Static | ZeroBOX

PE Compile Time

2024-09-28 19:30:45

PDB Path

c:\rje\tg\tj\obj\Release\ojc.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00059c64 0x00059e00 7.99523652555
.rsrc 0x0005c000 0x000005f8 0x00000600 4.18668975769
.reloc 0x0005e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0005c0a0 0x00000368 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0005c408 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
GyQZ;8
F2<_z?K
=W$_Dr
=Q=]IH
Yp{~m2b
m}P.C|g
_CEHY:
rI<@w*m
V]-.%{_
FH;K8/
+n/y'm)1
]@ww [
K4\8Ua
JVP)$wZ
"GNx|(
lDZL&
;KX&d
b.S`.Fm7
`c"~,+m
a3ku!`
J\^Jv>
*WPaW3Y
?{,A9Z
i]lJLU3TI
69[PO]b
z0k w\3
H0;{(.
0Jt$c1P~o8
}O,bfQ
-5Rikfq%`l
}$Qgic
'@.@[`
unDox]B
OJvfVh i
X271Wg
rqNg1V
.ln*q~
RG`=|MkR
6hD\<^<
C|VBLw6
R[F%I#
c!m"KD
%^Q>)A
Je27b5f
tEO*\wMk
)bh+}L_?Q
:#+X(y^
QTqQo*6
a;0,3O
E7ek@J
?my73A*
;kqZY
53eBZM~
q>|(9g
r`EB/2
CN18xB_
eSWSbZ
G998U;&
B}n8@7]
F&Qy7K
(vo[}+M
Ow\'%Y
^b#iU^
nX`[=!
,J-~JN
g'j[6*
k2J+v)
Kf+DU||
h7f3Z
xn_*XH)
:C((Wx
rcidnn
sYbe@G
-;PV<8
6,+WRh
GHchM3
b|6[Q~
NvhTDF#
NrBa#L
Ox<pUv
?i?TaJ
6Z1|Ft
.e!n"c
~;q+`;
ZRCF[-
y"n]mk
oBryY-
rW/gSX
<'uQIB
`]7G_u
|g,zjb_l
8[L3"9;*#C
{0,%AJ
Slv7wiAzM
1Cg0M|
Y/u4\)
uk +?]
OIaYuX9
KDU]eZ
NR9F2JC
]5c#I"c|=a
@O]xB+s
E-;0?H
WMdm/
!BoX]:b
vZ?b<UJn`'EA
4[38Z:
2YoLU2
6+GINWWt
!jG3wy
.SBfE
Oj#7ws
fmw;0nE'
rPP$!H
~mB`{X
o1"Oqvl
ojLC3k
86ujUf
MSU`ya
Yw,xk}
"szlJ0M
`58bih
&<+~fe
%-UoeG
nAZ6"un\
c0'12;
*Q^-hi
}_GEz9
%@,'3F7
%7zw?R6
DIb\i
^J\4I}
&|NxVz
TBZJ27+
Ih$"'8
/bA}UK
&s6J&>
Uc3PG%
zz\wWT
(R [p{
/]~?Zr
?!4G_o
f& s boW
$#EH,X7"
qKT8(9
,"x^^c|
Iua+l}
)$H2<)
HVXIpaA
8]&l3[5
||Vp34m
=C6c#r
e3j>C*
^%J>EqX
vv*\5B
haVh/Ms
ra &15
nW&:AFg
yneVVz
6iXu3m"
;BOCC
z4h*/bZ6
yv*+@B;
m//O)2.L
VJ\w$E
CgNNH|k
U*I)p
*0IOd
?{wWt$
wvTA.6
H0ug#|
""/uZN
MdFC<t
%DFg,u
}4%e4V9
Zkd~e.
(KK3(Ik
)F8M$iF
I?vo\x
Z&ent p/
CN_q%9
n}<c':
iD%+f#
0%goxq
lOi}'e
jFQ.#
(s]Qpz
r05pGbd
DW<V>T
>e@/<D
q}=YJ_
Vf!+2!
[ab~T)
y.sdG@,
:6+u:C]
l.W*Dp
r5*|zx
,vdaPJ
Bd&66=
m^'h%)_
nHu_"k
u$a?"8Z
,d^,@W
\q82vno
I[9J59v/
I$9dQ5
$}/9D2
7EluC"0
I/"2_7Re
N`^-ao
Dx;;'UQ
gYU:ky
ulF(mQL
1uaG4xTCF
wKcj\t
>K2js=s
ppNtc7M
?I!*x~
9Tt%O$
b`HPn2
8@NZIJ
s,UVkGe-
R8E<ov
rh'335
~9$-}P
^DD0gV
+=)Ql
J7|w=M
?"r93p\
R]&*AW
wz}%9f
g=]n9*&t
)qf#9E
G%\lH1
WjCc!r
3mm{=c
_EMIgi
EU*")MH#
&RS/nN]
eb`aHr<W
T{}w1%&
q$ugN{
$_eAi6
u$~+-t
WG!&6#Qf\_
*]k[47elIz
p4'H^G
lb.P5Zr
9.+T|Y
"m\{_&
1>J0^X
#Tdfs{|%
NT_>"4Q:
g(wjZ,
e8F-snrP
t_l*Jy
g0e\z%
|D~e2)
)F-]'P
#HrphF#B
Lrx0mbMg#g
/.yn58j
UF80'A
J%K7?
9-4gdr
tc|$i(
w$=fuc
6nH=E<
.{4lVFt
[Yu,v-
(9x{u/
&4je$I*2
sdgWBh
Y1~OXx
b[Z5e&
;x4`_}a!5
L;]K(:
7)_Tp[1
RoyyS)
+I!%bh`|
w+$7!kv0
VoKKSY
gqP3%j
m$Ta/o@
BUnq+4
uDesl>w
!D3RU(
{{mft1
^umJ_R
I3yie(
!CSGcH_
-v'~Au
Qv.[Zo,Wd
fa9xG`
jLg<:K&m
nm`Mz:
A}gP'dfY
){2oNHA}.
p?|Q{n'
F,gp1#E:
`|FLd
&"!PM>
)y<0JGo^}
3\+ZQG
+g-vEY
pNMHNx-!
ICUv9e
FsE]Jn
3.PR):
qf|!g-
&h5i0D
!.|d%^
DG@'oQ
28r9
D3b.\~
i flgE
7]^p_)
ggm4;]L
:D|7X*
$Df,<K
>'SmEQ
F>]LZ8Nd@
@PS\M`
h>;zK[,[
324*fK
LRD9=$
oTq/(h
i{3}PC
6k".iqa
3#b>U+
=:\Dt2
D}{j{~
<4[3LG
Q@Gz]}
,H/:hA
QFNV)W
;aU>;D
&m=7&
$OPOqA_
5"CmYe_
P]\4)b
G'&T}e
`C3)h
UgK=q\
vB2Wr
]P^QMoI
;5a>E5
AQS%xG
tXoCj)
A/#a[?
BPb>8m
&3C%#KL
~GqW'(U
i`U;Lp
Vt+/I+
@v,s4g
&$cNaeA
OnlRt:
j*?s}A8
]90#k;w
m.~:;{oV
CO64 gF
?d@r[8x
.?W[1;
e8"&SH?
{.%j@A\2F
yDbjKB
/@?SD@<
^|z6q+8{
H\NYRmg([
_/&#uo
C(]+;1|
5C:TV/B1
Ao_Rs
Tb35d2?
Z8a:o'G
h|,y-G8
Q!l%Ys6
qL9xN
S(\v)c?
et.&>e|c
WxGb9n5\
u2s]'&
]U)V?js.
K~m,{a
X#Rcwt}
{b&!v?*
42YO;J
k^&1lr\L
m#!9e\r
zC=>`J
&Ly,|0W
b&l(%:E
&ZLc&Dp
F)e*#"
ArmiE^
.4C:n5
~S5WZ@
v%R$*,>
y/R*R&
f)iMSq0!
@`WQQq]_
\}O0>1
^+C}LJ
Js*6Md
5=<37p
~6jBB3m
mf.FQgG
%=pR[M
.3; @eP
D"%\`$
J8n@%>
/Tj_/&8
D}93]i
I:Z*NI
g;H*Gm
vy0$*e
u7BdZl
F\iKwe
{6sj@*
cRltR_
c3`.Asa
%sO;kx
.6EDQ"
7p8Q"&
<%BTs/~
6<l)<1
|v\MB7
8+B`ek
mgC$sd
b%>-@2
thJ1aQ
r\,qa4
3,jj\
@""IAZ
t}R,'Dx_
iwH0A)
+6/iSI
{fPKr
,l9qH
U6Y_RH
|bx21e_
Xg8g{uC
@"Vz|
AM:C1g
Z{)&oy
e+9J%~S
`F.SST
Ry]bN|
A]EQE@W"W!_*
g2A Zx(
+z&ku$
5Q8DtY~
7'yc0$+
2Szwv[Gn}
UU{*eO
zW!|<
1bg2V%
6h$g(5
w\,`M#T
eHVSbH
*0x_vux~
: i@.
j3wPM&
=iL~XzT5
2yr6]>
NK4s!
dc9:mj]
,3>#,p
PhFmQN
E]eU99
9jUJy
\J-<=aV
)# yor
j9=k^4
|(Bp!Ur
KgPZFN9
94yV}Md
yH%p=a~
-<Pc cVul}
&!F)tg
zn-LO1
MQQ&D&
|>"}tB
~J5{ H
%px(<#
r>kN#`qI
2Yi~y^
zbPG45.
P:?3!//
A!6d&+
Tv|_2l
_6ll}~
NN6O9OX
qcu?d6{
woB507O
Rm!M-V><
|}^kd@
w#U[=6
]3qu3-
1\9"]s
_G*G_%
$$A+N6
9a2_)J
P3rS/f
=7mo6p<;<
`h1G^h
x$`R$^
4G=[O
6!JZx'r
n%6yvu
Pj~a@VQ
SFH.77
Kg$G'[Xd
oJLeKx
Y-]kkA
@'[qs+
yZrohZ
~lJ|R.
djpke)
jkJwy6
$(RbEv
:c+&p<
VY#vW~
`/EN3W"
V"apui
=6_hlf
^i:@q[
B8W"Ue
:"y 6W
4kYFl
i2qs|J;Q2
%[sua-;
D~zI($
ux-F5xf
bJG0 A
-Q3?,rr\#{
ep`F}a:
H@ht,2w
3'N"M,
8XJJTaq
.s3V=:
l|o'pE
;1_^M!
#;Nc2t
[\tS.m
qWFxk'
,9BM<4
ZbA$+T
i"HxT)
C;lgP.
h:ynA|3
\}z']m
TScgPt
-cwU*q
l:_Ts&
<M-#h}
Z2:;%1
ub0G<|hBk
qtG`"/
AH``4z
#tLV-cz
zl5aWT
rwEx94
<`LD[9
?sQepg
@yrn/
*aEkr?
z|\0KI
q.|"0j
G3$}-D*v;
q6(`'I!KEf
,Z)$TO
8X(7S%
_^2{c(
EElCYIL=
S-jl4,[
/3=__
@{*XE,(
9\OGEK
bgV8Rtk
Y-Ykjo
~%je)O
gU%>,pePh
\sBr/R
<d\Sfj+#q
LT#nq$
JO}[r+\vg
SN&ig}
*aq.e(QB5
6"R&XC
0M5PAX,
oZ{d9>
D*vQSj
l[)$9N%07
/F-yLf
.CSgpb
*kkJii
8Q61lrF
Nfs8AI
+rW8]%E
`ts`'i@
aVEi5d
evw~f|
%;(A0h_
GAl5W6
XHJ@^m("~t
Qt{~9JW
VAhjVG|
<\ICI)
Jj!c{c:/
E$.xHC
;kK~b~6
Jbe)]ei
2v*!0K
,M#RWZv
p?a}ctt}$
68J@v3Q
]hsp(Is\
q5xvW]
]jJwK,
~D'IQw
^_QM{O
GP}F{x
ywjuc~>
x;--d4
f!r3aO
q T]fA
GJn+7f
A&p'h[
~NbYbO
TRI};}
PxcNCr)/.8
M.="POs
3JI17Y
=Hh``\
sG'"PL
i!O[.r
GYrPz,].t{]
=qW}v[s
$ <1i;
? M7Zb
I lSI0
K {_}*
?,5U_ki7Z
_Q%VSl
v4.0.30319
#Strings
<Module>
GCM.exe
MoveAngles
Resolver
VirtualEnv
CallPr
Program
mscorlib
System
Object
MulticastDelegate
userBuffer
SetAccess
_founds
isAvailable
Invoke
IAsyncResult
AsyncCallback
BeginInvoke
EndInvoke
FreeConsole
GetProcAddress
LoadLibraryA
System.Collections.Generic
List`1
MemoryUntil
AIOsncoiuuA
founds
access
object
method
hrtgrefer
dwedwe
fgercwe
jytryhtr
frwcwedwe
callback
result
dceafre
jyrgetr
DSfdwertgtr
ASxewqrw
SAWSadew
moduleName
funcName
iuoAhdiu
uiOAshyuxgYUA
System.Runtime.Versioning
TargetFrameworkAttribute
System.Reflection
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
AssemblyCultureAttribute
System.Runtime.InteropServices
ComVisibleAttribute
GuidAttribute
AssemblyVersionAttribute
AssemblyFileVersionAttribute
System.Diagnostics
DebuggableAttribute
DebuggingModes
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
.cctor
rivateImplementationDetails>{9FBF6BC9-9E92-43BB-872D-E08DC6AE6C96}
CompilerGeneratedAttribute
ValueType
__StaticArrayInitTypeSize=16
$$method0x6000012-1
RuntimeHelpers
RuntimeFieldHandle
InitializeArray
__StaticArrayInitTypeSize=360448
$$method0x6000012-2
Convert
ToString
String
Concat
Console
WriteLine
Exception
UnmanagedFunctionPointerAttribute
CallingConvention
DllImportAttribute
KERNEL32.dll
kernel32.dll
TryParse
System.Core
HashSet`1
Marshal
GetDelegateForFunctionPointer
$$method0x6000013-1
__StaticArrayInitTypeSize=1196
$$method0x6000013-2
.NETFramework,Version=v4.7.2
FrameworkDisplayName
coteaux
stinkards planula subindexes
poppa tangles ritualizations
stemsons unshipped outsmokes
Copyright 2024
$375c5eff-0650-4301-85ef-382cfefa9adf
1.0.0.0
WrapNonExceptionThrows
c:\rje\tg\tj\obj\Release\ojc.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Available updated:
kernel32.dll
VirtualProtectEx
user32.dll
CallWindowProcW
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
stinkards planula subindexes
CompanyName
poppa tangles ritualizations
FileDescription
coteaux
FileVersion
1.0.0.0
InternalName
VQP.exe
LegalCopyright
Copyright 2024
OriginalFilename
VQP.exe
ProductName
stemsons unshipped outsmokes
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Win.Packed.Msilzilla-10036350-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Artemis!A6B892D48AFA
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Msil.Kryptik.Vrpe
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:MSIL/GenKryptik.ca400620
K7GW Trojan ( 700000121 )
K7AntiVirus Trojan ( 700000121 )
huorong Trojan/MSIL.Agent.li
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GenKryptik.HCCC
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Gen:Variant.Ser.Jalapeno.35
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Ser.Jalapeno.35
Tencent Msil.Trojan.Genkryptik.Wwhl
Sophos Mal/MSIL-WA
F-Secure Trojan.TR/AD.Nekark.udvtf
DrWeb Clean
VIPRE Gen:Variant.Ser.Jalapeno.35
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXEI2Z
McAfeeD ti!569F4E10B81E
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Gen:Variant.Ser.Jalapeno.35 (B)
Ikarus Trojan-Spy.LummaStealer
FireEye Generic.mg.a6b892d48afa9410
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.IRB.gen!Eldorado
Avira TR/AD.Nekark.udvtf
Fortinet MSIL/GenKryptik.HCCC!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Stelpak.gen
Gridinsoft Trojan.Win32.Packed.dd!ni
Xcitium Clean
Arcabit Trojan.Ser.Jalapeno.35
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.A!ml
Google Detected
AhnLab-V3 Malware/Win.Generic.C5675682
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Malware.AI.2195289062
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXEI2Z
Rising Malware.Obfus/MSIL@AI.88 (RDM.MSIL2:nFgxY6j7J+VDijtZb0CHgQ)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Gen:Variant.Ser.Jalapeno.35
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Sabsik.FE
No IRMA results available.