Static | ZeroBOX

PE Compile Time

2055-04-22 04:53:25

PDB Path

C:\Users\jpint\source\repos\Stubular\Stubular\obj\Release\Stubular.pdb

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00000e18 0x00001000 5.01786126169
.rsrc 0x00004000 0x0002de54 0x0002e000 6.01306796579
.reloc 0x00032000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000313f8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00031870 0x00000084 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00031904 0x00000350 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00031c64 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
__StaticArrayInitTypeSize=91
<Module>
<PrivateImplementationDetails>
B5F22747511BCBDBF25BB4915FF7E1CACC7656CF619785FDC4F300704D0E3E6A
resolveDB
get_ASCII
DownloadData
mscorlib
Thread
Replace
RuntimeFieldHandle
get_MainWindowHandle
ValueType
SecurityProtocolType
GetType
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
Stubular.exe
System.Threading
Encoding
System.Runtime.Versioning
FromBase64String
DownloadString
GetString
user32.dll
set_SecurityProtocol
Program
System
Boolean
System.Reflection
WebHeaderCollection
Stubular
InvokeMember
Binder
ServicePointManager
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
BindingFlags
get_Headers
RuntimeHelpers
GetCurrentProcess
Object
System.Net
WebClient
Convert
System.Text
ShowWindow
nCmdShow
InitializeArray
Assembly
WrapNonExceptionThrows
Stubular
Chris Roads
Stubular FileOPS
Copyright
2021
LTM Corp.
$0d5192b0-13ee-4051-9629-8089c0f31635
4.3.3.1
.NETFramework,Version=v4.7.2
FrameworkDisplayName
.NET Framework 4.7.2
C:\Users\jpint\source\repos\Stubular\Stubular\obj\Release\Stubular.pdb
_CorExeMain
mscoree.dll
https://cdn.discordapp.com/attachments/871555386254163998/883461051495100486/GreenLight.dll
J7db]D
`ggG+h
PgDAw?\
B:-du1
\f---)+LE^
;rP6?EUL
nbUu$`]i
={Vi=tn
._*MU.&
'OFVS(
[[[V~r
gVMmr{
9lllb{g;
%,--aqq
`3TFM~
+++X]]
'E$Bxo
#X^^N+
/--b~.
X9Aw8&
,.-b!N
=jt'~B
2,--aye
_qICPer
D,NQ7M
De&|q-C:<
BS1!JAR
J6"c,j
B(|?&%
pI<lF~
k:r0RDY
0u&fj%
f5kz(@
kkkW{{{
~~~hccc
eeequuu
ZZZSddd
CCCR$$$
+++y///
AAA,```
***+
;~~~;{{{;{{{;uuu;ooo;ooo;ooo;qqq;{{{;{{{;{{{;
U$$#rcc`
r''&reec
r&&%rdca
r&&%rbaa
r%%%r`_^
r%%$r]]\
r%$$r[ZZ
r$##rYYX
r###rVVV
r###rUUT
r###rSSS
r###rRRR
r$$$rQQQ
r%%%rRRR
r&&&rRRR
r'''rSSS
r(((rTTT
r***rVVV
r,,,oWWW
o777a___
q~~~pGGG;
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
https://a.uguu.se/ignDFZP.txt
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe
User-Agent: Mozilla 4.0
GreenLight.card
Goblin
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
Chris Roads
FileDescription
Stubular
FileVersion
4.3.3.1
InternalName
Stubular.exe
LegalCopyright
Copyright
2021
LegalTrademarks
LTM Corp.
OriginalFilename
Stubular.exe
ProductName
Stubular FileOPS
ProductVersion
4.3.3.1
Assembly Version
4.3.6.1
Antivirus Signature
Bkav Clean
Lionic Trojan.Multi.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.0425240f08e4a9d0
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
BitDefenderTheta Gen:NN.ZemsilF.34126.lm0@a0fsMsh
Cyren W32/MSIL_Agent.CEM.gen!Eldorado
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan-Spy.MSIL.Noon.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!0425240F08E4
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Noon!tr
AVG FileRepMalware
Cybereason malicious.cdc96b
Avast FileRepMalware
No IRMA results available.