Static | ZeroBOX

PE Compile Time

2024-09-06 17:54:50

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00006e24 0x00007000 7.4242735021
.rsrc 0x0000a000 0x00004868 0x00004a00 5.08869995267
.reloc 0x00010000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a130 0x00004228 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of \200.DBF, blocks size 0, block length 16384, next free block index 40, next free block 4293729316, next used block 4293729316
RT_GROUP_ICON 0x0000e358 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000e36c 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000e678 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
K#cmOrQ
M6<Y3[i
\mbs?W
qF'!La
3qy_Xl'
y$az{y
(2=t+@
|;VGLB
-K]9\H
O8V%#_8
iWBnfKm
M>%0E]
Sr Jf]
p@TNF?@
c`D1(t
=0}a:\^
ya-=V\
0`0nq"5
bqg^}9
azX:7#
.(s\^J
D[?gEt
~S/FoL
h_W+ 4
q@ {E>pC
i&)GU0p
Ew\ dH
;t~JIe
E3a@3}fb
D=E%Y
j#Bz*8
}%Cf3Z6
,~5(-
|9vsw
G;hh(]?O
cO,|`
QdEQvgTt
Y_cX*n
VMDj^m
Z?_b`
_bj2
_bY*
Z_bX
v4.0.30319
#Strings
GLSetup.exe
<Module>
DataField
Decrypt
mscorlib
GCHandle
System.Runtime.InteropServices
Resolve
Assembly
System.Reflection
ResolveEventArgs
System
Decompress
.cctor
DataType
ValueType
BitDecoder
Decode
BitTreeDecoder
Models
NumBitLevels
ReverseDecode
Decoder
Object
Stream
System.IO
ReleaseStream
Normalize
DecodeDirectBits
LzmaDecoder
m_IsMatchDecoders
m_IsRep0LongDecoders
m_IsRepDecoders
m_IsRepG0Decoders
m_IsRepG1Decoders
m_IsRepG2Decoders
m_LenDecoder
m_LiteralDecoder
m_OutWindow
m_PosDecoders
m_PosSlotDecoder
m_RangeDecoder
m_RepLenDecoder
_solid
m_DictionarySize
m_DictionarySizeCheck
m_PosAlignDecoder
m_PosStateMask
SetDictionarySize
SetLiteralProperties
SetPosBitsProperties
SetDecoderProperties
GetLenToPosState
LenDecoder
m_LowCoder
m_MidCoder
m_Choice
m_Choice2
m_HighCoder
m_NumPosStates
Create
LiteralDecoder
m_Coders
m_NumPosBits
m_NumPrevBits
m_PosMask
GetState
DecodeNormal
DecodeWithMatchByte
Decoder2
m_Decoders
OutWindow
_buffer
_stream
_streamPos
_windowSize
CopyBlock
PutByte
GetByte
UpdateChar
UpdateMatch
UpdateRep
UpdateShortRep
IsCharState
ConfusedByAttribute
Attribute
GLSetup
MainWindow
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
ComVisibleAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
AssemblyFileVersionAttribute
PresentationFramework
ThemeInfoAttribute
System.Windows
ResourceDictionaryLocation
DebuggableAttribute
System.Diagnostics
DebuggingModes
RuntimeCompatibilityAttribute
System.Runtime.CompilerServices
CompilationRelaxationsAttribute
AssemblyTitleAttribute
AssemblyCompanyAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
STAThreadAttribute
GLSetup.g.resources
GLSetup.Properties.Resources.resources
UInt32
GCHandleType
Module
MethodBase
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetExecutingAssembly
get_ManifestModule
get_Target
LoadModule
ResolveSignature
AppDomain
get_CurrentDomain
ResolveEventHandler
add_AssemblyResolve
GetTypes
ResolveMethod
GetParameters
ParameterInfo
Invoke
Encoding
System.Text
get_UTF8
get_Name
AssemblyName
get_FullName
String
ToUpperInvariant
GetBytes
Convert
ToBase64String
GetEntryAssembly
GetManifestResourceStream
get_Length
Buffer
BlockCopy
MemoryStream
ReadByte
ConfuserEx v1.0.0
Copyright
2024
GLSetup
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
1.0.0.0
WrapNonExceptionThrows
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
GLSetup
FileVersion
1.0.0.0
InternalName
GLSetup.exe
LegalCopyright
Copyright
2024
LegalTrademarks
OriginalFilename
GLSetup.exe
ProductName
GLSetup
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Generic.TRFH997
Skyhigh BehavesLike.Win32.Infected.ph
ALYac Gen:Variant.MSILHeracles.152262
Cylance Unsafe
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_70% (W)
Alibaba Trojan:MSIL/Heracles.a513ce25
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
huorong Clean
Baidu Clean
VirIT Trojan.Win32.MSIL_Heur.A
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:Malware-gen
Cynet Clean
Kaspersky Clean
BitDefender Gen:Variant.MSILHeracles.152262
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.MSILHeracles.152262
Tencent Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.lihey
DrWeb Clean
VIPRE Gen:Variant.MSILHeracles.152262
TrendMicro TROJ_GEN.R002C0DKC24
McAfeeD Real Protect-LS!EF46A9316CD3
Trapmine malicious.moderate.ml.score
CTX exe.trojan.msil
Emsisoft Gen:Variant.MSILHeracles.152262 (B)
Ikarus Trojan.MSIL.Heracles
FireEye Generic.mg.ef46a9316cd36251
Jiangmin Clean
Webroot Clean
Varist W32/MSIL_Agent.BLZ.gen!Eldorado
Avira TR/Redcap.lihey
Fortinet PossibleThreat
Antiy-AVL GrayWare/Win32.Wacapew
Kingsoft malware.kb.c.834
Gridinsoft Trojan.Win32.Agent.sa
Xcitium Clean
Arcabit Trojan.MSILHeracles.D252C6
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/Heracles!MTB
Google Detected
AhnLab-V3 Malware/Win.Generic.C5689005
Acronis Clean
McAfee Artemis!EF46A9316CD3
TACHYON Clean
VBA32 Malware-Cryptor.MSIL.Delta.Heur
Malwarebytes Generic.Malware/Suspicious
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DKC24
Rising Malware.Obfus/MSIL@AI.96 (RDM.MSIL2:cKxJw5ie8pdYRZYR0EBUOQ)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.257484626.susgen
GData Gen:Variant.MSILHeracles.152262
AVG Win32:Malware-gen
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.