-pF$3
]3s<x}u5
!xbgT#
g?!YEqKD
gi_j5P
Y03l&Wx=
:8RQ.z
qS8wLN
afbr*U
Ji&GDU
r[rMUJ
JAijvp
+z9f3%
[c}lp
c4C%02n
b4i|%
D9aCr=
N4Thm
zU0@'E
MHp[,$,y
<p^!v=~
,t4<~4C
-:P"b
_"iai{
y98nV}^
r_Xkt5
~_oRZn
2Z:f4>+d
HS&I2,
Ogm=f
YI=N2U}
dIWF_|$
}B%[]2d
>R[S@<
ibn]->T<
66X]#IfA0
6!78vc
,9`O.{ATx
\{p80
Jn+[}*
(WAh5D
+{o*|`
;dCZuE
cAIi-x
pla]NhV
;6_NYZ
{;.}GY
zcJAL$
:Stf%3
i(mw5p
7aDpy]E
|D=c94
J{~^wXL
Y|-i48
qSnZZ]^
'z\&rVS<Q
+_wZZ(
B$(b\eWA
7{E27;
B:xfiyL3i
$ <1i;
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
GCM.exe
MoveAngles
IaunjsklsnxbNZAiaq
Resolver
SAdrewgrtyjr
Program
mscorlib
System
Object
MulticastDelegate
userBuffer
LaunchDataValidation
returnNumbers
CallWindowProcA
SetAccess
_founds
isAvailable
Invoke
IAsyncResult
AsyncCallback
BeginInvoke
EndInvoke
FreeConsole
GetProcAddress
GetModuleHandleA
System.Collections.Generic
List`1
PersonalActivation
AIOsncoiuuA
GetComponentList
dceafre
jyrgetr
DSfdwertgtr
ASxewqrw
SAWSadew
founds
access
object
method
hrtgrefer
dwedwe
fgercwe
jytryhtr
frwcwedwe
callback
result
moduleName
funcName
uiOAshyuxgYUA
manager
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{6338E07E-7D6E-4F33-96D4-0D213361FA96}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x6000014-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=418816
$$method0x6000014-2
Console
WriteLine
DllImportAttribute
user32.dll
Convert
ToString
String
Concat
Exception
UnmanagedFunctionPointerAttribute
CallingConvention
KERNEL32.dll
kernel32.dll
TryParse
System.Threading
Thread
System.Core
HashSet`1
Contains
Marshal
GetDelegateForFunctionPointer
$$method0x6000015-1
__StaticArrayInitTypeSize=1196
$$method0x6000015-2
8cn}3O
.NETFramework,Version=v4.7.2
FrameworkDisplayName
Sorrowfulness Uncompetitive
Asana Metallize
Technic Griff
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\rje\tg\\obj\Release\e
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Available updated:
Consulter
kernel32.dll
VirtualProtectEx
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Sorrowfulness Uncompetitive
CompanyName
Asana Metallize
FileDescription
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
Technic Griff
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac IL:Trojan.MSILZilla.146906
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender IL:Trojan.MSILZilla.146906
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILZilla.146906
Tencent Clean
Sophos Mal/MSIL-WA
F-Secure Clean
DrWeb Clean
VIPRE IL:Trojan.MSILZilla.146906
TrendMicro Clean
McAfeeD Clean
Trapmine suspicious.low.ml.score
CTX exe.trojan.msilzilla
Emsisoft IL:Trojan.MSILZilla.146906 (B)
Ikarus Trojan-Spy.LummaStealer
FireEye Generic.mg.080774ce0bc02b88
Jiangmin Clean
Webroot W32.Rogue.Gen
Varist Clean
Avira Clean
Fortinet MSIL/GenKryptik.HAXT!tr
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit IL:Trojan.MSILZilla.D23DDA
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.Injection.C5674188
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.81 (RDM.MSIL2:+LxfSljFrodIpg+PIPEc8g)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
GData IL:Trojan.MSILZilla.146906
AVG Win32:PWSX-gen [Trj]
DeepInstinct Clean
alibabacloud Clean
No IRMA results available.