Static | ZeroBOX

PE Compile Time

2079-04-02 15:24:20

PDB Path

C:\Users\Test\source\repos\Payload Builder\Dynamic Payload\obj\Debug\Dynamic Payload.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000014f8 0x00001600 5.25082026424
.rsrc 0x00004000 0x000005dc 0x00000600 4.14377687329
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x0000034c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043ec 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
<>9__0_0
<Main>b__0_0
<>c__DisplayClass0_0
<>9__3_0
<RandomString>b__3_0
<>c__DisplayClass0_1
<Main>b__1
IEnumerable`1
CS$<>8__locals1
Microsoft.Win32
<>9__0_2
<Main>b__0_2
<>c__DisplayClass0_2
Func`2
CS$<>8__locals2
<>9__0_3
<Main>b__0_3
<>9__4
<Main>b__4
<Main>b__5
<Main>b__6
<Main>b__7
<Module>
System.IO
DownloadData
mscorlib
System.Collections.Generic
Thread
Dynamic Payload
Dynamic_Payload
Enumerable
System.Core
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
SetValue
Dynamic Payload.exe
System.Threading
System.Runtime.Versioning
DownloadString
RandomString
get_ExecutablePath
GetFolderPath
get_Length
length
runall
Program
System
Random
random
Application
System.Reflection
RegisterInStartup
System.Linq
SpecialFolder
CurrentUser
.cctor
System.Diagnostics
payloads
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
WriteAllBytes
System.Windows.Forms
Contains
get_Chars
Process
Concat
Repeat
Object
Select
System.Net
WebClient
Environment
ThreadStart
ToArray
OpenSubKey
RegistryKey
Registry
WrapNonExceptionThrows
Dynamic Payload
Copyright
2021
$a52ad413-302a-4cef-9098-0b17734461c4
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
%ff/(z-
C:\Users\Test\source\repos\Payload Builder\Dynamic Payload\obj\Debug\Dynamic Payload.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
https://pastebin.com/raw/VVpUeH0C
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789
SECONDARY_IPLOGGER
MAIN_IPLOGGER
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
Dynamic Payload
FileVersion
1.0.0.0
InternalName
Dynamic Payload.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
Dynamic Payload.exe
ProductName
Dynamic Payload
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.176a67399e1fd4d5
CAT-QuickHeal Clean
Qihoo-360 Clean
McAfee Clean
Cylance Clean
VIPRE Clean
SUPERAntiSpyware Clean
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky UDS:Trojan-PSW.MSIL.Racealer.gen
BitDefender Clean
NANO-Antivirus Clean
Paloalto generic.ml
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira TR/ATRAPS.Gen
Antiy-AVL Clean
Kingsoft Clean
Microsoft Backdoor:Win32/Bladabindi!ml
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 90)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34662.am0@aiMTC!e
ALYac Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.Downloader.MSIL.Generic
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Clean
Fortinet Clean
AVG FileRepMalware
Cybereason malicious.cb9ff2
Panda Clean
MaxSecure Clean
No IRMA results available.