Static | ZeroBOX

PE Compile Time

2093-07-30 17:08:27

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00004bf8 0x00004c00 5.57720967409
.rsrc 0x00008000 0x000005bc 0x00000600 4.12947027731
.reloc 0x0000a000 0x0000000c 0x00000200 0.0776331623432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00008090 0x0000032a LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000083cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<>c__DisplayClass2_0
<SystemDataSqlClientSqlColumnEncryptionEnclaveProviderj>b__0
<>o__0
<>p__0
<>c__DisplayClass2_1
<SystemDataSqlClientSqlColumnEncryptionEnclaveProviderj>b__1
<>p__1
Func`1
IEnumerable`1
CallSite`1
kernel32
ToUInt32
ToInt32
<>p__2
cbReserved2
lpReserved2
Func`3
ToInt64
isWow64
Func`4
__StaticArrayInitTypeSize=226
FE11E3722805C72BC0137B3817E9B4977419FA88
get_UTF8
<Module>
<PrivateImplementationDetails>
SystemComponentModelComponentResourceManagerC
get_MicrosoftWinSessionEndedEventHandlerC
set_MicrosoftWinSessionEndedEventHandlerC
SystemComponentModelDefaultPropertyAttributeE
SystemNetMimeMimeMultiPartE
lSystemNetWebClientcDisplayClassF
SystemConfigurationIriParsingElementF
SystemCodeDomCodeTypeDeclarationCollectionG
SystemDataSqlClientSqlNotificationTypeH
BidBindingCookieI
get_SystemNetSemaphoreI
SystemComponentModelIComNativeDescriptorHandlerI
SystemSecurityCryptographyCAPIBaseCERTIDUNIONK
SystemDataSqlClientSqlConnectioncDisplayClassK
SystemSecurityCryptographyCAPIBaseCMSGENVELOPEDENCODEINFOL
SystemDataXmlToDatasetMapL
SystemComponentModelDesignSerializationMemberRelationshipServiceRelationshipEntryL
System.IO
SystemNetNetworkInformationIPvInterfacePropertiesP
SystemComponentModelIDataErrorInfoR
SystemNetWebSocketsWebSocketHttpListenerDuplexStreamHttpListenerAsyncEventArgsHttpListenerAsyncOperationV
SystemNetContextAwareResultX
SystemNetDirectProxyX
SystemNetNetworkInformationOldOperationalStatusZ
SystemConfigurationIriParsingElementFa
SystemDiagnosticsSourceSwitcha
SystemNetMimeEightBitStreama
SystemDataCommonDbSchemaTableColumnEnuma
SizeOfRawData
PointerToRawData
mscorlib
NewtonsoftJsonLinqJObjectGetEnumeratordc
e_magic
System.Collections.Generic
SystemDataPrimaryKeyTypeConverterc
dwThreadId
dwProcessId
hThread
lpReserved
<SystemNetMailMBDataTypeu>k__BackingField
Append
GetMethod
method
SystemDataSqlClientSqlDataReaderSmiReaderEventSinkvasd
Replace
CreateInstance
exitCode
SizeOfImage
EndInvoke
BeginInvoke
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
handle
lpTitle
hModule
procName
fileName
SystemIOCompressionZLibNativeNativeMethodsNtionName
lpApplicationName
lpCommandLine
ValueType
SecurityProtocolType
ExpressionType
flAllocationType
GetType
System.Core
Signature
MethodBase
ImageBase
Dispose
Create
MulticastDelegate
DebuggerBrowsableState
CallSite
CompilerGeneratedAttribute
UnverifiableCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
dwFillAttribute
AssemblyFileVersionAttribute
SecurityPermissionAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
ReliabilityContractAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
ParamArrayAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
SetValue
Impledges.exe
dwXSize
dwYSize
dwSize
SizeOf
Encoding
System.Runtime.Versioning
FromBase64String
ToString
GetString
SystemIOPortsSerialErrorg
SystemDiagnosticsEntryWrittenEventArgsg
get_Length
SystemNetContextAwareResultStateFlagsi
SystemDataSqlClientSqlColumnEncryptionEnclaveProviderj
SystemNetNetworkInformationMibUdpStatsj
AsyncCallback
callback
SystemNetServicePointConnectSocketStatek
SystemConfigurationNameValueFileSectionHandlerk
AllocHGlobal
FreeHGlobal
Marshal
kernel32.dll
System
SystemDiagnosticsListenerElementsCollectionm
SystemNetSafeDeleteContextm
SystemSecurityCryptographyCAPIBaseCERTIDUNIONn
Boolean
hToken
hNewToken
lpNumberOfBytesWritten
lpProcesSystemNetMailMailHeaderInfoHeaderInfon
BinaryOperation
SecurityAction
action
System.Reflection
DllNotFoundException
EndOfStreamException
System.Runtime.ConstrainedExecution
SystemNetSocketsAcceptExDelegateo
MethodInfo
lpStartupInfo
CSharpArgumentInfo
PropertyInfo
lpDesktop
Microsoft.CSharp
FileHeader
OptionalHeader
StringBuilder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
ServicePointManager
SystemNetUnsafeNclNativeMethodsUnsafeWinInetCacher
GetDelegateForFunctionPointer
SystemComponentModelAttributeProviderAttributer
gcrootSystemStringr
SystemDataSqlClientSqlConnectionStringr
hStdError
Activator
.cctor
IntPtr
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
Impledges
bInheritHandles
lpThreadAttributes
lpProcessAttributes
dwCreationFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
ContextFlags
dwFlags
System.Linq.Expressions
System.Security.Permissions
NumberOfSections
get_Chars
dwXCountChars
dwYCountChars
SizeOfHeaders
RuntimeHelpers
hProcess
GetProcAddress
lpBaseAddress
VirtualAddress
lpAddress
arguments
SystemRuntimeInteropServicesComTypesDATADIRt
Object
object
flProtect
System.Net
Target
op_Explicit
IAsyncResult
result
lpEnvironment
AddressOfEntryPoint
Convert
get_Host
set_Host
hStdInput
hStdOutput
System.Text
pContext
SystemNetUnsafeNclNativeMethodsWinHttpWINHTTPAUTOPROXYOPTIONSu
get_SystemNetMailMBDataTypeu
set_SystemNetMailMBDataTypeu
SystemCollectionsSpecializedStringDictionaryu
SystemDataSqlClientSqlDataReaderSmiReaderEventSinkv
e_lfanew
wShowWindow
InitializeArray
Consistency
LoadLibrary
FreeLibrary
lpCurrentDirectory
op_Equality
op_Inequality
System.Security
GetProperty
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
WrapNonExceptionThrows
Ss Cmd
Ss Command Line
Ss Corp.
5.14.22.1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
SystemDiagnosticsEventLogEntryY
Expect100Continue
SecurityProtocol
NetConfigurationUnicodeEncodingConformanceO
BNetConfigurationUnicodeEncodingConformanceOEc7Ew0fIT8AM147MBJBDzM+EjMpCzQHNToABx4vJ20UeB40CQQjNiI6PxA7RSc6OgFnZB0eFhwkG0M8ABspEzAGDGcNMRIbGxttBzMMAw0OPh4rPg0OaTI6LCEtZx0FPSEZOjlZASEBIx5aJ2oyehUiPmUZBR8tJy4NAAQIM1Y=
ANetConfigurationUnicodeEncodingConformanceOzNuWgs1Dz0VDzkDMBk+JwsEO0o=
MNetConfigurationUnicodeEncodingConformanceODwFWQoQOn0AIVInGDwYZzMuDgIvCzAHND1kDTM6UAwSEwJoMQBlHi4POz86GQUkAgYBGwhGLyYwACU7KDU9GQ4JJjgLWwoNHiEOBTYMH0Q0BwURLRw0LzEPHiQ=
QtWiiXwKLXkWT
MNetConfigurationUnicodeEncodingConformanceOEYBEAs1ITgBIiIiDhYMJA==
MNetConfigurationUnicodeEncodingConformanceOxoFAgsfAD4WHxMk
ANetConfigurationUnicodeEncodingConformanceOEcdBTAAJScZECEhDWMiLQpZNAIvCw4SNTkXBwEeVGU=
PROTECT
BNetConfigurationUnicodeEncodingConformanceOzMBEAsPGz4VADk7ARk+ITBbDg0oO2VW
ANetConfigurationUnicodeEncodingConformanceOEYvHwpqIQIVD148NhYhag==
ANetConfigurationUnicodeEncodingConformanceOiwZMQtrFHkCHikuNmM6OwpaFUo=
BNetConfigurationUnicodeEncodingConformanceOxk7EA0QISMuHS0kNhZNPTsxP0o=
BNetConfigurationUnicodeEncodingConformanceO0cdGQ0fIRovNVI9Dgk6LT0+DgMpfxJe
BNetConfigurationUnicodeEncodingConformanceO0ZuWicyJQMWADkCNRk+OzA+CjMpfm1bDQw5RA==
ANetConfigurationUnicodeEncodingConformanceO0YBWT8fHzIWDy08BWNNIg0uDkMvDWVW
BNetConfigurationUnicodeEncodingConformanceO0ZuWicyJR8WADkCNRk+OzA+CjMpfm1bDQw5RA==
BNetConfigurationUnicodeEncodingConformanceOEYBWT8fHzIWDy08BWNNIg0uDkMvDWVW
BNetConfigurationUnicodeEncodingConformanceOBkBEw0PRicaHwMuDgYyPA==
BNetConfigurationUnicodeEncodingConformanceORoFPws1RiMvHjEnDgkQBzMFFhsSfwobNWZlSQ==
@C:\WindPROTECTows\MicrPROTECTosoft.NPROTECTET\FramPROTECTework\v4.0.30PROTECT319\AddInPPROTECTrocess32.exePROTECT
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Ss Command Line
CompanyName
FileDescription
Ss Cmd
FileVersion
5.14.22.1
InternalName
Impledges.exe
LegalCopyright
Ss Corp.
LegalTrademarks
OriginalFilename
Impledges.exe
ProductName
Ss Cmd
ProductVersion
5.14.22.1
Assembly Version
12.3.5.3
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Razy.839017
FireEye Generic.mg.c4007a10fead6776
CAT-QuickHeal Clean
ALYac Gen:Variant.Razy.839017
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005781551 )
BitDefender Gen:Variant.Razy.839017
K7GW Trojan-Downloader ( 005781551 )
Cybereason malicious.0fead6
BitDefenderTheta Gen:NN.ZemsilF.34608.cm2@aSSdcAd
Cyren W32/MSIL_Troj.AIO.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/TrojanDownloader.Small.CKP
Baidu Clean
APEX Malicious
Avast Win32:RATX-gen [Trj]
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Razy.839017
Emsisoft Gen:Variant.Razy.839017 (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Siggen2.62510
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Gen:Variant.Razy.839017
MaxSecure Clean
Avira HEUR/AGEN.1141272
MAX malware (ai score=81)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Razy.DCCD69
SUPERAntiSpyware Clean
AhnLab-V3 Malware/Win32.RL_Generic.C4365930
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
TotalDefense Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.RedLineStealer
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet MSIL/Small.CKP!tr.dldr
Webroot Clean
AVG Win32:RATX-gen [Trj]
Paloalto Clean
CrowdStrike win/malicious_confidence_80% (D)
Qihoo-360 Clean
No IRMA results available.