Static | ZeroBOX

PE Compile Time

2070-12-29 18:57:34

PDB Path

C:\Users\black\Desktop\Forensic\project\rats\poly\tcpratserverplymarphism\tcpratserver\obj\Debug\tcpratserver.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00001898 0x00001a00 5.37284963784
.rsrc 0x00004000 0x000005cc 0x00000600 4.08474175341
.reloc 0x00006000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00004090 0x0000033c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x000043dc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
IEnumerator`1
GetLocalIPv4
get_UTF8
<Module>
get_ASCII
System.IO
exdata
mscorlib
System.Collections.Generic
ReadToEnd
NetworkInterface
Replace
CryptoStreamMode
get_Message
IDisposable
Console
set_FileName
WriteLine
get_NetworkInterfaceType
Dispose
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
tcpratserver.exe
Encoding
System.Runtime.Versioning
FromBase64String
ToBase64String
ToString
GetString
get_Length
FlushFinalBlock
NetworkStream
CryptoStream
GetStream
MemoryStream
Program
System
SymmetricAlgorithm
ICryptoTransform
System.Net.NetworkInformation
UnicastIPAddressInformation
System.Reflection
UnicastIPAddressInformationCollection
get_InnerException
SocketException
get_StartInfo
ProcessStartInfo
StreamReader
TextReader
DESCryptoServiceProvider
TcpListener
ToUpper
StreamWriter
TextWriter
tcpratserver
IEnumerator
GetEnumerator
CreateDecryptor
CreateEncryptor
System.Diagnostics
GetAllNetworkInterfaces
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
GetIPProperties
IPInterfaceProperties
get_UnicastAddresses
GetBytes
Contains
System.Collections
get_Chars
Process
IPAddress
get_Address
System.Net.Sockets
get_OperationalStatus
Concat
Object
System.Net
WaitForExit
AcceptTcpClient
get_Current
textToDecrypt
textToEncrypt
Convert
get_StandardInput
set_RedirectStandardInput
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
set_CreateNoWindow
ToArray
publickey
System.Security.Cryptography
get_AddressFamily
op_Equality
WrapNonExceptionThrows
tcpratserver
Copyright
2021
$8c09b54e-81ea-47b6-be49-85b2d588a666
1.0.0.0
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\black\Desktop\Forensic\project\rats\poly\tcpratserverplymarphism\tcpratserver\obj\Debug\tcpratserver.pdb
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
87654321
Waiting for a connection...
Connected!
Received: {0}
Decrypting...
Finding key...
Key Found:
Data Found:
12345678
cmd.exe
Executed.
Sent: {0}
SocketException: {0}
Hit enter to continue...
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
tcpratserver
FileVersion
1.0.0.0
InternalName
tcpratserver.exe
LegalCopyright
Copyright
2021
LegalTrademarks
OriginalFilename
tcpratserver.exe
ProductName
tcpratserver
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.46738336
FireEye Trojan.GenericKD.46738336
CAT-QuickHeal Clean
ALYac Trojan.GenericKD.46738336
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46738336
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46738336
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
MaxSecure Trojan.Malware.300983.susgen
CMC Clean
Emsisoft Trojan.GenericKD.46738336 (B)
SentinelOne Clean
GData Trojan.GenericKD.46738336
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Generic.D2C92BA0
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!78C1154BCBA1
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09H521
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilCO.34058.am0@auxdu3p
Cybereason Clean
Avast Clean
Qihoo-360 Clean
No IRMA results available.