Static | ZeroBOX

PE Compile Time

2043-08-16 00:24:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0002b504 0x0002b600 6.72492336372
.rsrc 0x0002e000 0x00028ce8 0x00028e00 3.00162046347
.reloc 0x00058000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00056240 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000566a8 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0005672c 0x000003d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00056afc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
%(r7
%)r#7
%-r'7
%.r#7
%/r+7
%0r/7
%2r37
%7r77
%cr7
%dr#7
%hr'7
%ir#7
%jr+7
%kr/7
%mr37
%sr;7
%xr?7
%yrC7
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
v4.0.30319
#Strings
Microsoft.VisualStudio.Modeling.Sdk.Integration.Shell.15.0
Microsoft.VisualStudio.Modeling.Sdk.Integration.15.0
List`1
PInvoke.Kernel32
Microsoft.Win32
ToInt32
Mscorlib_KeyedCollectionDebugView`2
WIN32_FILE_ATTRIBUTE_DATA
get_LCID
FORMATFLAGS
NTSTATUS
System.Runtime.Remoting.Metadata
System.Private.Reflection.Metadata
mscorlib
System.Collections.Generic
Microsoft.VisualBasic
get_ErrorExtractTemplateFailed
Synchronized
get_ErrorScopeTypeNotValid
get_ErrorTemplateFilePathNotValid
Append
get_ErrorDocDataNotFound
get_ErrorServiceTypeNotFound
get_ErrorEditorNotFound
Replace
get_ParentScopeOrNamespace
GetNamespaceReference
GetTypeReference
ComputeNestedTypeHashCode
ToHashCode
Win32ErrorCode
SeverityCode
set_AutoScaleMode
ComposeUIMessage
FormatMessage
PInvoke
IDisposable
Double
ToNamespaceReferenceHandle
ToTypeReferenceHandle
SafeHandle
RuntimeTypeHandle
ConstantStringValueHandle
GetTypeFromHandle
ToNamespaceDefinitionHandle
TypeDefinitionHandle
DangerousGetHandle
SafeLibraryHandle
get_Name
get_TypeName
System.Runtime.InteropServices.WindowsRuntime
UnmanagedType
ComInterfaceType
ClassInterfaceType
get_HandleType
get_EnclosingType
get_ParentNamespaceOrType
OidKeyType
PInvoke.Windows.Core
get_CurrentCulture
Capture
ApplicationSettingsBase
MethodResponse
Dispose
EditorBrowsableState
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
DefaultSettingValueAttribute
UserScopedSettingAttribute
ContractClassAttribute
ToByte
get_Value
Win32Native
set_ClientSize
Microsoft.VisualStudio.Threading
NewLateBinding
System.Runtime.Remoting.Messaging
DownloadString
ToString
GetString
Substring
disposing
get_ErrorTemplateFileMissing
System.Drawing
get_ErrorViewReferenceMismatch
get_Length
System.ComponentModel
LateCall
Microsoft.VisualStudio.Modeling.Integration.Shell
get_ErrorArgumentMemberCannotBeNull
ContainerControl
UserControl
get_Item
set_Item
System
Boolean
System.Deployment.Internal.Isolation
Microsoft.VisualStudio.Modeling.Integration
System.Configuration
System.Globalization
System.Runtime.Serialization
System.Reflection
MatchCollection
GroupCollection
WebHeaderCollection
get_NamespaceDefinition
GetNamespaceDefinition
GetTypeDefinition
CallingConvention
SoapOption
Win32Exception
MissingManifestResourceException
NTStatusException
StringComparison
CultureInfo
ToChar
MetadataReader
System.Private.TypeLoader
IFormatProvider
HashCodeBuilder
System.Resources.ResourceManager
System.CodeDom.Compiler
IContainer
IterableToEnumerableAdapter
IEnumerator
GetEnumerator
.cctor
SurrogateSelector
System.Diagnostics
System.Runtime.InteropServices
Microsoft.VisualBasic.CompilerServices
System.Runtime.CompilerServices
System.Resources
.Properties.Resources.resources
Matches
Utilities
System.Security.Cryptography.X509Certificates
TypeAttributes
System.Reflection.Primitives
get_Flags
FormatMessageFlags
VSModelBusStrings
Equals
get_ErrorCannotFindContainingProjectItems
TypeHashingAlgorithms
System.Windows.Forms
Contains
NativeFormatReaderExtensions
System.Text.RegularExpressions
System.Collections
get_Groups
get_Chars
get_Headers
RegistryChangeNotificationFilters
System.Diagnostics.Contracts
Concat
Internal.Metadata.NativeFormat
Internal.NativeFormat
Object
LateGet
System.Net
ReadOnlyPermissionSet
CharSet
op_Explicit
WebClient
get_Current
Convert
SortedList
MoveNext
set_Text
get_ErrorCannotCreateView
ToArray
get_Assembly
LoadLibrary
get_Severity
System.Security
IReferenceIdentity
get_ErrorArgumentMemberCannotBeEmpty
IsNullOrEmpty
E1E.E'E
A]P]]]c]@]d]Z]
N N#N N
3x8k8r8j8x8y8
8N8_8~8`8y8Z8
8m8~8J8W8l8W8_8\8
m0m6m;m-m.m
m0m1m5m
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.6.0.0
_CorExeMain
mscoree.dll
t<!gnL
}]=2=r
40;2i<%Xyi
@}]=Ug
Fr?Fr
FrFrOFr
FrFrOFr
Fr?Fr
Fr/FroFr
Fr_Fr
Fr_Fr
Fr/FroFr
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
JVtPeMTCpO
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}{43}{44}{45}{46}{47}{48}{49}{50}{51}{52}{53}{54}{55}{56}{57}{58}{59}{60}{61}{62}{63}{64}{65}{66}{67}{68}{69}{70}{71}{72}{73}{74}{75}{76}{77}{78}{79}{80}{81}{82}{83}{84}{85}{86}{87}{88}{89}{90}{91}{92}{93}{94}{95}{96}{97}{98}{99}{100}{101}{102}{103}{104}{105}{106}{107}{108}{109}{110}{111}{112}{113}{114}{115}{116}{117}{118}{119}{120}{121}{122}{123}{124}{125}{126}{127}{128}{129}{130}{131}{132}{133}{134}{135}{136}{137}
UserAgent:
Mozilla/5.0 (X11;
Linux x86
AppleWebKit/537
KHTML, l
Gecko) Chrome
0.2704.
106 Saf
ari/537
.36 OPR/
2220.41
{0}{1}{2}{3}{4}{5}{6}{7}{8}{9}{10}{11}{12}{13}{14}{15}{16}{17}{18}{19}{20}{21}{22}{23}{24}{25}{26}{27}{28}{29}{30}{31}{32}{33}{34}{35}{36}{37}{38}{39}{40}{41}{42}{43}{44}{45}{46}{47}{48}{49}{50}{51}{52}{53}{54}{55}{56}{57}{58}{59}{60}{61}{62}{63}{64}{65}{66}{67}{68}{69}{70}{71}{72}{73}{74}{75}{76}{77}{78}{79}{80}{81}{82}{83}{84}{85}{86}{87}{88}{89}{90}{91}{92}{93}{94}{95}{96}{97}{98}{99}{100}{101}{102}{103}{104}{105}{106}{107}{108}{109}{110}{111}{112}{113}{114}{115}{116}{117}{118}{119}{120}{121}{122}{123}{124}{125}{126}{127}{128}{129}{130}{131}{132}{133}{134}{135}{136}{137}{138}{139}{140}{141}{142}{143}{144}{145}{146}{147}{148}{149}{150}{151}{152}{153}{154}{155}{156}{157}{158}{159}{160}{161}{162}{163}{164}{165}{166}{167}{168}{169}{170}{171}{172}{173}{174}{175}{176}{177}{178}{179}{180}{181}{182}{183}{184}{185}{186}{187}{188}{189}{190}{191}{192}{193}{194}{195}{196}{197}{198}{199}{200}{201}{202}{203}{204}{205}{206}{207}{208}{209}{210}{211}{212}{213}{214}{215}{216}{217}{218}{219}{220}{221}{222}{223}{224}{225}{226
OneMillionPacoRabanne.Properties.Resources
VS_VERSION_INFO
StringFileInfo
040904e4
Comments
CompanyName
FileDescription
FileVersion
4.144.557.25
LegalCopyright
All Rights Reserved
InternalName
LegalTrademarks
OriginalFilename
ProductName
ProductVersion
4.144.557.25
Assembly Version
4.144.557.25
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.83c01f327b9dad97
CAT-QuickHeal Clean
McAfee Artemis!83C01F327B9D
Cylance Unsafe
VIPRE Trojan.Win32.Generic.pak!cobra
SUPERAntiSpyware Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.488899
Baidu Clean
Cyren W32/MSIL_Kryptik.CXK.gen!Eldorado
Symantec Clean
ESET-NOD32 a variant of MSIL/TrojanDownloader.Agent.HQO
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Downloader.Agent!8.B23 (CLOUD)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Ikarus Trojan-Downloader.MSIL.Agent
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34654.vm0@a4wl5Lci
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.95%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_98%
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 HEUR/QVM03.0.3937.Malware.Gen
No IRMA results available.