Static | ZeroBOX

PE Compile Time

2072-09-11 22:51:09

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00002078 0x00002200 6.54224282935
.rsrc 0x00006000 0x0000059c 0x00000600 4.03328402985
.reloc 0x00008000 0x0000000c 0x00000200 0.0815394123432
.CSS 0x0000a000 0x0005a400 0x0005a400 7.99950667049

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00006090 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000063ac 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
F N/2'
Z };7%
o N"rV
v4.0.30319
#Strings
AD446C34F2704865A9E424BE5755BC8F9140414FD7E1456F1A4581F8C2D778A0
__StaticArrayInitTypeSize=11
List`1
ToUInt32
ToInt32
__StaticArrayInitTypeSize=1355
ToUInt16
__StaticArrayInitTypeSize=36
get_UTF8
<Module>
<PrivateImplementationDetails>
GetModuleHandleA
074E1DFFDDF2B0C3F55E8F7D1DC7FF42122304BC54707F839B1BFC631CC929CD
B86C921CDC504CE0C498E5F2E9548A01E33F930047FB5D22BF2DA2270E113ECD
get_ASCII
System.IO
CallWindowProcW
inputData
ioAdhugxya
mscorlib
System.Collections.Generic
lpPrevWndFunc
TrimEnd
method
DeleteSentence
EndInvoke
BeginInvoke
RuntimeFieldHandle
Console
hModule
procName
moduleName
WriteLine
ValueType
MulticastDelegate
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Thrones.exe
dwSize
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
get_ExecutablePath
AsyncCallback
callback
Marshal
kernel32.dll
user32.dll
lParam
wParam
Program
get_Item
System
Application
System.Reflection
ArgumentNullException
ArgumentException
Publisher
Thrones
GetDelegateForFunctionPointer
BitConverter
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
ReadAllBytes
System.Windows.Forms
get_Chars
RuntimeHelpers
lpAdress
GetProcAddress
Object
object
lpflOldProtect
VirtualProtect
flNewProtect
iuogfht
IAsyncResult
result
sectionContent
Convert
System.Text
cjhgay
InitializeArray
Sygcydy
dataKey
WrapNonExceptionThrows
Thrones
Copyright
2025
$5c249bfa-2dd8-4f1a-9314-11e3fed61454
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\Event\source\repos\Thrones\Thrones\obj\Release\Thrones.pdb
_CorExeMain
mscoree.dll
o%2E`L
*#Cs9ve9
+q%FL`p9
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
#@,xY?5
I;vye)$
@sF =
*'rR(9
]fBxqpr
b}+\ZH
(^V66f
[DL58<
Kbi!%l3
vUV1R'
kX#y9'z
ps{.P`7'
VU?7.c
'zQR=iLF
v<:N@
dkh#=h
wa9R#Z
~=N 3w
u)sCmM
OOG[X_.\X
<7,4#9
%;q YR
4\<7|>
`>m{;#
WMQF`+
BW5j(N
eg6Q-=4
C]oC`AAU,
#QPUNe
y)F?*6
fz!|'{
P4"|Ql
<NEBjng
y{Tt+%
tM@6_~
Hq2kko#
U?*FHS
kE^u)%}
zaXT<g
D BVf>
_3L?/g6\^
)cAL;2
$E%{T
&66.W2o
07t4#g4
Kkpjc)
^QHN<&
K4dM}y
{$gqQr
tc+(F(
1>0hF<
)>)(+d
,*3;V^
$/Yf&F
O9YPPo
}! Zfg
Z`4]1#e
V%u/4ym
/t)6}:
@^Gl#DJ
uG`qP|u
;P4tWC5
T4454Z
|B^c[y
uo\#T^.
B,oR" 2
8;jy|>
2d]!#M
]n1[uP
[yBX{+ 8Ou
n]SdN@
Jjp)b
3Ao&1c
vjkp/5
DWY)J8>/
|w+jD}
<i}"`qm
1fQ7Rilz'
cm'PXU
r)e|(M
GPFU0^
5ZQhC@
B+HPkr
iA/G>w
8AZ8Oj
TDt)243
bX\(aIC/
lV)BISd
mO82=Hke
+d=+{f
<>>W\y"
sdU|0x,
J/hKE}
x"m1T-X-?^
~u[Trg
pj{f
{$bP2;
J>p"D3
"7vQgSHY$y
n300zd
oH][p0~
\ers ,
G5?h 5
x]Y19m
F)Ocba
*zK\"$A}x$Ot
88@mj+R
](c^Hpp
P69J6k
"5Z10zk<
20PVH3
{:?%$A
~$<p]l
aI,K3U
%{G!yK
Yyf7QX
"(KHkg
+c~:oi/
n^qOdZ
J5)GAgy
)"HUoh2
aNe<cV;
"ATSl@
W#"P6s
/a~n"R
e02L]7j
1F$,->
'L00oR
iR7R<m
-WvP,D
fpWbJ!
>3_X*}
hFQA+
zibKNqb
'&{Hiv
Zt[P/m
A YupN
^{HM;=
4S`P1/m[
^HDT_G
pG tmH
Tw~&]0
?;IO@]
-nZnD/
4!Q 4?;
UL"'fs
N d~-o
59eIGQ
(|?48\
RGW0>]
*xqpTL
rwu"q
2kfZ96r
jgq`qc
UcG8#fF
7%v3AX7
XRzybA
@JXu:
nqsR1/h|^
6\#9Lm
YWX%H4
MxVmsb
m0z};LJ
dT3Gy{6
|QBut$
GCG&lA
$a(\5J
a0Jo<'
(o0b}Pr
j;R!1L
qH:?NpNM
Cyy2"}5g:
+Wl,BU`]
2>rApn
zTRgq+
d[Hap\
fa[D9:
$Kk_50
%$z0i$
XznGE~7u=
#HqSgx=
#%EbW5
LXG%Zg
Sy?nEUs
C*H[mBaiG+L
l|qNq#
kde$>hp
6~a{k{
MSIWb3
goAT7${<Lsc
_,sI]T
;]wA~m
6<T<EO
au2_c"x
p"ghxD
v)!Fd1
bV3M>k
?HS@DM
X.8_f'
"*<N<|
ujER3K
'I(U@9S,3
^29M:_
SKMIPq
IcI>O3
N<)^I/
T!7r%a
<0L.akm
^Of u
*<D-89
LPW3#XG
7p'S]o
qpL:J
'gt\v*
7y7,TK
>J_6v=
3XOHeb
z>YPh{R
]\X;-5
Fxo^'\
I:/"yJ
/$^Ig_|
ls;h:<
:Bt";l
?7~:~S!
($v>`v
IB8(R1
L'@O>U
5D'Qy#"
0Lmj'@
xNh>[?
^jQ7,"O
),Yj&6m
Yj(^VX
qN(agf+x
GommVT
.VGrX}
CzM%m<
6698;;
Gv_?O\
B*.P/M;
;^ynS8w
=Jb%vI
j*:-rb
S-wW1u@
nZ^R95_
I,zX W4w
z<8T"l
M6`sYv
pqa?,y
=%6a+@
(.6_Mr
)hG1_j!
lxi+\
=[-fJ}
ZJGKJO
3G_8 V
#H;$@w
Z{d+~U&1
tTa0'lXc
&HP{wJ\
>`*~,q
VCL|'e
C;1^o[
-{._)O
jHeXD8
g0F=wQ
Q6paw}}
j})`M
=MS/}1
<P;u$U
2bD:Jc
q' 4-/
aB>19w$^4
I]*u`2
.ax*,PH
H=5tki
j[3@'s-h
S>ge$5
Uh{2<&
8ben\5(yb+
8e y/G
Unkzt!
,ZIMX8@
H]Ou<g
XAPDK\
kx@f>5
>a~dm=
t4,5\8
%t%9.PK
c^*0x8
jf1Rf_
Qg~;JNU=
Ig)Z@1p
~pyRS(
G>u`Y))
;_?N5'l
*qiKCwJ
Sh5j.B>
i> y2;
GEH,p?
=re<_YgJ;
TUC[f\
bM~3R:&
F@WyB'8!
$Whm\jT
Zp2[]
.<C.xl
`irgi~
Uw&9"H
)V%@{A
hHm{I#
$D1r2e[:
2j}$AV
S[AS`2h
J@8oK9
BQ`Z{g6
yR#Tu&;
->g\7'
P37;s<
C ,OzH
hf7JW3
#>{YDO
^f#wt.l
d4FDDb
0j@2k?L
U_Z6"0
`lDF6H
]uGKs>E
x6v7pA'
a4h`8J
!!>lB"T
/Q2O~5
^Dy9YW
Ln,O#4BA#
`Op9&s
qUeR%2
,SN`er
wTPZw@
1tz&2"l
zJ0MaaL
tJBL.%
5vgmM g/
[>gBqP
k7%a}}c
1OM`pP
*u7&"NV
BFnj[T
#<%SQbX+
y%wPv:{I
3rnPMO
_0G)o
LHkOqJ?
I.'s}\
YH Z2'*%
0EzV#i
))s5<;
=l 13/
.:9QgDl
luEV_P
L^*~*fG=c
AbRLzV3
UBi)+ .m
%U~KJTD
sLtc\4
KW#DE%|
Vd GFY
*byLp;
#,:?V!
W`0,Gn
<x,P)}
vg=j_\
:Y'"_
QZ(:!^c
by2PoFD
$H)!;2
7nB}z$
\}k-CZ
Sv_&#0jg
<]c>R@
/n,)m&
Ee'uc
W95A+G
{=@X@r
+~V$>
bU0c2G
N#y[3g
I9$X-8
pPd/Sj
!KRK~
6?*j\xL#=
;j$@f+
,RN!}#
U.2ih(
]m(nG~
iye%>/
c<X{;UK
Q?e>W!
8A-2Z]
/nh*/a
a4j_$B
X]ZsO@D
+4nIl
25ws$6
uNg]4%Py
2>-aU\_
Vw{FU1
VB(B=}2<`
LUUGK
SEg@gN
_"Vslj
o8:G:\
iSvP|?
_j Ye\
XkAukq
P6&j`+^B@
oy1R#:
cKs\t'x
$cTo{P
`~;(SQ
v*M;tS
Xl4(1P
+w?nRn
qZc*5rJ
1:b+:xl
6I;7aP!
x1Q|<G
;vavtD'
Y9L0_Ez
+[<(es
xnazHU!0
N|xl3+
y}SFa"R}b
m#YvL|'
hd,~2{A
7E?38h
s+-uf0
w:H=*+
Tx(Kq(
S:]cse
)7Si-_0
;bo""F
vd3L]|
WJV6Pe
"uJ:o5E
C13F_D
rH>HYaa
?D,y+zQ@
a8[ F#
Om$2S=5
SP}|VS
4'm(]|A
APSziK
uP(6~'
x;m;t_S}
s]vI4!~
$Blub2
jIM4$/#
G.*GVZ
=$ywO)m
d2*HDF
1+%a9[
QH?Fk7.!
<&0A2j
Mv"#*V
]T,?i@
Hi3=,n
Ygh73R
AB5U%Y)
RVWN.|b}}(
xYq%c%N
_\b!vH
($QfsH
%C<`WH
L[<&k!
X.LVxq
s?[jG@
e1e$O{
<^AQb2
Y6U`E;
Kh<yOO
1.w#>$
bNKuv[6{U/n
6[?=CI
~'c#q$g
lNH&R
7fjQ>D
f4+xaL
U5{='"Y
.[zbK*V
P+]?MJ
^ IL*p,
;=i.!:i
D+*kyU|~
2:FV8W
8Eb=xt'?
jAW?` !
{3BB%0
0NZvlI-
g&Q{=%.
%-2o@X0=F
^J.6p/+mw
rFbpeR
!$n[#<+
IDX}r'
(s`ur)
j3J9R)
}Ts56[K=
;sd!5Q
`rwx*u
42ny|$
h)JlVe
1!3][h
cIBC]t
4Uy?#J7
W9Q1$C
[Oz0&;
##\0zs
K5_IE"ER
F/[c*c
)fPrd,
P0&&xF
EO+Xu
GJv}#`
.9fz&w
,bwh,F
w(<Bz%
xs-?M?
~mNQ=8
`mhnI5
{6/2/3
74@t:Q:
fZ;IjN\d
@kik#2
q5qP{z
/OF!$X
p$D'd'
Qi-sbCf
^Q6RM
)_q1`\
MxFbuH
>wAqF<
UixZf
B_#f-3
Kqp|PaYC}v
T,y~%#BK
lXnR7E
WmdNzN]u
hKNRN5
MT0x&+
b*:Js<
QgJ}kM|
_iGgl"4
ML4o^_
2B>uyu
)kI#b~h
Kg;q#-+
TSN@GBQ
0T|[|n
&o/Mn@
9rN[iU
}|TiA7(
>${,`p
:#Q&kc
4F!8l-R(
OU/]qH
o]phom
^F83nC
H-)N[I=O
|nBz|4J
Fmn8HoU
QYq_W3
/*fq'&
-gYY1+
KTJa_H/
:qfZv}
AplR1:
_G$h/jg[
YStua9)
(i6Oh]
p<$|!`
6?kiIr
Yz|7PH
s_jjeba^*
ImN{fH
k"dg@\
YhBl6V
P!si,p\
f*ra:Z
/P{L0l8
`JI9z2
m"GIZz
'51`r3
w`9J^
Y#RP|a<
DSdqk\3!
B"64}-
`W(z/e
G$<:7^
/GfV*F
YrE4H9L
$>aN4%
pmm$jl
=-!2moU
zh3),b
X=fI7M
n. Z(S
HimK+1
0zb8J
6NV@}A
L[Xnt~`
"mb4=_C
,hJXSZ
?wD7m2G
FK>Rk"
='^0fk
"rZfU$
)yTspv
vBSRdJ
}A5^x_J
XR,Vo[
+gh2k=B
BV&ctW
lrI4F+
T)K.x1
e&uiq4$
#SQIvm
aJ^}@o
kernel32.dll
VirtualProtect
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
Thrones
FileVersion
1.0.0.0
InternalName
Thrones.exe
LegalCopyright
Copyright
2025
LegalTrademarks
OriginalFilename
Thrones.exe
ProductName
Thrones
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav W32.AIDetectMalware.CS
Lionic Trojan.Win32.Stelpak.4!c
Elastic malicious (high confidence)
ClamAV Win.Packed.Msilzilla-10042543-0
CMC Clean
CAT-QuickHeal Trojan.MSIL
Skyhigh BehavesLike.Win32.Generic.fc
ALYac Gen:Variant.Lazy.656125
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:MSIL/Stelpak.4af52b97
K7GW Trojan ( 005c27361 )
K7AntiVirus Trojan ( 005c27361 )
huorong Trojan/MSIL.Agent.vl
Baidu Clean
VirIT Trojan.Win32.GenusT.ERFU
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of MSIL/Kryptik.ANFM
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.MSIL.Stelpak.gen
BitDefender Gen:Variant.Zusy.584302
NANO-Antivirus Trojan.Win32.Stelpak.kvzolr
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.584302
Tencent Malware.Win32.Gencirc.10c16924
Sophos Troj/MSIL-THD
F-Secure Trojan.TR/AD.Nekark.depcy
DrWeb Trojan.PWS.Lumma.1819
VIPRE Gen:Variant.Lazy.656125
TrendMicro Clean
McAfeeD Real Protect-LS!93E601392DD2
Trapmine Clean
CTX exe.trojan.msil
Emsisoft Gen:Variant.Zusy.584302 (B)
Ikarus Trojan.MSIL.Krypt
FireEye Generic.mg.93e601392dd24741
Jiangmin Clean
Webroot W32.Malware.gen
Varist W32/ABTrojan.CBHR-4065
Avira TR/AD.Nekark.depcy
Fortinet MSIL/Kryptik.ANFM!tr
Antiy-AVL Clean
Kingsoft MSIL.Trojan.Stelpak.gen
Gridinsoft Spy.Win32.Gen.tr
Xcitium Clean
Arcabit Trojan.Zusy.D8EA6E
SUPERAntiSpyware Clean
Microsoft Trojan:MSIL/LummaC.AFNA!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5736914
Acronis Clean
McAfee GenericRXWQ-QK!93E601392DD2
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.MalPack
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:0hOzxbJfSu8iFiJimWGMNQ)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Trojan.Kryptik.CC2AOM
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:MSIL/Wacatac.B9nj
No IRMA results available.