Static | ZeroBOX

PE Compile Time

2021-02-18 21:32:17

PDB Path

D:\OneDrive\Dokumenty\Kody\Composer\update\WindowsApplication3\obj\Debug\download.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00019494 0x00019600 7.58287015484
.sdata 0x0001c000 0x00000138 0x00000200 2.02791589579
.rsrc 0x0001e000 0x00003208 0x00003400 3.51541592566
.reloc 0x00022000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00020b48 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00020fb0 0x00000068 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0001e250 0x000002d8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00021018 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.sdata
@.reloc
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
paint.net 4.0.5
2015-01-13T16:01:24+01:00
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
[UFK3r
Zt1X<U
Se>7e4
Y^}&g
KHA)kel
RQRN2I
"[)n o
O&?{e5
Kk+T>U
ZT1x<V
hey6WA
ic{=OL
A<FH.m
u(L7vWq
<.-ErP
s,E>hT
<&-ErP
Ik{k4rZjzm
-fy^++
=|5|-z
tgF4iW
qn8\,ZRp
u)NqJ-#
a0y~?/
e%i9E
F&m*Tk
jXG,La
i}k2Kg
=<t%Ys
m:4W{
y"4R<n
i}g2Ig
UE+IMV
p_X_ZJ
\][P)ic
)*8zw~
{Xt=oJ6
!)FQz8
9v7.st
ci`sLg
*u#(JQ|9
v{Qf2A>
'y&/t~.
b+kKhF
B+kKhF
Wydv;4Q_
Uk(WU#
T=:nT
Wn\mJU|
F?YaaR
\]xy/$
.u84-_T
jUib18j
x[SS<iwi
>(})/#
oookz4y
kmqnnLv
}oqis
PUr|%|4%
q5eBXzt
\n&5*J|;7O
;F)h}_
s*N5)p
BmIv><
OEy4s\E
zthFSi
*tp8z*
)v.H;|
e$3Xj6
,O%jnS
,V;k}O
.z;z~H:
_-J\9Nq
Hb@:ugv-$
;*")f
'yJRwnRm
IJu')Ns
v4.0.30319
#Strings
<Module>
mscorlib
Microsoft.VisualBasic
MyApplication
download.My
MyComputer
MyProject
MyForms
MyWebServices
ThreadSafeObjectProvider`1
InternalXmlHelper
RemoveNamespaceAttributesClosure
Resources
download.My.Resources
MySettings
MySettingsProperty
updateWindow
download
Microsoft.VisualBasic.ApplicationServices
WindowsFormsApplicationBase
.cctor
__ENCAddToList
System.Collections.Generic
List`1
System
WeakReference
__ENCList
OnCreateMainForm
Microsoft.VisualBasic.Devices
Computer
Object
get_Computer
m_ComputerObjectProvider
get_Application
m_AppObjectProvider
get_User
m_UserObjectProvider
get_Forms
m_MyFormsObjectProvider
get_WebServices
m_MyWebServicesObjectProvider
Application
WebServices
get_updateWindow
m_updateWindow
set_updateWindow
Create__Instance__
System.Windows.Forms
Instance
Dispose__Instance__
instance
System.Collections
Hashtable
m_FormBeingCreated
Equals
GetHashCode
GetType
ToString
get_GetInstance
m_ThreadStaticValue
GetInstance
IEnumerable`1
System.Xml.Linq
XElement
get_Value
source
set_Value
get_AttributeValue
set_AttributeValue
XAttribute
CreateAttribute
XNamespace
CreateNamespaceAttribute
RemoveNamespaceAttributes
inScopePrefixes
inScopeNs
attributes
IEnumerable
AttributeValue
m_inScopePrefixes
m_inScopeNs
m_attributes
ProcessXElement
ProcessObject
System.Resources
ResourceManager
resourceMan
System.Globalization
CultureInfo
resourceCulture
get_ResourceManager
get_Culture
set_Culture
System.Drawing
Bitmap
get_infokoliber720
Culture
infokoliber720
System.Configuration
ApplicationSettingsBase
defaultInstance
addedHandler
addedHandlerLockObject
EventArgs
AutoSaveSettings
sender
get_Default
Default
get_Settings
Settings
Dispose
disposing
System.ComponentModel
IContainer
components
InitializeComponent
Form1_Load
System.Threading
Monitor
get_Count
get_Capacity
get_Item
get_IsAlive
set_Item
RemoveRange
set_Capacity
System.Runtime.CompilerServices
RuntimeHelpers
GetObjectValue
get_UseCompatibleTextRendering
SetCompatibleTextRenderingDefault
AuthenticationMode
set_IsSingleInstance
set_EnableVisualStyles
set_SaveMySettingsOnExit
ShutdownMode
set_ShutdownStyle
set_MainForm
EditorBrowsableAttribute
EditorBrowsableState
System.CodeDom.Compiler
GeneratedCodeAttribute
System.Diagnostics
DebuggerHiddenAttribute
STAThreadAttribute
DebuggerNonUserCodeAttribute
DebuggerStepThroughAttribute
Microsoft.VisualBasic.CompilerServices
StandardModuleAttribute
HideModuleNameAttribute
System.ComponentModel.Design
HelpKeywordAttribute
ArgumentException
System.Reflection
TargetInvocationException
Control
get_IsDisposed
RuntimeTypeHandle
GetTypeFromHandle
ContainsKey
String
GetResourceString
InvalidOperationException
Activator
CreateInstance
ProjectData
Exception
SetProjectError
get_InnerException
get_Message
ClearProjectError
Remove
Component
MyGroupCollectionAttribute
ThreadStaticAttribute
System.Runtime.InteropServices
ComVisibleAttribute
CompilerGeneratedAttribute
IEnumerator`1
GetEnumerator
get_Current
IEnumerator
MoveNext
IDisposable
Attribute
op_Explicit
SetAttributeValue
get_NamespaceName
XObject
AddAnnotation
Func`2
System.Core
System.Linq
Enumerable
Select
get_FirstAttribute
get_NextAttribute
get_IsNamespaceDeclaration
Annotation
get_Name
get_LocalName
op_Equality
ExtensionAttribute
ReferenceEquals
Assembly
get_Assembly
GetObject
SettingsBase
Synchronized
get_SaveMySettingsOnExit
ObjectFlowControl
CheckForSyncLockOnValueType
ShutdownEventHandler
add_Shutdown
EventHandler
add_Load
SuspendLayout
ContainerControl
set_AutoScaleDimensions
AutoScaleMode
set_AutoScaleMode
set_BackgroundImage
ImageLayout
set_BackgroundImageLayout
set_ClientSize
FormBorderStyle
set_FormBorderStyle
set_Name
FormStartPosition
set_StartPosition
set_Text
FormWindowState
set_WindowState
ResumeLayout
set_TopMost
get_StartupPath
Concat
System.IO
Exists
ServerComputer
Microsoft.VisualBasic.MyServices
FileSystemProxy
get_FileSystem
DeleteFile
Network
get_Network
DownloadFile
ReadAllText
Strings
CompareMethod
Conversions
ToInteger
WriteAllText
Interaction
MsgBoxResult
MsgBoxStyle
MsgBox
Process
DesignerGeneratedAttribute
DebuggableAttribute
DebuggingModes
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
AssemblyFileVersionAttribute
GuidAttribute
AssemblyTrademarkAttribute
AssemblyCopyrightAttribute
AssemblyProductAttribute
AssemblyCompanyAttribute
AssemblyDescriptionAttribute
AssemblyTitleAttribute
System.Runtime.Versioning
TargetFrameworkAttribute
download.exe
download.updateWindow.resources
download.Resources.resources
MyTemplate
11.0.0.0
My.Computer
My.Forms
My.User
My.WebServices
My.Application
System.Windows.Forms.Form
Create__Instance__
Dispose__Instance__
My.MyProject.Forms
4System.Web.Services.Protocols.SoapHttpClientProtocol
Create__Instance__
Dispose__Instance__
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
12.0.0.0
My.Settings
WrapNonExceptionThrows
1.0.0.0
$4a506e8d-bdb4-48ec-af47-0945a581e3e2
Copyright
2015
WindowsApplication3
.NETFramework,Version=v4.5
FrameworkDisplayName
.NET Framework 4.5
_CorExeMain
mscoree.dll
D:\OneDrive\Dokumenty\Kody\Composer\update\WindowsApplication3\obj\Debug\download.pdb
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwwwwwwwwwww
wwwwww
wwwwww
wwwwww
wwwwww
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
infokoliber720
Property can only be set to Nothing
WinForms_RecursiveFormCreate
WinForms_SeeInnerException
download.Resources
infokoliber720
updateWindow
\new.txt
http://proxnet.eu/compo/update/ver.txt
\ver.txt
\Composer.exe
http://proxnet.eu/compo/update/Composer.exe
d - uruchom aktualizacj
ponownie
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
FileDescription
WindowsApplication3
FileVersion
1.0.0.0
InternalName
download.exe
LegalCopyright
Copyright
2015
OriginalFilename
download.exe
ProductName
WindowsApplication3
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Elastic Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Zusy.233629
FireEye Generic.mg.d2296420a619f590
CAT-QuickHeal Clean
ALYac Gen:Variant.Zusy.233629
Cylance Clean
Zillya Clean
SUPERAntiSpyware Clean
Sangfor Backdoor.MSIL.Generic.ky
K7AntiVirus Clean
Alibaba Backdoor:Win32/Generic.8d9858ee
K7GW Clean
Cybereason malicious.0a619f
Arcabit Clean
BitDefenderTheta Clean
Cyren W32/Trojan.VZMS-9202
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Avast Win32:Malware-gen
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Generic
BitDefender Gen:Variant.Zusy.233629
NANO-Antivirus Clean
Paloalto generic.ml
ViRobot Clean
Tencent Msil.Backdoor.Generic.Wnvt
Ad-Aware Gen:Variant.Zusy.233629
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro TROJ_GEN.R049C0PFL21
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Gen:Variant.Zusy.233629 (B)
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
eGambit Unsafe.AI_Score_99%
Avira BDS/Agent.zvmhx
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/AgentTesla!ml
AegisLab Trojan.MSIL.Generic.m!c
ZoneAlarm Clean
GData Gen:Variant.Zusy.233629
Cynet Malicious (score: 99)
AhnLab-V3 Malware/Win.Generic.C4518105
Acronis Clean
McAfee RDN/Generic BackDoor
TACHYON Clean
VBA32 TScope.Trojan.MSIL
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R049C0PFL21
Rising Clean
Yandex Clean
Ikarus Backdoor.Agent
MaxSecure Trojan.Malware.300983.susgen
Fortinet PossibleThreat
Webroot Clean
AVG Win32:Malware-gen
Panda Trj/GdSda.A
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.