Static | ZeroBOX

PE Compile Time

2024-10-31 17:00:30

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000417b4 0x00041800 7.831361955
.rsrc 0x00044000 0x000006d8 0x00000800 3.73523473751
.reloc 0x00046000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000440a0 0x00000448 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000444e8 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
+[>GYl
f=95PZ
i^,w=z
S>YLj0
OF[_S'X
q~=nP
>V?P+T
:Y=|cq
[+\ge%
(Zj%Xx
o1POP)
ICA]Hed
ick1\D
sB@,9q
2O9"sK{
Us;.6M
"}P\]^
Rb[aOy
F"jJB(H
C5>?V}^
ZMuIU_
w\2hDps
5k#=!i
),</46
4VV'4-<
<U63pc
L-]P%F4M
8P^xEg
gbd0YT
ZZjMK9f
:LonTih
s{zXHB
mn9(<r
X~XIbE
q*8Ce?
:Q*qhqQ
2f`w#fklT
1>p_oI
?7AYQR)
x=&P)3
i5t3Q
aoA2;
~^r3z`
y-SX!p]
<9#Q^0H
>O;]^o
*km_(0
PuM`<,
(#2aG]
>S^[OJ
G7-1Ii
8r!OMx
Q-:x&!
`LWqfE
i qG!R
Gk*lV0)
Bd>vn'
I$My`O
rZUAS=
79Ptf/;
Xb<;G.
3J,_:-
q+D]3J
xDkh3q
1e2$R}
]~p:/x
qvPH7S~
h[pN/b<qs
XPJ#.C
g!^{r>{
2!&J5i
`n6+lo}L
j&\c/{4
5k/W%'c<
]$ozIU
)`TVYnZR
4xd@ZAY
P]k^O
G!{Tz C
86AYG(
woLhQW
7S,qON
\,Z_rO
Aq0pdh
sjOBce
bjaOJ,E
#/f=Ff
<=Rd!m
NI0XYR
:Vs2D8`
_S-, L
%x-"^m
P{6b}'
{xXr J
9JgMD-
2S7i8](;
Nla@7$
Mo&16JO]%
J^tHW"
NBYbN"T
(#JEma$
mDlRHh
D_7lT12A
}P}L+D
F'x<]u
s,!Kcv{
oo%_o#
Vhe7s^
O3UbY`
gda26a
L^*=h4=
Z.7.NJ
11G_}
COeWRl
y5:ZPZ9
V1bOPTvu*
$NpE-\
N;Yw<j
;-Ub\;
B2nUx0@
Y|S*\\
F_=yCjUS
&,PQb`D@
cn7v6
,[!>]7
w>nW?.D
4ek/AiF
-3l121JGz
<Vs:{c
bU["p]4M
^gZ7FG
RoPPa-
p,1b<3
5g\\w6
ujURAI-
G?1dFCd
Z1nR2l
j_Y{xVu
nQ#@L~
mNgCu2
|.Jmr9
{??J>J
`+,MD_
w2?f]0
eu)qGXX
r |n&d
*",iM&g
XNlg:zqs
E#/~~f
R$OKk4
>9.rC/w
Qr]=j[~>
x$U+'v
y!sI8~
~_=_/T
b-/d-=Z
Zx6)K@
4w0{"m3=Y
N=B<WB
M_E=Hl
tJV!YF
"GV+p]
SH+f3]
=(hJ`mA
{~Ge|=
%Yj`-b
~&"t$d~
+gFd].=
G5{Xlj
g+4S|u
@:%J.F
#:~'/Gi
G")fy5(R
`bGC~j
jp6~ 5
$7`dj>
\@3HAZ
h\!x0X
j!5r$#}
Ox&h_q
+6b_0kIZ
sU*$r(Y
s\"CB*8
Cw\!J#
H,KK~G
-#4@hO
n?Y\,<
HJV| ;
I[H$aV
]g`9df+
<n/$(l
JN]nQh
Vqil|J1
R&,W=N
<Qm2eT
stPto!%
+$StN:HH
@)*]mH
)|yQq/?
LIlk]I
,)BG@s
d}l6P*64
#w4~Tl
v3uB~/
p$M?7D9?A)w
kRmp!r
,%"xQIA
Y"#mGwA
UpF?"?
+>545Gl
a;N`j89
lP+J'pN
3Wgk^#
|4,zw(=
!yx7Fim
-zbyiV
uJs{k
+@yJO=
=v?xH#i
3Y&H6|
)@ -R{
Gnax|4
z#%B*.
}-RA^Y
~t8vvn
z.AvTB
K$wp.$@
gY/o4(
[%/XH!
?doHd0q%o.{GD
q6$[yfHk
qzkKB@b
'?j^x'
cQhg@eO%
vMo){=/&
{UcE#Np
(~Jy~D
BPai1.vkF
mLY.oo
9}g^mx
'>I'ON
4$jzNW;
qX2I0y9
dE7AR}
u9rI$E
A;_6<
p'/("}
:M[_Q|
^idNA~
T_"TsE
?vzK>jf{
4quMh9c
fP<I-/ra
^7q@m+
;VZG42
j8Z_y@
,!s*T
EdDin(@
W^h<48b
<_taL\
)AYD_e
Palf-E
"K+;xNG
>jW~^So
t{P5@i
t/_SGn
wHXSi]
?Wy g&kD
{iyaHE<vy
DUdn`!
rH]Uv
`.nS,a
)L]iw"
q'![x?
`Wk^7c
\B3#=hKb
CLIG=v
BoEyU~
w)F30`
~P5'f+d
1F%PrN
waW(,
(^J4l`
zf*zJW
gtYbo#
7~5s_^
ww[.d?{
`l9"40
-?Y7"B
wS?4*s
nO2X&g
\0"k#4/
GS3OP>
V#~hrJU:
4JwZ-?
0@o:z(E
(IE12}z
66`H[y
xStmVk
kv+EKq
`HL?o[
)W< Y^
})B}D/
dQ`vo>
eBI4{=
]4T &&4
tU_GI.
</@,R?
`MF,<
AsfBnY
]baql#}
iOgN>^
)wdE^pq|
J<,~?Y@da
_"R]mu
thKi]7
t[$yh-cIj
*vWPgO
so`B8o
/M%pTn
3G?/lN
F,TpQo|
9VJ<lE{
tb*l^$
D_^Xo]w
r_$Z%L
5"jU[
*+etdS
_EUSd,E
8OSyH\|6
:JC u
..qu)1
_74$kb
qPy|?TO,Vm_
Nn@/Zi-x
*rx,<"
L+~c`6
2}A&_*
T&^J"f
`u+r33
EhZR2H
|(npPFxm
]!T,B[
N6GLfN
Br<-yXy^
`;GE0Ho9
Cn[,Sj
w{Z;g-Z;
vV*gIL
AG=~!1
ubNLo0
>=dKAi
%rBVI.
y_Za8]
wP_Ta%
Z?_b`
TeXU &c
&o/a89
6s2a8a
8E%&8G
X<`Z h
~O4a88
Z jG+ a8
[gZ Pjm
-U48%&+
Z '>&Aa8A
]KZa8%
Ch'xZ
Z w#n&a
bS]a8U
NUxa8;
GafZ a
Qi,Z yd
C)LZ Z
^OxZ e
2n~Z
w Gr82
_bj/
_bY*
+V {W)I
{W)I%+
w7Za8$
0:%a8J
Qq3Z \
L%Oa8i
~:)`%+
J.5a%+
Z_bX
Y_cX*
LftHZ
yk%&8m
4b :m;
+cl(T
MKZ Yn~
v4.0.30319
#Strings
ChloeJackUlysses.YH
<Module>
mscorlib
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
Environment
SpecialFolder
LoadLibrary
kernel32.dll
GetProcAddress
CloseHandle
WaitForSingleObject
MemoryStream
Encoding
System.Text
StreamWriter
TextWriter
IDisposable
FileAttributes
Delegate
MulticastDelegate
Invoke
BeginInvoke
IAsyncResult
AsyncCallback
callback
object
EndInvoke
result
ChloeJackUlysses
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
String
GetTypeFromHandle
GetMethod
Concat
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
System.Diagnostics
get_IsAttached
IsLogging
get_IsAlive
ReadByte
get_Length
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
Buffer
BlockCopy
GetElementType
CreateInstance
get_UTF8
GetString
Intern
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
get_FullName
get_Name
op_Equality
GetFolderPath
Replace
Combine
IntPtr
op_Inequality
get_ASCII
set_Position
ToArray
Convert
FromBase64String
Dispose
Substring
GetAttributes
SetAttributes
Exists
Delete
WriteAllBytes
Marshal
GetDelegateForFunctionPointer
large advance blue
4destroy red destroy black idea us old slow lead slow
build apple we
universe we black
database build plan
%teach me banana old organize (c) 2024
them organize design solve moon
$0f6f9e45-686a-46cd-b15c-958a130c0481
5.1.2.9
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
destroy red destroy black idea us old slow lead slow
CompanyName
universe we black
FileDescription
large advance blue
FileVersion
5.1.2.9
InternalName
ChloeJackUlysses.YH
LegalCopyright
teach me banana old organize (c) 2024
LegalTrademarks
them organize design solve moon
OriginalFilename
ChloeJackUlysses.YH
ProductName
database build plan
ProductVersion
5.1.2.9
Assembly Version
5.1.2.9
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Gen:Variant.Ser.Jalapeno.72
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_60% (D)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/TrojanDropper.Agent.GCY
APEX Malicious
Avast Win32:DropperX-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Injuke.gen
BitDefender Gen:Variant.Ser.Jalapeno.72
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Ser.Jalapeno.72
Tencent Trojan.Msil.Kryptik.16001337
Sophos Clean
F-Secure Clean
DrWeb Trojan.PackedNET.3006
VIPRE Gen:Variant.Ser.Jalapeno.72
TrendMicro Clean
McAfeeD Real Protect-LS!500904922500
Trapmine malicious.moderate.ml.score
CTX exe.unknown.jalapeno
Emsisoft Gen:Variant.Ser.Jalapeno.72 (B)
Ikarus Clean
FireEye Generic.mg.500904922500a6b2
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft malware.kb.c.1000
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Ser.Jalapeno.72
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Google Clean
AhnLab-V3 Dropper/Win.DropperX-gen.C5688502
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL.Generic
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Gen:Variant.Ser.Jalapeno.72
AVG Win32:DropperX-gen [Drp]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.