Static | ZeroBOX

PE Compile Time

2071-04-17 08:03:01

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00018824 0x00018a00 6.2707451465
.rsrc 0x0001c000 0x000006d0 0x00000800 5.07426676361
.reloc 0x0001e000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0001c0a0 0x00000444 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0001c4e4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
********* d
*****
*****
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
IEnumerable`1
List`1
ToUInt32
ToInt32
Func`2
Func`3
Action`3
System.IO
GwDdAYDoLSxMY
RemotingTypeCachedData
System.Runtime.Remoting.Metadata
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
CommentId
DiscussionThread
Versioned
Synchronized
GetField
ReadToEnd
Append
get_Method
GetMethod
Replace
set_AutoScaleMode
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
RuntimeModule
CallByName
CallType
Capture
ApplicationSettingsBase
HttpWebResponse
GetResponse
Dispose
Create
Delegate
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
ParamArrayAttribute
WriteByte
ToByte
get_Value
GetObjectValue
PropertyValue
Remove
set_ClientSize
GetEncoding
InterfaceMapping
KeyValueOfStringString
ToString
GetString
WriteElementString
disposing
System.Drawing
get_Length
StartsWith
Microsoft.VisualStudio.Services.Common.Internal
System.ComponentModel
System.Xml
ArrayOfObjectFromXml
EnumerableOfObjectToXml
ArrayOfObjectToXml
ContainerControl
GetResponseStream
MemoryStream
get_Item
set_Item
System
Boolean
UIPermission
System.Configuration
System.Globalization
System.Reflection
MatchCollection
GroupCollection
GetBaseDefinition
TeamFoundationServiceException
MissingManifestResourceException
ArgumentNullException
ArgumentException
Microsoft.VisualStudio.Services.Common
StringComparison
FieldInfo
MethodInfo
TypeInfo
CultureInfo
EventInfo
PropertyInfo
GetInterfaceMap
ToChar
VolumeSeparatorChar
AltDirectorySeparatorChar
XmlReader
StreamReader
TextReader
IServiceProvider
StringBuilder
System.Resources.ResourceManager
System.CodeDom.Compiler
IContainer
XmlWriter
IEnumerator
GetEnumerator
.cctor
IdentityDescriptor
System.Diagnostics
GetFields
GetMethods
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
CommonResources
.Properties.Resources.resources
OpCodes
Matches
GetProperties
System.Runtime.InteropServices.ComTypes
BindingFlags
System.Threading.Tasks
Equals
System.Windows.Forms
Contains
System.Runtime.Extensions
System.Text.RegularExpressions
System.Security.Permissions
System.Collections
InternalTaskOptions
get_Groups
get_Chars
StringContainsIllegalChars
RuntimeHelpers
LastCalledMethodClass
GetEvents
Concat
Format
Object
System.Net
get_CharacterSet
System.Reflection.Emit
set_UserAgent
Microsoft.TeamFoundation.Framework.Client
Microsoft.TeamFoundation.Discussion.Client
Microsoft.TeamFoundation.Client
Int32FromXmlElement
Int16FromXmlElement
ToXmlElement
Comment
get_Current
GetEvent
Insert
Convert
System.Deployment.Internal.Isolation.Manifest
HttpWebRequest
MoveNext
System.Text
set_Text
IBindCtx
ToArray
get_Assembly
IEntryPointEntry
op_Equality
XmlUtility
TeamFoundationIdentity
IsNullOrEmpty
GetProperty
#C@B@;@
@D@6@J@
QPVNVJVbVpVSV_VbVhVLVRVPV[VpVoVCV_VLVOVnVoVBV`VLV:VHVFVHVNV@V;ViV@VZVJVKVcVBV>VSV
/n-7-Y-p-h-B-[-W-p-m-M-N-P-b-P-=-A-H-;-]-<-H-J-
_3_%_/_
_._9_<_;_
_)_*_6_
GTkikgkWknkSkgkEkNkWkxk\kckrkKkokkkskTkmkFkOkdktkokekckMkEkVkgkWkmkCkuk
j-W-G-X-4-G-A-b-i-B-f-
_u}w}f}
}t}e}h}m}
}^}m}_}w}n}i}
}_}a}t}b}
5Z<t<R<
<O<`<z<x<a<k<L<y<L<w<^<
<j<N<i<^<z<|<M<
;);8;(;-;
;2;<;';);
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
:xJx=x
x}xxxzx
|7xuzqznzhzwzFzuzKzJzTzRz[zYzWz[z
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.6.0.0
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
GdfzsqrayYKVdNMHVakHpGUWD1200
)bBvGlICpsjfYNvWjRYKFafdbUtLrxlDPoPESNbtOv1604
-CBXiEoxHjrCbvsCjOiDaMUuXhgFZkImFCBgSpfoUPblnt1"0
mqDnlkuQHCkxiSyxBfq1
wTQvrycpgWSjKUMsJ10
GvbkMUEHRXvsAgWQAvUmOi1.0,
%VnUOtADvzOQfeolgWQJGfUKDscNdmWOuGTgXR1.0,
%flhoBVHCucIFtzdChcbCqwqMAjDZvykinoQFC0
210314095553Z
220314095553Z0
GdfzsqrayYKVdNMHVakHpGUWD1200
)bBvGlICpsjfYNvWjRYKFafdbUtLrxlDPoPESNbtOv1604
-CBXiEoxHjrCbvsCjOiDaMUuXhgFZkImFCBgSpfoUPblnt1"0
mqDnlkuQHCkxiSyxBfq1
wTQvrycpgWSjKUMsJ10
GvbkMUEHRXvsAgWQAvUmOi1.0,
%VnUOtADvzOQfeolgWQJGfUKDscNdmWOuGTgXR1.0,
%flhoBVHCucIFtzdChcbCqwqMAjDZvykinoQFC0
;4_=+Qx
[TK4c7
GdfzsqrayYKVdNMHVakHpGUWD1200
)bBvGlICpsjfYNvWjRYKFafdbUtLrxlDPoPESNbtOv1604
-CBXiEoxHjrCbvsCjOiDaMUuXhgFZkImFCBgSpfoUPblnt1"0
mqDnlkuQHCkxiSyxBfq1
wTQvrycpgWSjKUMsJ10
GvbkMUEHRXvsAgWQAvUmOi1.0,
%VnUOtADvzOQfeolgWQJGfUKDscNdmWOuGTgXR1.0,
%flhoBVHCucIFtzdChcbCqwqMAjDZvykinoQFC
20210314095554Z
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
210101000000Z
310106000000Z0H1
DigiCert, Inc.1 0
DigiCert Timestamp 20210
http://www.digicert.com/CPS0
,http://crl3.digicert.com/sha2-assured-ts.crl02
,http://crl4.digicert.com/sha2-assured-ts.crl0
http://ocsp.digicert.com0O
Chttp://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
QJxy6z'
dwc_#Ri
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
160107120000Z
310107120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA0
fnVa')
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
https://www.digicert.com/CPS0
8aMbF$
V3"/"6
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Timestamping CA
210314095554Z0+
WindowsFormsApp1.Properties.Resources
EcMqjvCmiR
[^\u0000-\u007F
[^\u0000-\u007F]+
[^\u0000-\u
007F]+
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
CompanyName
FileDescription
FileVersion
3.79.685.569
InternalName
LegalCopyright
All Rights Reserved
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
3.79.685.569
Assembly Version
3.79.685.569
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan-Downloader ( 005793451 )
BitDefender Clean
K7GW Trojan-Downloader ( 005793451 )
Cybereason Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.DNK.gen!Eldorado
Symantec ML.Attribute.HighConfidence
TotalDefense Clean
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Clean
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
Alibaba TrojanDownloader:MSIL/Kryptik.da86faf4
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.PWS.Siggen2.62925
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic PWS.y
FireEye Generic.mg.bb0c7c3de7df87ca
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira TR/Dldr.Agent.tqrer
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan.Agent.NF37T3
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Trojan.Downloader.MSIL
Panda Clean
Zoner Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HOG
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan-Downloader.MSIL.Agent
MaxSecure Clean
Fortinet MSIL/Agent.HNY!tr.dldr
BitDefenderTheta Gen:NN.ZemsilF.34628.gm1@auQOq!li
AVG Win32:Trojan-gen
Paloalto Clean
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.