Static | ZeroBOX

PE Compile Time

2039-04-06 12:29:16

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000361f4 0x00036200 7.97711723913
.rsrc 0x0003a000 0x000046c0 0x00004800 2.2691671316
.reloc 0x00040000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003a130 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0003e158 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0003e16c 0x00000366 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0003e4d4 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Dtiqyjksq
Dtiqyjksq.exe
<Module>
Registry
Dtiqyjksq.Exceptions
Object
System
mscorlib
Resources
WindowsFormsApp1.Properties
Settings
ApplicationSettingsBase
System.Configuration
AssemblyLoader
Costura
WrapperProducer
WindowsFormsApp1.Producers
.cctor
MoveObject
CallRegistry
Stopwatch
System.Diagnostics
Double
Boolean
WebClient
System.Net
DateTime
TimeSpan
get_Now
get_Ticks
ToString
String
Concat
DownloadData
IDisposable
Dispose
Console
ReadLine
Thread
System.Threading
ClassLibrary
set_Bytes2
WriteLine
get_Elapsed
set_Bytes1
get_TotalSeconds
Serial
PrintRegistry
ReadKey
ConsoleKeyInfo
Enumerable
System.Linq
System.Core
IEnumerable`1
System.Collections.Generic
SetObject
ResolveObject
m_Visitor
ResourceManager
System.Resources
m_Composer
CultureInfo
System.Globalization
RateObject
get_ResourceManager
GetTypeFromHandle
RuntimeTypeHandle
get_Assembly
Assembly
System.Reflection
get_Culture
set_Culture
get_Xswjtlynk
GetObject
get_Qxcogrrlr
VerifyObject
SelectObject
Culture
Xswjtlynk
Qxcogrrlr
defaultInstance
EnableObject
get_Default
SettingsBase
Synchronized
VisitObject
DisableObject
Default
nullCacheLock
nullCache
Dictionary`2
assemblyNames
symbolNames
isAttached
ForgotObject
CultureToString
culture
get_Name
ReadExistingAssembly
AssemblyName
get_CultureInfo
Equals
StringComparison
AppDomain
get_CurrentDomain
GetAssemblies
GetName
CopyTo
Stream
System.IO
source
destination
LoadStream
fullName
DeflateStream
System.IO.Compression
MemoryStream
GetManifestResourceStream
EndsWith
CompressionMode
set_Position
GetExecutingAssembly
resourceNames
TryGetValue
ReadStream
stream
get_Length
ReadFromEmbeddedResources
requestedAssemblyName
ToLowerInvariant
IsNullOrEmpty
ResolveAssembly
sender
ResolveEventArgs
get_Flags
AssemblyNameFlags
op_Equality
op_Inequality
Monitor
ContainsKey
set_Item
Attach
Interlocked
Exchange
ResolveEventHandler
IntPtr
add_AssemblyResolve
FlushObject
LogoutObject
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
STAThreadAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
CompilerGeneratedAttribute
EditorBrowsableAttribute
System.ComponentModel
EditorBrowsableState
WindowsFormsApp1.Properties.Resources.resources
costura.classlibrary.dll.compressed
costura.costura.dll.compressed
WrapNonExceptionThrows
FileZilla FTP Client
Tim Kosse
FileZilla
$d70e22c5-84ee-4d5e-91e9-5ef19d80b56c
3.48.1.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
fUhcTU
X8NGu:`
.nzz`gN
b/O_^T
d.N&F[
?10S2d
5Ch+wU
lx]z8T
(7i+vSy
/F?WTJ
\QzRzZ\Z
-(<0x
oB&z>p
57UF{n@1
IQ%7uM
&}O#gD
A=.}A#
*JJ&VWWO
iCiVhl
UmVerbB{"
JBTQIGnO
;{lomN
>Y9l`|
=DwQ1QN
mxuxExixZ|,
oYG/(q
dxeM=e
%Y|[=q
)z8GpC
N)?Pj5
><4{(u
8y=EY[m
=f |>yQ
+<%{<z
My'xf
9{5g<8
\[K3+-,
8xI|B>
Xl`N,?(%!
."\)TP
4R1a<-'E
g=HEqg=
r_PKL.C
sC-"TrJ
F'N14@
Y&nSk{Uk
g32fgJ
q@nA<Wa
)9^iN[
5rbB]
@T~CyQb
V'Mes//
*;~TEb
jT?Hvh
hg&U4c
v&"LiJ
Ge"SoOoJ
>'H>%O
fpsd|q
!sA8?V
B_]o4\
avNPz"
M-f oJI
jTA^GX
QHB~"j)
}QLH~$
3}RAZf
vbdVN#n
PEB"_e
8dCIab3q
Fkbk=^fJ
d$:(K/5H
DQsRr|
wg<RNy
`RLx#|
\)%sa|
IE,:aN
$|FLL
2{#<zC
YS\@V1
YPYNSXVu
AeYYM!x
@Op-Ah;
LSiWat+
As n 9
^AZ@ZA/
ku>%+./2
{U[SWK
(y;>^?
b&AF?+
|ufvu?{
)%%))'
MU[ok{t
rO4Xstl
xf#"ycnn
Hf{R$>
y%%K3^(
[MMYD'
fki0x9]
}l|^=^
c#]}|BK
^.I5kx
4-k5p*
nyg\3N
q~as3~|
cKsMsJs_
93X5up/
:H\.7C
q5`ab_
-+//\W
e_{tTT
Y|i<oO;
IE^iZsy%> {
VVPO\@HHX
U].M 7
!EY)EM
}.>nQA.
^7"=Le;
AUU|jC}U
Y*~_'\
Y#K+LF
Buq_PK*I
Lx> ~?$
=ArZA|
q-ZB_c
\F-">_
yx5H+r
g[`Ns4
t.!xSd/xMe0oV
BwFW[6
@i7s0J
kce18Q
k%<^>/
<`_@mt
v*r:W$
-.DNqc
~v:PEDx
o0MOMu
|0`}Eez
K'_]v>
|%.c]g
o2IG2o
HfpHp|K
*JVcJl
qcB6V8
Y1hQE
uM@3)
^w0SRn
ml1jh*
@q&WhOQc1'b
fx#omU
)UX)WM9
=p8me;.
[?YolG
gU<x*<[
}[sa31
0M.TOz
1'#TSD
F(oO;>
?L|35t4[
\\(ewv
}UH}~4
5J's"v=
}$,~j}c!9
/z_APmk
:$2PVb
qJ9-BqF^
;OfJ5cQ&
{o@#DC
&%/R,
"opWkj,a,}h
JN1H[$
UWY'Esv
~3z~UBV
_{Qf9D
]>s6lo
$ej~$=6
k$1eJ
*cisQ/
aKLC$f
@;;{:MG
|z~5}~
%c2]amo#
[yxt W
!B52E|
x`.O]-X
2ge{/MJG
8wSj%R
(!hiL*U
?cx=9J
@Vhl*[
L*FwI#
V\*s <
'Y=Lx[i
Opv.APO
c#~-OZBD
?CRd5N
|,5P%D
]"S2lB
48}jr
X7?42Y*
\^|5@>
7`bY\Dw
99b!w5
B,PMbY
Ch|T D
>PE~3
Cj\ZcS
A(BbG:B
?XClF
R*ea5>
4]:3`A
@WKE9~|
_+4V%\xr
gkJdk\
;R*l>~
%$DD$y:
J.l~hPT
r)Z~u\
YY/UF_
u8t`FI
u"Mc}]
mr>vg};:
{t`AMRlV
^1I*W
VeJ_t8
S?\30d
=CV_\V
\Ur9W7I
lya>xq
J:g>9u\{O
YTrbJ}
?$fSZ`A~
u*K9aH
 `gM/
;$+mnD
Gb7!DK
No{Vo^
WZ6iv]
dA'dA_
fcs_jR
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
Q(E!$)K$
$i9*-*m
]P=V/"Y
2q;.hS{
5ubb5y6
jeIGSOg
,e?op[<
?*X7>nT
ne{8KC
<&tmQ7.+
)k4YX'
$noyYzT
_F*[UK
pW#3RKY
o!Opz>9
>g#G(1k
(&xGEq
&yBi"Z(
h'+)jt+Tq?
D;Y)P}
#t5'i2
Dt>|Bu8
6 K-D;
b6#O KV;
X&'-r3&
\MZ|3X
dVR@BV
F;,3@6
"F8se-T
~vS%zX
Q#8_|4
Mn*O3l
T566.h\
[Y,v!w)
FY!>RCo
FrS&=U
BOf8k7Hk
,Lalgv
Vx'R)['
J'p{z$
MGjW&i
9 ,IgG
2p=3#\
JK5D\$DR
cwj"_:zdP
bD~83"}Y
QGX:Ix
@6ky_xB>R
vpq(k=
1`<=&:&
QWLQQV]~
</U>/%N@
7CkD1X|Ms+
`/;!Z.
B,*STE
8KJ?m0G
DZEj@B
dVb^.c
T2vY7,
h/0O@^&
"jgv+N
t.]N,=
z`W+63,
.6\^xr
7~wX_M
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
http://dl.google.com/googletalk/googletalk-setup.exe?t=
Speed: {0} bps
Press any key to continue...
Download duration: {0}
Downloading file....
File size: {0}
https://www.yoursite.com
bytes / S
WindowsFormsApp1.Properties.Resources
Xswjtlynk
Qxcogrrlr
.compressed
classlibrary
costura.classlibrary.dll.compressed
costura
costura.costura.dll.compressed
Qxcogrrlr
Xswjtlynk
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
FileZilla FTP Client
CompanyName
Tim Kosse
FileDescription
FileZilla FTP Client
FileVersion
3.48.1.0
InternalName
Dtiqyjksq.exe
LegalCopyright
Tim Kosse
LegalTrademarks
OriginalFilename
Dtiqyjksq.exe
ProductName
FileZilla
ProductVersion
3.48.1.0
Assembly Version
3.48.1.0
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.f800c3f06fc079a0
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren W32/MSIL_Kryptik.DYX.gen!Eldorado
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Win32:MalwareX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
MaxSecure Trojan.Malware.300983.susgen
CMC Clean
Sophos ML/PE-A
Ikarus Trojan.MSIL.Inject
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!F800C3F06FC0
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.Crypt.MSIL
Panda Clean
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.34678.om0@ayTuzBf
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.b0611b
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.