Static | ZeroBOX

PE Compile Time

2088-01-06 18:56:40

PDB Path

C:\Users\Administrator\Desktop\PassPrm\obj\Debug\PassPrm.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00008b4c 0x00008c00 5.4068304871
.rsrc 0x0000c000 0x00001b90 0x00001c00 2.70734470082
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000c598 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_ICON 0x0000c598 0x000010a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0000d650 0x00000022 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000d684 0x0000030c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000d9a0 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
7Cs.
xZs.
v4.0.30319
#Strings
get_P1
set_P1
label1
panel1
lblParm1
txtParm1
ToInt32
get_P2
set_P2
label2
txtParm2
AXDNAWJK9J3
label3
txtParm3
label4
txtParm4
label5
QDMMNKDPO9
<Module>
<PrivateImplementationDetails>
1C2890BDC821550514DA0182A88A0D0403693DA6718E002E5F961882466D7B8D
System.IO
GyanLada
Arelada
mscorlib
Thread
add_Load
FrmParent_Load
get_IndianRed
Synchronized
<ParmChild>k__BackingField
<ParmParent>k__BackingField
FrmChild
get_ParmChild
set_ParmChild
SaveParmChild
CreateInstance
defaultInstance
set_AutoScaleMode
get_WhiteSmoke
IDisposable
RuntimeFieldHandle
RuntimeTypeHandle
GetTypeFromHandle
DockStyle
set_BorderStyle
set_FlatStyle
FontStyle
set_Name
SecurityProtocolType
get_Culture
set_Culture
resourceCulture
ButtonBase
ApplicationSettingsBase
HttpWebResponse
GetResponse
Dispose
Create
DebuggerBrowsableState
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
DebuggerBrowsableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
ToByte
PassPrm.exe
get_Size
set_Size
set_AutoSize
set_ClientSize
System.Threading
System.Runtime.Versioning
disposing
System.Drawing
ShowDialog
ParmArg
get_Width
get_Black
add_Click
BtnCancel_Click
BtnCallForm_Click
set_Dock
btnCancel
System.ComponentModel
set_SecurityProtocol
ContainerControl
GetResponseStream
MemoryStream
Program
System
PassPrm
btnCallForm
ParmForm
resourceMan
set_TextAlign
AppDomain
GetDomain
set_ShowIcon
Application
get_Location
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
set_StartPosition
FormStartPosition
get_Maroon
Button
CopyTo
get_edit_redo
SaveParmRecebido
CultureInfo
get_Gainsboro
lblTexto
set_ShowInTaskbar
sender
get_ResourceManager
ServicePointManager
EventHandler
System.CodeDom.Compiler
IContainer
set_Anchor
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
PassPrm.FrmChild.resources
PassPrm.Properties.Resources.resources
PassPrm.FrmParent.resources
DebuggingModes
PassPrm.Properties
EnableVisualStyles
AnchorStyles
Settings
EventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
get_emblem_photos
RuntimeHelpers
ParmClass
CommonClass
components
GetObject
System.Net
get_Height
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
get_DialogResult
set_DialogResult
ContentAlignment
InitializeComponent
FrmParent
get_ParmParent
set_ParmParent
SaveParmParent
set_Font
Convert
HttpWebRequest
SuspendLayout
ResumeLayout
PerformLayout
get_Text
set_Text
set_TabIndex
set_MinimizeBox
set_MaximizeBox
set_ControlBox
TextBox
InitializeArray
ToArray
get_Assembly
set_Opacity
WrapNonExceptionThrows
PassPrm
Copyright
2020
$b5c18f11-5432-475b-864b-5a571ed4ba46
1.0.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.7.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
(*!(''
'-+"%''+#%$2
%&($$$$+!""2
A8%,9.
@5!O?5!"1)
G=*FMC1
ND2=QG5
NE2MoeX
TK9~TK8
bYHwe\KSe]L<e]L7`XF
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
VM:RWO<
d\J,e^L
vo^(wp`
|ue6~wg
C:\Users\Administrator\Desktop\PassPrm\obj\Debug\PassPrm.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
FORM AUXILIAR CHILD
Este formulario(child) mostra os parametros recebidos do formulario(parent)
Microsoft Sans Serif
lblTexto
txtParm2
txtParm1
label1
Parametro 2 :
lblParm1
Parametro 1 :
label2
C H I L D
btnCallForm
txtParm3
label3
Parametro 3 :
btnCancel
Cancel
label4
txtParm4
label5
Parametro 4 :
panel1
FrmChild
FORM AUXILIAR - CHILD
PASSING PARAMETERS
Este formulario (parent) chama e passa os parametros abaixo ao formulario (child)
Argumento original 1
Argumento original 2
Argumento original 3
Argumento original 4
Chamar Formulario Child
P A R E N T
FrmParent
Form Principal - Parent
PassPrm.Properties.Resources
edit_redo
emblem_photos
http://matix.cf/files/raz/mxwo
Default P1
Default P2
edit_redo
emblem_photos
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
PassPrm
FileVersion
1.0.0.0
InternalName
PassPrm.exe
LegalCopyright
Copyright
2020
LegalTrademarks
OriginalFilename
PassPrm.exe
ProductName
PassPrm
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.46358460
FireEye Trojan.GenericKD.46358460
CAT-QuickHeal Trojan.MSIL
Qihoo-360 Clean
McAfee RDN/Generic.rp
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.MSIL.Injuke.gen
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46358460
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/Trojan.NVMV-9222
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Generik.FLBDJTL
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Injuke.gen
Alibaba Trojan:Win32/Injuke.54c9e919
NANO-Antivirus Trojan.Win32.Injuke.ivresi
ViRobot Clean
AegisLab Trojan.MSIL.Injuke.4!c
Rising Clean
Ad-Aware Trojan.GenericKD.46358460
Emsisoft Trojan.GenericKD.46358460 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Trojan.Injuke.Win32.20467
TrendMicro TROJ_GEN.R002C0PET21
McAfee-GW-Edition RDN/Generic.rp
CMC Clean
Sophos Clean
Ikarus Trojan.SuspectCRC
GData Trojan.GenericKD.46358460
Jiangmin Trojan.MSIL.aabpc
Webroot Clean
Avira TR/Redcap.sasln
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2C35FBC
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Woreflint.A!cl
Cynet Malicious (score: 99)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Malware.AI.28357507
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PET21
Tencent Msil.Trojan.Injuke.Lorq
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet PossibleThreat
AVG Win32:Trojan-gen
Paloalto generic.ml
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Trojan.Malware.74181957.susgen
No IRMA results available.