Static | ZeroBOX

PE Compile Time

2021-07-19 13:11:41

PDB Path

G:\VPN-Update\VPN-release\VPN-L-WH\LoginApplication\LoginApplication\obj\Debug\KV-Update.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00007358 0x00007400 6.26624682732
.rsrc 0x0000a000 0x00002bf4 0x00002c00 4.75530955823
.reloc 0x0000e000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a100 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL dBase IV DBT of `.DBF, block length 9216, next free block index 40, next free block 1867971, next used block 1867971
RT_GROUP_ICON 0x0000c6b8 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0000c6dc 0x00000316 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0000ca04 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
T sQ
7:sQ
:"sQ
:"sQ
v4.0.30319
#Strings
txt_Password_TextChanged_1
txt_UserName_TextChanged_1
label1_Click_1
label1
panel1
pictureBox1
pictureBox2
label3
pictureBox3
label4
get_UTF8
<Module>
System.IO
FromArgb
mscorlib
Thread
add_Load
frmLogin_Load
add_TextChanged
Synchronized
txt_Password
FlatButtonAppearance
get_FlatAppearance
defaultInstance
set_Mode
set_AutoScaleMode
set_SizeMode
PictureBoxSizeMode
PaddingMode
CipherMode
set_Image
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
UploadFile
set_FormBorderStyle
set_FlatStyle
FontStyle
set_Name
txt_UserName
WriteLine
get_Culture
set_Culture
resourceCulture
ButtonBase
ApplicationSettingsBase
Dispose
nWidthEllipse
nHeightEllipse
KV-Update
EditorBrowsableState
showState
Delete
get_White
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_Leave
txt_UserName_Leave
KV-Update.exe
set_Size
set_AutoSize
set_BorderSize
set_ClientSize
ISupportInitialize
System.Threading
set_Padding
Encoding
System.Runtime.Versioning
ToBase64String
add_FormClosing
frmMain_FormClosing
disposing
System.Drawing
ComputeHash
GetFolderPath
get_Width
get_Black
get_HotTrack
label1_Click
button1_Click
label2_Click
label4_Click
add_Click
btn_LogOut_Click
TransformFinalBlock
System.ComponentModel
Gdi32.dll
kernel32.dll
user32.dll
ContainerControl
Program
System
SymmetricAlgorithm
HashAlgorithm
nBottom
ICryptoTransform
resourceMan
CreateRoundRectRgn
FromHrgn
frmMain
frmLogin
set_Icon
set_Region
LoginApplication
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
set_StartPosition
FormStartPosition
Button
CultureInfo
set_TabStop
set_UseSystemPasswordChar
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
SpecialFolder
sender
get_ResourceManager
ComponentResourceManager
FormClosingEventHandler
PaintEventHandler
System.CodeDom.Compiler
IContainer
StreamWriter
TextWriter
add_Enter
txt_UserName_Enter
txt_UserName_MouseEnter
get_Silver
set_ForeColor
set_BackColor
set_UseVisualStyleBackColor
.cctor
CreateEncryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
LoginApplication.frmMain.resources
LoginApplication.frmLogin.resources
LPAP.Properties.Resources.resources
DebuggingModes
LPAP.Properties
EnableVisualStyles
GetBytes
Settings
FormClosingEventArgs
PaintEventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
SystemColors
Process
components
Exists
Concat
GetObject
System.Net
get_ControlLightLight
nRight
get_Height
btn_Submit
EndInit
BeginInit
GraphicsUnit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
WebClient
Environment
InitializeComponent
panel1_Paint
add_Paint
set_Font
Convert
btn_LogOut
SuspendLayout
ResumeLayout
PerformLayout
System.Text
get_Text
set_Text
PlainText
get_ActiveCaptionText
EncryptPlainTextToCipherText
GetConsoleWindow
ShowWindow
set_TabIndex
MessageBox
PictureBox
set_MaximizeBox
set_ControlBox
TextBox
get_DimGray
set_Key
SecurityKey
System.Security.Cryptography
get_Assembly
op_Equality
op_Inequality
WrapNonExceptionThrows
KVS Update
$b178f132-e751-4961-b54c-c4f946669545
5.3.58.4
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
16.8.1.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3ahSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPADPBj
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Icon
IconData
IconSize
System.Drawing.Size
System.Drawing.Size
height
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDAThC
OV&aVD
Ye$wRv
~xsF F
7S!-AJ
B7*g$G
xCxN
#|J#%ni
39gZx6
iZXSv;
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
q92q{4U
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
System.Drawing.Bitmap
IDATx^
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
G:\VPN-Update\VPN-release\VPN-L-WH\LoginApplication\LoginApplication\obj\Debug\KV-Update.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
LPAP.Properties.Resources
Please provide UserName and Password
Successfully Identified User:
\Kavach Authentication\KavachAuthentication.exe
\2163786281
\kavachdb\kavach.db
http://149.248.52.61/vpn-update/vpn-update.php
NICAdmin@123
example@nic.in
Microsoft Sans Serif
txt_UserName
txt_Password
btn_Submit
panel1
label1
KAVACH UPDATE
pictureBox1.Image
pictureBox1
label4
Please enter your NIC Email as Username
pictureBox2.Image
pictureBox2
pictureBox3.Image
pictureBox3
label3
and Password to Activate
$this.Icon
frmLogin
btn_LogOut
Log out
frmMain
Main Application
NICAdmin@123
$this.Icon
pictureBox1.Image
pictureBox2.Image
pictureBox3.Image
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
KVS Update
FileVersion
5.3.58.4
InternalName
KV-Update.exe
LegalCopyright
LegalTrademarks
OriginalFilename
KV-Update.exe
ProductName
KVS Update
ProductVersion
5.3.58.4
Assembly Version
5.3.5.84
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.37334543
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Win32/Trojan.Agentb.HgIASZkA
McAfee RDN/Generic.dx
Cylance Clean
Zillya Trojan.Agent.Win32.2353590
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0040eff71 )
Alibaba Clean
K7GW Riskware ( 0040eff71 )
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Agentb.gen
BitDefender Trojan.GenericKD.37334543
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37334543
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic.dx
FireEye Trojan.GenericKD.37334543
Emsisoft Trojan.GenericKD.37334543 (B)
Ikarus Win32.Outbreak
GData Trojan.GenericKD.37334543
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D239AE0F
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.MSIL.Agentb.gen
Microsoft Trojan:Win32/Zpevdo.B
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Trojan.GenericKD.37334543
MAX malware (ai score=88)
Malwarebytes Clean
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CH421
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike Clean
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.