Static | ZeroBOX

PE Compile Time

2024-10-12 20:38:01

PDB Path

C:\Users\SERVER\Desktop\MMOParadox Expansion Launcher\cabal\obj\Release\cabal.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00013a64 0x00013c00 6.51029968417
.rsrc 0x00016000 0x000051d4 0x00005200 6.09451945549
.reloc 0x0001c000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001a620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001a620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001a620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001a620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x0001a620 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x0001aa98 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001aaf4 0x000003c4 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0001aec8 0x00000306 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
BandwidthList`1
ToInt32
ToInt64
<Module>
SW_SHOWMAXIMIZED
get_ASCII
System.IO
DecryptStringAES
EncryptStringAES
get_IV
set_IV
System.Windows.Data
CHashData
mscorlib
System.Collections.Generic
CancelAsync
RunWorkerAsync
baseId
diskId
connectionId
videoId
biosId
Thread
processDownload
pb_download
bgWorker_startdownload
forced
_contentLoaded
get_Downloaded
set_Downloaded
file_downloaded
RijndaelManaged
add_ProgressChanged
bgWorker_ProgressChanged
add_PropertyChanged
remove_PropertyChanged
INotifyPropertyChanged
Interlocked
add_RunWorkerCompleted
bgWorker_RunWorkerCompleted
Synchronized
RootGrid
<CabalMainBuild>k__BackingField
<Maintenance>k__BackingField
<file>k__BackingField
<Hash>k__BackingField
<UpdateHash>k__BackingField
<CabalHash>k__BackingField
<CabalMainHash>k__BackingField
<hash>k__BackingField
<UpdateRevision>k__BackingField
<UpdateVersion>k__BackingField
<Hashes>k__BackingField
<Settings>k__BackingField
<count>k__BackingField
<maxCapacity>k__BackingField
get_CabalMainBuild
set_CabalMainBuild
cabalmainbuild
ReadToEnd
Append
UriKind
get_StackTrace
get_Maintenance
set_Maintenance
CheckInstance
defaultInstance
SetSource
source
FileMode
CryptoStreamMode
MessageBoxImage
CalculateAverage
get_Message
get_Percentage
set_Percentage
get_ProgressPercentage
percentage
CompareExchange
DnsFlushResolverCache
Invoke
IDisposable
ToDouble
RuntimeTypeHandle
GetTypeFromHandle
DownloadFile
GetMd5HashFromFile
get_file
set_file
Console
set_FileName
fileName
get_MachineName
get_UserName
GetProcessesByName
propertyName
launcher_ininame
appname
launcher_hostname
client_hostname
DateTime
startTime
WriteLine
get_NewLine
Combine
targetType
get_Culture
set_Culture
resourceCulture
culture
PropertyChangedBase
ApplicationSettingsBase
WebResponse
processDownloadResponse
processCheckResponse
GetResponse
Dispose
Create
Delegate
ConfigTemplate
EditorBrowsableState
Delete
LoadRemote
SaveRemote
ConfigRemote
remote
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
XmlTypeAttribute
XmlAttributeAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
ValueConversionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
ThemeInfoAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
XmlElementAttribute
XmlRootAttribute
XmlTextAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ProvideValue
maxvalue
wmiMustBeTrue
Remove
cabal.exe
get_DownloadSize
set_DownloadSize
get_KeySize
Serialize
Deserialize
file_size
LastIndexOf
mgr_cfg
System.Threading
get_CancellationPending
ASCIIEncoding
add_PropertyChanging
remove_PropertyChanging
INotifyPropertyChanging
is_working
IsRunning
running
System.Runtime.Versioning
FromBase64String
ToBase64String
ToString
GetHexString
set_Formatting
System.Drawing
get_Hash
set_Hash
get_UpdateHash
set_UpdateHash
ComputeHash
get_CabalHash
set_CabalHash
get_CabalMainHash
set_CabalMainHash
GetHash
get_hash
set_hash
updatehash
cabalhash
cabalmainhash
GetTempPath
get_AverageBandwidth
set_AverageBandwidth
avgBandwidth
get_CurrentBandwidth
set_CurrentBandwidth
crntBandwidth
get_ContentLength
set_StartupUri
fileuri
ConvertBack
processCheck
pb_check
bgWorker_check
TextBlock
add_DoWork
bgWorker_DoWork
PresentationFramework
ConfigLocal
set_Cancel
System.ComponentModel
MainViewModel
user32.dll
dnsapi.dll
System.Xml
System.Xaml
FileStream
GetResponseStream
CryptoStream
MemoryStream
get_Item
OperatingSystem
SymmetricAlgorithm
HashAlgorithm
MainForm
ICryptoTransform
resourceMan
TimeSpan
AppDomain
get_CurrentDomain
get_favicon
get_UpdateRevision
set_UpdateRevision
get_LauncherRevision
set_LauncherRevision
launcherrevision
MarkupExtension
get_OSVersion
get_UpdateVersion
set_UpdateVersion
updateversion
Application
ResourceDictionaryLocation
set_WorkerSupportsCancellation
SupportCancellation
System.Configuration
System.Globalization
System.Xml.Serialization
op_Subtraction
System.Reflection
ManagementObjectCollection
add_UnhandledException
CurrentDomain_UnhandledException
ArgumentNullException
SystemException
ApplicationException
LauncherException
innerException
MessageBoxButton
CultureInfo
get_StartInfo
ProcessStartInfo
DirectoryInfo
txt_info
Crypto
server_ip
dir_temp
System.Windows.Markup
OnStartup
ProgressBar
StringReader
StreamReader
TextReader
get_FileDownloader
set_FileDownloader
downloader
IServiceProvider
MD5CryptoServiceProvider
serviceProvider
StringBuilder
sender
get_ResourceManager
ConfigManager
launcher
identifier
IPropertyChangedNotifier
BackgroundWorker
bgWorker
ProgressChangedEventHandler
PropertyChangedEventHandler
RunWorkerCompletedEventHandler
PropertyChangingEventHandler
DoWorkEventHandler
UnhandledExceptionEventHandler
System.CodeDom.Compiler
grid_updater
parameter
StringWriter
XmlWriter
StreamWriter
XmlTextWriter
BaseConverter
IValueConverter
StringFormatConverter
BandwidthFormatConverter
CheckFormatConverter
BitConverter
XmlSerializer
xmlSerializer
ManagementObjectEnumerator
GetEnumerator
.cctor
IComponentConnector
CreateDecryptor
CreateEncryptor
System.Diagnostics
get_TotalSeconds
get_TotalMilliseconds
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetInstances
System.Resources
cabal.g.resources
cabal.Properties.Resources.resources
DebuggingModes
CHashes
get_Hashes
set_Hashes
cabal.Properties
GetHostAddresses
Rfc2898DeriveBytes
GetBytes
CSettings
get_Settings
set_Settings
RemoteSettings
ProgressChangedEventArgs
PropertyChangedEventArgs
RunWorkerCompletedEventArgs
PropertyChangingEventArgs
DoWorkEventArgs
CancelEventArgs
UnhandledExceptionEventArgs
StartupEventArgs
cabal.ViewModels
System.Windows.Controls
cabal.Functions
wmiClass
ManagementClass
FileAccess
GetCurrentProcess
get_ReportProgess
set_ReportProgess
IPAddress
set_WorkerReportsProgress
ReportProgress
reportprogress
set_Arguments
Exists
System.Windows
Concat
Format
ManagementBaseObject
get_ExceptionObject
GetObject
ManagementObject
System.Windows.Markup.IComponentConnector.Connect
System.Net
get_WorkingSet
SetTarget
target
sharedSecret
get_Default
MessageBoxResult
percent
WebClient
System.Management
FrameworkElement
newElement
Environment
LoadComponent
InitializeComponent
get_Current
dir_current
FingerPrint
fingerPrint
get_Count
get_count
set_count
Insert
Convert
WebRequest
pb_downloadPercentTxt
pb_checkPercentTxt
MoveNext
System.Text
plainText
cipherText
set_DataContext
get_Now
SetForegroundWindow
MainWindow
ShowWindow
nCmdShow
MessageBox
Display
ReadByteArray
ToArray
get_Key
set_Key
System.Security.Cryptography
get_Assembly
CreateDirectory
set_WorkingDirectory
get_CurrentDirectory
GetCurrentDirectory
get_maxCapacity
set_maxCapacity
capacity
op_Equality
op_Inequality
CheckSecurity
IsNullOrEmpty
wmiProperty
set_Proxy
IWebProxy
WrapNonExceptionThrows
Rif Cabal Online Launcher
Cabal Online
Rif Cabal Online
"Copyright
Rif Cabal Online 2018
1.0.0.1
.NETFramework,Version=v4.8
FrameworkDisplayName
.NET Framework 4.8
PresentationBuildTasks
4.0.0.0
3System.Resources.Tools.StronglyTypedResourceBuilder
17.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
17.11.0.0
ZSystem.Object, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089ZSystem.String, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
ConfigTemplate
RemoteSettings
AnonymousType
UpdateHash
CabalHash
UpdateVersion
LauncherRevision
CabalMainHash
CabalMainBuild
Settings
Hashes
Maintenance
UpdateRevision
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP#
G/>jGy
888888888
>iV#@.
NNNNooNNNo
'uAAAuuAA
TbXXbT
LLLLLL
cLLLLLLX
LLLLL,
TbXXbT
<cabal, Version=1.0.0.1, Culture=neutral, PublicKeyToken=null
clr-namespace:cabal.Functions
cabal.Functions
cabal.MainWindow
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
x,http://schemas.microsoft.com/winfx/2006/xaml
mc;http://schemas.openxmlformats.org/markup-compatibility/2006
converter
clr-namespace:cabal.Functions
d2http://schemas.microsoft.com/expression/blend/2008
MainForm
Title$
LC Cabal Online
ResizeMode$
CanMinimize=
SizeToContent$
WidthAndHeight=
WindowStyle$
AllowsTransparency
WindowStartupLocation$
CenterScreen=
Icon$"
/cabal;component/favicon.ico
Resources
%cabal.Functions.StringFormatConverter
PercentageConverter
$cabal.Functions.CheckFormatConverter
CheckPercentageConverter
MergedDictionaries
Source
/Resources/Themes/Generic.xaml?
RootGrid
ImageSource$1
+/cabal;component/Resources/Images/cabal.png
txt_info
Updating Cabal Launcher.
Center=
WrapWithOverflow=
TextAlignment$
!/Updater;component/Fonts/#Calibri)
Normal"
29,40,22,0q
grid_updater
25,65,22,0q
Center=
RowDefinitions
pb_download
Center=
dProgressBarTemplate#
IsIndeterminate
0,3,0,0q
FileDownloader.Percentage+
OneWay=
pb_downloadPercentTxt
Center=
Center=
!/Updater;component/Fonts/#Calibri)
Normal"
0,3,0,0q
FileDownloader.Percentage+
Converter#
pb_check
Center=
cProgressBarTemplate#
0,3,0,0q
ReportProgess.Percentage+$
OneWay=
pb_checkPercentTxt
Center=
Center=
!/Updater;component/Fonts/#Calibri)
Normal"
0,3,0,0q
ReportProgess.Percentage+#
tEXtSoftware
Adobe ImageReadyq
"iTXtXML:com.adobe.xmp
<?xpacket begin="
" id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:50F6D99629A611E38A99CE37F8D7CABE" xmpMM:DocumentID="xmp.did:50F6D99729A611E38A99CE37F8D7CABE"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:50F6D99429A611E38A99CE37F8D7CABE" stRef:documentID="xmp.did:50F6D99529A611E38A99CE37F8D7CABE"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>
BYgYq^
U&u-Axc
HLM[~eqj
*l~SVa
Vga-Oa
Ds}}Mo
Yy.$'T>
2mZY #
6qJbq /^
t6bXFqEf
#GN(qd
xby'.}
J>\>:-M
%LQ\0u
R/#WO.m
EZZZb_
viiiYi"w
Z___8s
NWindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
XPresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
SPresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
NSystem.Xaml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
TargetType
DownloadProgressBar
Property
GrayBrush4
Value
TextBoxBorderBrush
dProgressBarTemplate
TargetType
CornerRadius
EndPoint
StartPoint
Color
Offset
Effect
-System.Windows.Media.Effects.DropShadowEffect
Color
ShadowDepth
BlurRadius
Opacity
MappingMode
Triggers
Property
Value
TargetName
Angle
cProgressBarTemplate
9http://schemas.microsoft.com/winfx/2006/xaml/presentation
x,http://schemas.microsoft.com/winfx/2006/xaml
Maximum$
PART_Track
#FF212224$
0.5,1&
0.5,0&
#FF151618
#FF151618
#FF17181A
ProgressBarRootGrid
DeterminateRoot
PART_Indicator
#FFA10F0F
0.5,1&
RelativeToBoundingBox=
0.5,0&
#FFe02021
#FF860303
#FFe02021
Orientation$
Vertical=
LayoutTransform
IsIndeterminate
DeterminateRoot
Collapsed=
PART_Track
#FF212224$
0.5,1&
0.5,0&
#FF151618
#FF151618
#FF17181A
ProgressBarRootGrid
DeterminateRoot
PART_Indicator
#FFA10F0F
0.5,1&
RelativeToBoundingBox=
0.5,0&
#FFff7315
#FF8a3700
#FFff7315
Orientation$
Vertical=
LayoutTransform
IsIndeterminate
DeterminateRoot
Collapsed=
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
G/>jGy
888888888
>iV#@.
NNNNooNNNo
'uAAAuuAA
TbXXbT
LLLLLL
cLLLLLLX
LLLLL,
TbXXbT
C:\Users\SERVER\Desktop\MMOParadox Expansion Launcher\cabal\obj\Release\cabal.pdb
_CorExeMain
mscoree.dll
G/>jGy
888888888
>iV#@.
NNNNooNNNo
'uAAAuuAA
TbXXbT
LLLLLL
cLLLLLLX
LLLLL,
TbXXbT
<?xml version="1.0" encoding="utf-8"?>
<asmv1:assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
</application>
</compatibility>
</asmv1:assembly>
MainWindow.xaml
127.0.0.1
Error while connecting to the updater server...
update
update.exe
/client/update.exe
/client/7z.dll
7z.dll
/client/SevenZipSharp.dll
SevenZipSharp.dll
/client/System.Windows.Interactivity.dll
System.Windows.Interactivity.dll
mmoparadox
/cabal;component/mainwindow.xaml
http://217.15.164.94/update/
resources.xml
cabal.Properties.Resources
favicon
(kB/s)
Downloading files...
Downloading Launcher files (
Checking files...
Checking Launcher files (
0l}i{HE%-6QhfnYbQ1BxXxtVDCLQB/oY
loaded.
Failed to load
saved.
Failed to save
plainText
sharedSecret
cipherText
Stream did not contain properly formatted byte array
Did not read byte array properly
o6806642kbM7c5
Percentage
AverageBandwidth
CurrentBandwidth
Downloaded
DownloadSize
FileDownloader | Download timed out!
CPU >>
BIOS >>
BASE >>
Win32_Processor
UniqueId
ProcessorId
Manufacturer
MaxClockSpeed
Win32_BIOS
SMBIOSBIOSVersion
IdentificationCode
SerialNumber
ReleaseDate
Version
Win32_DiskDrive
Signature
TotalHeads
Win32_BaseBoard
Win32_VideoController
DriverVersion
Win32_NetworkAdapterConfiguration
MACAddress
IPEnabled
Machine Name:
Machine ID:
OS Version:
Local Username:
Working Set:
Current Directory:
Error Message:
RIF Cabal
favicon.ico
mainwindow.baml
resources/images/cabal.png
resources/themes/generic.baml
MSBAML
MSBAML
favicon
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Rif Cabal Online Launcher
CompanyName
Cabal Online
FileDescription
Rif Cabal Online Launcher
FileVersion
1.0.0.1
InternalName
cabal.exe
LegalCopyright
Copyright
Rif Cabal Online 2018
LegalTrademarks
Rif Cabal Online
OriginalFilename
cabal.exe
ProductName
Rif Cabal Online
ProductVersion
1.0.0.1
Assembly Version
1.0.0.1
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Backdoor.MsilFC.S23224046
Skyhigh Clean
ALYac Gen:Variant.MSILHeracles.163774
Cylance Clean
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_60% (D)
Alibaba Clean
K7GW Trojan ( 700000121 )
K7AntiVirus Trojan ( 700000121 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/GameTool_AGen.J potentially unsafe
APEX Clean
Avast Clean
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Agent.gen
BitDefender Gen:Variant.MSILHeracles.163774
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.163774
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.163774
TrendMicro Clean
McAfeeD ti!CD5B88476DBC
Trapmine Clean
CTX exe.unknown.msilheracles
Emsisoft Gen:Variant.MSILHeracles.163774 (B)
Ikarus Backdoor.Androm
FireEye Gen:Variant.MSILHeracles.163774
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.INB.gen!Eldorado
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.MSILHeracles.D27FBE
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Agent.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent!8.B23 (TFE:dGZlOgwUqWaUcm+9Ig)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Gen:Variant.MSILHeracles.163774
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.