Static | ZeroBOX

PE Compile Time

2024-10-16 16:02:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0000bcb4 0x0000be00 5.89018656799
.rsrc 0x0000e000 0x0001edc2 0x0001ee00 7.86246137564
.reloc 0x0002e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00012630 0x00019f0c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00012630 0x00019f0c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00012630 0x00019f0c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00012630 0x00019f0c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00012630 0x00019f0c LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002c53c 0x0000004c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0002c588 0x00000650 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0002cbd8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
COSU71410202480_pdf
<>9__0_0
<A>b__0_0
<>c__DisplayClass0_0
<>9__11_0
<TryParse>b__11_0
<>c__DisplayClass1_0
<>9__2_0
<IndicesOf>b__2_0
<>c__DisplayClass2_0
<>c__DisplayClass3_0
<>9__4_0
<Parse>b__4_0
<>9__5_0
<TryParse>b__5_0
<>9__26_0
<Parse>b__26_0
<>9__6_0
<TryParse>b__6_0
<>c__DisplayClass6_0
<>9__7_0
<TrySetMember>b__7_0
<>c__DisplayClass7_0
<>9__8_0
<Replace>b__8_0
<>9__29_0
<InternalParse>b__29_0
<>9__9_0
<Parse>b__9_0
<Add>b__0
<Divide>b__0
<TryParse>b__0
<ToString>b__0
<OnParseException>b__0
<Run>b__0
<IsNonValueTypeExplicitlyCastableTo>b__0
<TryInvokeMember>b__0
<OnValueBelowMinError>b__0
<OnValueAboveMaxError>b__0
<Subtract>b__0
<Multiply>b__0
<GetDownload>d__0
<Run>d__0
<>o__0
<>p__0
<>c__DisplayClass0_1
<>9__11_1
<TryParse>b__11_1
<>9__2_1
<IndicesOf>b__2_1
<>9__13_1
<TryParse>b__13_1
<>9__4_1
<Parse>b__4_1
<>9__5_1
<TryParse>b__5_1
<>9__6_1
<IsNonValueTypeExplicitlyCastableTo>b__6_1
<TryInvokeMember>b__6_1
<>c__DisplayClass6_1
<>c__DisplayClass7_1
<>9__8_1
<Replace>b__8_1
<>9__9_1
<Parse>b__9_1
<thread>5__1
<Run>b__1
<TrySetMember>b__1
<>o__1
<>p__1
<>u__1
<>c__DisplayClass20_0`1
<>c__DisplayClass21_0`1
<>c__DisplayClass13_0`1
<>c__DisplayClass28_0`1
<>c__13`1
<>c__6`1
<>c__29`1
Func`1
TaskCompletionSource`1
Nullable`1
IEnumerable`1
IOrderedEnumerable`1
IEquatable`1
CallSite`1
Task`1
Expression`1
ICollection`1
AsyncTaskMethodBuilder`1
EqualityComparer`1
TaskAwaiter`1
CrontabFieldAccumulator`1
IEnumerator`1
IList`1
get_Item1
CS$<>8__locals1
<>9__13_2
<TryParse>b__13_2
<>9__6_2
<IsNonValueTypeExplicitlyCastableTo>b__6_2
<>9__7_2
<TrySetMember>b__7_2
<occurrence>5__2
<buffer>5__2
<TryInvokeMember>b__2
<>o__2
<>u__2
Universal.Common.<>f__AnonymousType0`2
Func`2
KeyValuePair`2
IDictionary`2
get_Item2
<>9__6_3
<TryInvokeMember>b__6_3
<key>5__3
<IsNonValueTypeExplicitlyCastableTo>b__3
<>o__3
Func`3
Tuple`3
Action`3
get_Item3
<>9__6_4
<TryInvokeMember>b__6_4
<iv>5__4
<IsNonValueTypeExplicitlyCastableTo>b__4
Func`4
<GetNextOccurrences>d__15
<http>5__5
<IsNonValueTypeExplicitlyCastableTo>b__5
<>o__6
<Module>
System.IO
value__
Lambda
System.Data
NCrontab
mscorlib
Oiohyrb
System.Dynamic
System.Collections.Generic
GetByteArrayAsync
<<Run>b__1>d
get_ManagedThreadId
<>l__initialThreadId
ExitThread
get_CurrentThread
GetDownload
get_IsSealed
IsDefined
AwaitUnsafeOnCompleted
get_IsCompleted
<Value>i__Field
<Length>i__Field
<ErrorProvider>i__Field
<Index>i__Field
ICrontabField
<Kind>k__BackingField
<MinValue>k__BackingField
<MaxValue>k__BackingField
<LineBreak>k__BackingField
<WriteHeader>k__BackingField
<HasHeader>k__BackingField
<TextQualifier>k__BackingField
<Delimiter>k__BackingField
<DataValidator>k__BackingField
<IncludingSeconds>k__BackingField
<LineSkips>k__BackingField
get_End
MoveEnd
IsAtEnd
Append
get_Kind
CrontabFieldKind
DateTimeKind
FromKind
FieldByKind
get_Second
get_Method
MakeGenericMethod
GetMethod
GetCurrentMethod
method
get_IsInterface
Replace
IObjectReference
TryGetNextOccurrence
taskCompletionSource
Divide
GetHashCode
CryptoStreamMode
ToEscapedUnicode
message
ImplicitCastCache
Gjpiqie
DynamicInvoke
EndInvoke
BeginInvoke
mDataTable
ICloneable
Nullable
IEnumerable
IDisposable
YieldAwaitable
IConvertible
add_Idle
remove_Idle
RuntimeMethodHandle
RuntimeTypeHandle
GetMethodFromHandle
GetTypeFromHandle
FillFromDelimitedFile
CrontabSchedule
get_Name
get_FullName
get_ColumnName
<>3__endTime
<>3__baseTime
get_MaxSupportedDateTime
get_NewLine
aNewLine
IAsyncStateMachine
SetStateMachine
stateMachine
get_IsGenericType
genericInterfaceType
get_IsValueType
get_DeclaringType
GetUnderlyingType
ExpressionType
get_ReturnType
aReturnType
get_ParameterType
GetType
GetElementType
System.Core
HasSameSignature
HasMatchingSignature
callSignature
get_InvariantCulture
Capture
MethodBase
InternalDataCollectionBase
System.IDisposable.Dispose
InternalParse
TryParse
Inverse
Create
bDelegate
mDelegate
MulticastDelegate
Accumulate
DebuggerBrowsableState
SetApartmentState
<>1__state
CallSite
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AsyncStateMachineAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
DebuggerHiddenAttribute
ExtensionAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
get_Minute
get_Value
FastFormatNumericValue
oldValue
ParseValue
get_MinValue
minValue
IndexToValue
get_HasValue
FormatValue
TryGetValue
newValue
get_MaxValue
maxValue
get_IsPrimitive
Remove
COSU71410202480_pdf .exe
IndicesOf
LastIndexOf
Kvkbcf
HasFlag
System.Threading
OrderByDescending
System.Runtime.Versioning
newValueMapping
FromBase64String
ToXmlSafeString
mString
ToString
tString
Substring
get_Length
get_Month
GetDaysInMonth
get_LineBreak
set_LineBreak
AsyncCallback
callback
StringSeparatorStock
DaysOfWeek
_daysOfWeek
get_DayOfWeek
get_Task
op_GreaterThanOrEqual
interval
ReplaceAll
SelectAll
SetAll
CrontabFieldImpl
CryptoStream
MemoryStream
get_Item
set_Item
System
SymmetricAlgorithm
IsAssignableFrom
ICryptoTransform
Boolean
op_LessThan
AppDomain
get_CurrentDomain
DataColumn
dataColumn
LambdaExpression
MethodCallExpression
ParameterExpression
expression
Application
BinaryOperation
System.Globalization
System.Runtime.Serialization
get_Selection
SubSelection
System.Reflection
MatchCollection
DataColumnCollection
DataRowCollection
function
GetGenericMethodDefinition
GetGenericTypeDefinition
aPosition
aEndPosition
mEndPosition
aStartPosition
mStartPosition
CrontabException
NotSupportedException
NullReferenceException
OnParseException
ArgumentNullException
innerException
FormatException
SetException
ArgumentException
Universal.Common
IsCastableTo
IsImplicitlyCastableTo
IsNonValueTypeExplicitlyCastableTo
MethodInfo
get_CompareInfo
CultureInfo
get_CallInfo
SerializationInfo
MemberInfo
ParameterInfo
CSharpArgumentInfo
SecondZero
Microsoft.CSharp
System.Net.Http
System.Linq
<Value>j__TPar
<Length>j__TPar
<ErrorProvider>j__TPar
<Index>j__TPar
get_Calendar
get_Year
TryInvokeMember
TryGetMember
TrySetMember
get_WriteHeader
set_WriteHeader
get_HasHeader
set_HasHeader
TripleDESCryptoServiceProvider
ExceptionProvider
get_ErrorProvider
IFormatProvider
AsyncVoidMethodBuilder
StringBuilder
<>t__builder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
InvokeMemberBinder
GetMemberBinder
SetMemberBinder
binder
MessageLoopManager
get_TextQualifier
set_TextQualifier
worker
idleHandler
EventHandler
mTimer
Comparer
YieldAwaiter
GetAwaiter
get_Delimiter
set_Delimiter
StringWriter
TextWriter
writer
OnValueBelowMinError
onError
OnValueAboveMaxError
aSelectionCursor
get_DataValidator
set_DataValidator
IEnumerator
System.Collections.Generic.IEnumerable<System.DateTime>.GetEnumerator
System.Collections.IEnumerable.GetEnumerator
.cctor
valueSelector
errorSelector
CreateDecryptor
get_Hour
System.Diagnostics
mFields
get_IncludingSeconds
set_IncludingSeconds
includingSeconds
_seconds
GetMethods
GetInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
GetNextOccurrences
DebuggingModes
Matches
matches
noNames
GetNames
_names
aDelimitedFileLines
SplitLines
NormalizeNewLines
GetTypes
mDelegates
get_Attributes
MethodAttributes
Minutes
_minutes
oldValues
values
BindingFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
EventArgs
Months
_months
<>4__this
System.Threading.Tasks
Equals
System.Windows.Forms
Contains
get_Columns
Universal.Common.Extensions
FuncExtensions
DataTableExtensions
TypeExtensions
StringExtensions
CharExtensions
TimerExtensions
System.Linq.Expressions
System.Text.RegularExpressions
mNewLineRepresentations
System.Collections
DictionaryExtentions
aOptions
DelimitedFileReadOptions
StringReplaceOptions
CompareOptions
ParseOptions
DelimitedFileWriteOptions
aStringSplitOptions
options
get_LineSkips
set_LineSkips
get_Chars
System.Timers
get_Parameters
aParameters
GetParameters
_hours
success
successs
GetGenericArguments
get_Rows
aErrorRows
Concat
Format
format
Subtract
DynamicObject
MutableObject
System.Runtime.Serialization.IObjectReference.GetRealObject
object
Select
Myfrducdt
_minValueSet
_maxValueSet
Target
System.Collections.IEnumerator.Reset
op_Implicit
get_Default
GetValueOrDefault
get_Result
IAsyncResult
GetResult
SetResult
result
HttpClient
Environment
aAdjustment
System.Collections.Generic.IEnumerator<System.DateTime>.Current
System.Collections.IEnumerator.Current
System.Collections.Generic.IEnumerator<System.DateTime>.get_Current
System.Collections.IEnumerator.get_Current
<>2__current
get_Count
get_ValueCount
get_ArgumentCount
get_Start
ThreadStart
MoveStart
IsAtStart
Restart
Convert
AttemptImplicitCast
AttemptExplicitCast
ReplaceLast
ToList
ReplaceFirst
GetFirst
MoveNext
System.Text
ReadAllText
StreamingContext
context
Sqbldmu
DataRow
NewRow
get_Index
ValueToIndex
IsPrefix
ThenBy
get_Day
ToArray
get_IsArray
BitArray
get_Body
get_Key
DelegateKey
System.Security.Cryptography
Assembly
Ssjjvkly
Multiply
mDictionary
op_Equality
op_Inequality
IsNullOrEmpty
WrapNonExceptionThrows
Microsoft .NET SDK 8.0.401 (x64)
Microsoft Corporation
9Copyright (c) Microsoft Corporation. All rights reserved.
$4baf164c-f94c-406c-bd10-8c1d4382b8bf
8.4.124.41202
.NETFramework,Version=v4.6
FrameworkDisplayName
.NET Framework 4.6
Uqdwl.A1+<GetDownload>d__0, COSU71410202480_pdf , Version=8.4.124.41202, Culture=neutral, PublicKeyToken=null
-Universal.Common.MessageLoopManager+<Run>d__0
EUniversal.Common.MessageLoopManager+<>c__DisplayClass0_0+<<Run>b__1>d
_CorExeMain
mscoree.dll
;=>344
(Gt*Iv
HKL?AA
%+.%*,
$-1$+/
#.2)37
-4/:>
CA?GED
(1%17
$#%((*
%-8BG
"(HQS
%>HK
@`p?`l
#5AD
CdtDfv
DW]BU[
/Wf6]l
g{}BRT
OXPE^R
XV XW
,B:0iZ
=TFBZM
1DN7LW
;=?001
LNOBCC
9=?;??
!(+"'*
%.2$,/
#-1%/3
!-2,6:
|zx|zy
-4,7=
643;98
,5"07
GLu@Dm
!(BLO
5Ls<O
&3>A
8Z]8X_
"')58
(+&48
/N^5Ue
ShnH\c
;at6^n
Q[TRaW
HOGCbV
"5.-bT
3xu2rq
MgvOiy
7OA>TF
';E,AL
D(vb"6
cXYYgei
DeJ]f\e
m.\Y$S
+H)Q*GkE
$IX]YAi@
t$y:$+2
5mlGZ`
{)E6d8
n"04[#
N&@02:
(bjfc3s\
]F+.i7
^lX^Yc
g?M=0\
zQLqWz
VdYN^(
`zvpzW/
c@!0EJ
[[[$ijAK
0NY_]&/$
w.\"Mb
7$IbFG
+CX%K
kuVo]"
AiCRX_E)%
WkdyF?J
_k+^al+
tXX\cl
*-AH;5
(4Ef7B
0.X\\e
*AQ%nb[D
Kk<Gpx
rrSJ|k
>%%X):
%pIiCV
FHSebf
pscH'V
ijKCaQ
rd2dy=A
2^+`;.
EdTJ6Q
+9|Fd0
fDQB*2
B|?blb
42F~xt
JeF~ 3
t4Mckg
P):&s
M$x~H9
'Jb,C!
%LMN{m
2M8f~i
E~eB9"
\0PIiT
Sv7RvvF,
+MRR-E
?h3Qwx
c8:NU%
"3UF^@
reY&C1
7o^dqq
67]*c1
ZZ&JzXNJ
2=VDS`f
B,+eg+!K
wolR1>
R*:DqB
0N>\*0P
tC!MtJE
2n<Ke<
SLL,33
`2>Yacs
)23icZ!
(JHR9NKR
h0@W%;
qJeN-M0[7
Q+Q,Z<
lLf"cf
<"DB]K
8;=eyt
EUM(rCU
s $.x|
5+8Y5 $}
`5Mcy|t
!R7OPa
MR JeF
:YrtVs
fH)1Jq
]*E.5Rg
&EUrtx
gkQ1t=
,!X$i
5-&3h%1
dJR(IU
BR E2!
wn_ggg
'@gHH)
&#/&Hc
-YQRM*@
#CW'e`9'
!e(zhz
`2=&$
w)*++*
jJUUI@
k UeY^`
zyJ]7#
\VNP&
_Ae%}?
(EU$We
H&Ez,W-C?
WH)8::fh;
Cv.=7V
9'GO8y
-1D&EIYh
3TWP;/Sn_K
i-QedYFf
8@+Xlm3
1;/"$h
EI)G/zr
%~H6j%
5jT^lVg0
HMZ$;W
HU:)3C
tRJ) $1
H.JX+!
ZL('%m
Xl-8;[
XuNnVR
`S?`go
J3y!$Be
'JM^mQd
IWb@
z/|6;%?
,$rT_~
IlwF^M(
CYd87PhIn"U!
jb,Viv
95JE{G4Z4
iyxEuh
5ED)--f
mf:_0Fq8
C \GwUI3
zvwG|'S
vN@!1nl
\^^8O3
*hU0Z6
^Ng>?>
}m$' '
["R$$HES
1mJ e}J
9Yc*rz
M,Vat%
*!fb*b
}8HoB[B
+8U0$j
TrL(cH
3ZRL<~|
"k-C?r
O'BHt]
#ei4[%2
gxyyAk
xcxxx`
7ipfpV
0ja]V|'
KSzimx~>
VZHC_P
+O*"m4
.mqjD%
-+N+Ens
VJIyy9_
Q2Xc)J
IDATy)a
lxc%k/
ZbS5z'
q"OOOt
vrl-VZF
{g.YD5
b{}9/|
H&j{0+
:i_Ai=
2!EJq7
Z2^yJn!&
pi)O!&
#l+9fv
mbc,N!
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
! "#&%'%(%)%*%-,2131415161718191<;@?A?B?
z6/+XRKBNqdyP9gN/bsQNg==
+XHT0YHpLQs=
http://103.72.57.120/diddyishere/Kqgma.wav
M4dYsgIXq
nhqBY9oJMD3iOhdS6w.mGopN4B8rS4Xc3vtgO
{{ ErrorProvider = {0}, Value = {1} }}
Crontab error.
{0} is higher than the maximum allowable value for the [{1}] field.
Value must be between {0} and {1} (all inclusive).
{0} is lower than the minimum allowable value for the [{1}] field.
Invalid crontab field kind. Valid values are
writer
A crontab field value cannot be empty.
'{0}' is not a valid [{3}] crontab field value. It must be a numeric value between {1} and {2} (all inclusive).
' is not a known value name. Use one of the following:
January
February
August
September
October
November
December
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
'{0}' is not a valid [{1}] crontab field expression.
expression
5 components of a schedule in the sequence of minutes, hours, days, months, and days of week
6 components of a schedule in the sequence of seconds, minutes, hours, days, months, and days of week
' is an invalid crontab expression. It must contain
{{ Index = {0}, Length = {1} }}
DynamicInvoke
Invoke
Row with incorrect number of columns:
Unexpected line break - {0}
Unmatched text qualifier - {0}
&#x([0-8BCEFbcef]|1[0-9A-Fa-f]);|[\x01-\x08\x0B\x0C\x0E\x0F\u0000-\u0008\u000B\u000C\u000E-\u001F]
op_Explicit
op_Implicit
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Microsoft .NET SDK 8.0.401 (x64)
CompanyName
Microsoft Corporation
FileDescription
Microsoft .NET SDK 8.0.401 (x64)
FileVersion
8.4.124.41202
InternalName
COSU71410202480_pdf .exe
LegalCopyright
Copyright (c) Microsoft Corporation. All rights reserved.
LegalTrademarks
OriginalFilename
COSU71410202480_pdf .exe
ProductName
Microsoft .NET SDK 8.0.401 (x64)
ProductVersion
8.4.124.41202
Assembly Version
8.4.124.41202
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Dnoper.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Clean
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_100% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.OXE
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan-Downloader.Ader.Edhl
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!367F7E823D0A
Trapmine suspicious.low.ml.score
CTX exe.trojan.msil
Emsisoft Clean
huorong TrojanDownloader/MSIL.Agent.aeh
FireEye Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet MSIL/Kryptik.AMMR!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Dnoper.gen
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Leonem
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5683482
Acronis Clean
VBA32 Downloader.MSIL.PureCrypter.Heur
TACHYON Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Yandex Clean
Ikarus Trojan.MSIL.Agent
MaxSecure Trojan.Malware.300983.susgen
GData Clean
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Trojan[downloader]:MSIL/Wacatac.B9nj
No IRMA results available.